Commission Implementing Regulation (EU) 2025/848 of 6 May 2025 laying down rules for the application of Regulation (EU) No 910/2014
as it stood on 2025-05-06, permalink: /eu-eurlex/32025r0848/2025-05-06
Article 1
This Regulation lays down rules for the registration of wallet-relying parties.
Article 2
For the purposes of this Regulation, the following definitions apply:
| (1) | ‘wallet-relying party’ means a relying party that intends to rely upon wallet units for the provision of public or private services by means of digital interaction; |
|---|
| (2) | ‘wallet unit’ means a unique configuration of a wallet solution that includes wallet instances, wallet secure cryptographic applications and wallet secure cryptographic devices provided by a wallet provider to an individual wallet user; |
|---|
| (3) | ‘wallet solution’ means a combination of software, hardware, services, settings, and configurations, including wallet instances, one or more wallet secure cryptographic applications and one or more wallet secure cryptographic devices; |
|---|
| (4) | ‘wallet instance’ means the application installed and configured on a wallet user’s device or environment, which is part of a wallet unit, and that the wallet user uses to interact with the wallet unit; |
|---|
| (5) | ‘wallet secure cryptographic application’ means an application that manages critical assets by being linked to and using the cryptographic and non-cryptographic functions provided by the wallet secure cryptographic device; |
|---|
| (6) | ‘wallet secure cryptographic device’ means a tamper-resistant device that provides an environment that is linked to and used by the wallet secure cryptographic application to protect critical assets and provide cryptographic functions for the secure execution of critical operations; |
|---|
| (7) | ‘critical assets’ means assets within or in relation to a wallet unit of such extraordinary importance that where their availability, confidentiality or integrity are compromised, this would have a very serious, debilitating effect on the ability to rely on the wallet unit; |
|---|
| (8) | ‘wallet provider’ means a natural or legal person who provides wallet solutions; |
|---|
| (9) | ‘wallet user’ means a user who is in control of the wallet unit; |
|---|
| (10) | ‘national register of wallet-relying parties’ means a national electronic register used by a Member State to make information on wallet-relying parties registered in that Member State publicly available as set out in Article 5b(5) of Regulation (EU) No 910/2014; |
|---|
| (11) | ‘provider of wallet-relying party access certificates’ means a natural or legal person mandated by a Member State to issue wallet-relying party access certificates to wallet-relying parties registered in that Member State; |
|---|
| (12) | ‘wallet-relying party access certificate’ means a certificate for electronic seals or signatures authenticating and validating the wallet-relying party issued by a provider of wallet-relying party access certificates; |
|---|
| (13) | ‘provider of person identification data’ means a natural or legal person responsible for issuing and revoking the person identification data and ensuring that the person identification data of a user is cryptographically bound to a wallet unit; |
|---|
| (14) | ‘registrar of wallet-relying parties’ means the body responsible for establishing and maintaining the list of registered wallet-relying parties established in their territory and who has been designated by a Member State; |
|---|
| (15) | ‘wallet-relying party registration certificate’ means a data object that describes the intended use of the relying party and indicates the attributes the relying party has registered to intend to request from users; |
|---|
| (16) | ‘provider of wallet-relying party registration certificates’ means a natural or legal person mandated by a Member State to issue wallet-relying party registration certificates to wallet-relying parties registered in that Member State. |
|---|
Article 3
Member States shall establish and maintain at least one national register of wallet-relying parties with information regarding registered wallet-relying parties established in that Member State.
The register shall include at least the information set out in Annex I.
Member States shall designate at least one registrar to manage and operate at least one national register of wallet-relying parties.
Member States shall make the information set out in Annex I on registered wallet-relying parties publicly available online, both in human-readable form and in a form suitable for automated processing.
The information referred to in paragraph 2 shall be available through a single common application programming interface (‘API’) and through a national website. It shall be electronically signed or sealed by or on behalf of the registrar, in accordance with the common requirements for a single API set out in Section 1 of Annex II.
Member States shall ensure that the API referred to in paragraph 5 complies with the common requirements set out in Section 2 of Annex II.
Member States shall ensure that the registers comply with the relevant common registration policies set out in Article 4.
Article 4
Member States shall lay down and publish one or more national registration policies applicable to the national registers established in their territory.
Member States may include or reuse existing sectoral or national registration policies.
The national registration policy shall include at least information on:
| (a) | the identification and authentication procedures applicable to wallet-relying parties during the registration process; |
|---|
| (b) | the required supporting documentation, regarding the identity, business registration, applicable entitlement or entitlements, and other relevant information on the wallet-relying party; |
|---|
| (c) | the authentic sources or other official electronic records and where those sources or records can be relied upon to provide accurate data; |
|---|
| (d) | any other information or other evidence required as part of the registration process; |
|---|
| (e) | where applicable, the automated means of enabling wallet-relying parties to register or to update an existing registration; |
|---|
| (f) | the redress mechanism available to wallet-relying parties under the laws and procedures of the Member State where the national register is established; |
|---|
| (g) | the rules and procedures for the verification of the identity of the registered wallet-relying parties and of any other relevant information provided by that party. |
|---|
The procedures and documentation referred to in paragraph 3, points (a) and (b), shall enable the wallet-relying parties to indicate which specific entitlement or entitlements it is acting under, as set out in Annex I.
Where appropriate, the requirements set out in the national registration policy shall not impede an automated registration process.
Article 5
Wallet-relying parties shall at least provide the information set out in Annex I to national registers.
Wallet-relying parties shall ensure that the information provided is accurate at the time of registration.
Wallet-relying parties shall update any information previously registered in the national register of wallet-relying parties without undue delay.
Article 6
Registrars shall establish easy to use electronic, and where possible, automated registration processes for wallet-relying parties.
Registrars shall process applications for registration without undue delay and provide a response to the application for registration to the applicant within the timeframe defined in the applicable registration policy, using appropriate means and in accordance with the laws and procedures of the Member State where the national register is established.
Where possible, registrars shall verify in an automated manner:
| (a) | the accuracy, validity, authenticity and integrity of the information required under Article 5; |
|---|
| (b) | where applicable, the power of attorney of representatives of the wallet-relying parties drawn up and submitted in accordance with the laws and procedures of the Member State where the national register is established; |
|---|
| (c) | the type of entitlement or entitlements of the wallet-relying parties as set out in Annex I; |
|---|
| (d) | the absence of an existing registration in another national register. |
|---|
Registrars shall verify the information set out in paragraph 3 against the supporting documentation provided by the wallet-relying parties or against appropriate authentic sources or other official electronic records in the Member State where the national register is established and to which the registrars have access in accordance with the applicable national laws and procedures.
The verification of entitlements of wallet-relying parties referred to in paragraph 3, point (c) shall be carried out in accordance with Annex III.
Where the registrar cannot verify the information in accordance with paragraphs 3 to 5, the registrar shall reject the registration.
When a wallet-relying party no longer intends to rely upon wallet units for the provision of public or private services under a specific registration, it shall notify the relevant registrar without undue delay and request the cancellation of that registration.
Article 7
Member States shall authorise at least one certificate authority to issue wallet-relying party access certificates.
Member States shall ensure that providers of wallet-relying party access certificates issue wallet-relying party access certificates exclusively to registered wallet-relying parties.
Member States shall implement in a syntactically and semantically harmonised manner the certificate policies and certificate practice statements for the wallet-relying party access certificates, in accordance with the requirements set out in Annex IV.
Article 8
Member States may authorise at least one certificate authority to issue wallet-relying party registration certificates.
Where a Member State authorised the issuance of a wallet-relying party registration certificate, that Member State shall;
| (a) | require providers of wallet-relying party registration certificates to issue wallet-relying party registration certificates exclusively to registered wallet-relying parties; |
|---|
| (b) | ensure that each intended use is expressed in the wallet-relying party registration certificates; |
|---|
| (c) | ensure that wallet-relying party registration certificates include a general access policy, being syntactically and semantically harmonised across the Union, informing users that the wallet-relying party is only allowed to request the data specified in the registration certificates for the intended use registered in the registration certificates; |
|---|
| (d) | ensure that providers of wallet solutions established in that Member State comply with the general access policy by informing users when a wallet-relying party requests data that is not specified in the registration certificates; |
|---|
| (e) | implement wallet-relying party registration certificates in a syntactically and semantically harmonised manner and in line with the requirements set out in Annex V; |
|---|
| (f) | implement dedicated certificate policies and certificate practice statements for the wallet-relying party registration certificates in accordance with the requirements set out in Annex V; |
|---|
| (g) | ensure that wallet-relying parties provide a URL to the privacy policy regarding the intended use. |
|---|
- The policy referred to in point (g) shall be expressed in the wallet-relying party registration certificate.
Article 9
Registrars shall suspend or cancel a registration of a wallet-relying party where such a suspension or cancellation is requested by a supervisory body pursuant to Article 46a(4), point (f) of Regulation (EU) No 910/2014.
Registrars may suspend or cancel a registration of a wallet-relying party where the registrars have reasons to believe one of the following:
| (a) | the registration contains information, which is inaccurate, out of date or misleading; |
|---|
| (b) | the wallet-relying party is not compliant with the registration policy; |
|---|
| (c) | the wallet-relying party is requesting more attributes than they have registered in accordance with Article 5 and Article 6; |
|---|
| (d) | the wallet-relying party is otherwise acting in breach of Union or national law in a manner related to their role as wallet-relying party. |
|---|
Registrars shall suspend or cancel a registration of a wallet-relying party where the request for cancellation or suspension is made by the same wallet-relying party.
When considering the suspension or cancellation in accordance with paragraph 2, the registrar shall conduct a proportionality assessment, taking into account the impact on the fundamental rights, security and confidentiality of the users in the ecosystem, as well as the severity of the disruption envisaged to be caused by the suspension or cancellation and the associated costs, both for the wallet-relying party and the user. Based on the result of this assessment, the registrar may suspend or cancel the registration with or without prior notice to the affected wallet-relying party.
Where the registration of a wallet-relying party is suspended or cancelled, the registrar shall inform the provider of the relevant wallet-relying party access certificates, the provider of the relevant wallet-relying party registration certificates, and the affected wallet-relying party of this action without undue delay and not later than 24 hours after the suspension or cancellation. This notification shall include information on the reasons for the suspension or cancellation and on the available means of redress or appeal.
The provider of wallet-relying party access certificates and the provider of wallet-relying registration certificates, shall, where applicable, revoke without undue delay the wallet-relying party access certificates, and the wallet-relying party registration certificates, respectively, of the wallet-relying party for which registration has been suspended or cancelled.
Article 10
Registrars shall keep records of the information provided by wallet-relying parties and registered in accordance with Annex I for the registration of a wallet-relying party and the issuance of the wallet-relying party access certificates and the wallet-relying party registration certificates, and of any subsequent changes to this information, for 10 years.
Article 11
This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union.
It shall apply from the 24 December 2026.
This Regulation shall be binding in its entirety and directly applicable in all Member States.
Provenance and validity dates, identifier, hash
| as of | 2025-05-06 → this version applied |
| valid | 2025-05-06 → open publisher-asserted |
| type | REG_IMPL Commission Implementing Regulation (EU) 2025/848 of 6 May 2025 laying down rules for the application of Regulation (EU) No 910/2014 of the European Parliament and of the Council as regards the registration of wallet-relying parties |
| language | en |
| published | 2025-05-06 |
| lex_id | eu-eurlex:32025r0848:2025-05-06 |
| record sha256 | 138ce9d6ce0313e9f2de75cb13783bd212fb40f06ff5752740315733b79d2817 |
New here? What am I looking at?
This is a consolidated text: the original law with every later amendment merged in, as the official publisher produced it for a given date. Laws are amended constantly, so “the law” has no single text, only a text per date. That date is the banner above.
It has no legal force. Only the version published in the official gazette (Mémorial / Official Journal) is authentic, the publishers say so themselves, and so do we. Lex reproduces their text without altering a byte, and links the source on every page. This is legal information, never legal advice: it reports what the text said, never what it means for your situation.
“Valid from → to” = the window in which this text applied. “Open” = still current as far as the publisher has consolidated. Each article carries its own hash so you can prove it was not tampered with , here is how.
timeline next version (2025-05-06) →
| tier | A, publisher-supplied validity dates |
| history begins | publisher |
| index built | 2026-08-07T19:46:23Z · corpus 8d5e859 |
| stamp signature | valid (ECDSA-P256) |