Commission Implementing Regulation (EU) 2025/849 of 6 May 2025 laying down rules for the application of Regulation (EU) No 910/2014
as it stood on 2025-05-06, permalink: /eu-eurlex/32025r0849/2025-05-06
Article 1
This Regulation lays down the formats and procedures as regards the submission of information by Member States to the Commission and the Cooperation Group for the list of certified wallets pursuant to Article 5d of Regulation (EU) No 910/2014, to be updated on a regular basis to keep in line with technology and standards developments and with the work carried out on the basis of Commission Recommendation (EU) 2021/946 (5), and in particular the Architecture and Reference Framework.
Article 2
For the purposes of this Regulation, the following definitions apply:
| (1) | ‘wallet solution’ means a combination of software, hardware, services, settings, and configurations, including wallet instances, one or more wallet secure cryptographic applications and one or more wallet secure cryptographic devices; |
|---|
| (2) | ‘wallet instance’ means the application installed and configured on a wallet user’s device or environment, which is part of a wallet unit, and that the wallet user uses to interact with the wallet unit; |
|---|
| (3) | ‘wallet unit’ means a unique configuration of a wallet solution that includes wallet instances, wallet secure cryptographic applications and wallet secure cryptographic devices provided by a wallet provider to an individual wallet user; |
|---|
| (4) | ‘wallet provider’ means a natural or legal person who provides wallet solutions; |
|---|
| (5) | ‘wallet user’ means a user who is in control of the wallet unit; |
|---|
| (6) | ‘wallet secure cryptographic application’ means an application that manages critical assets by being linked to and using the cryptographic and non-cryptographic functions provided by the wallet secure cryptographic device; |
|---|
| (7) | ‘wallet secure cryptographic device’ means a tamper-resistant device that provides an environment that is linked to and used by the wallet secure cryptographic application to protect critical assets and provide cryptographic functions for the secure execution of critical operations; |
|---|
| (8) | ‘critical assets’ means assets within or in relation to a wallet unit of such extraordinary importance that where their availability, confidentiality or integrity are compromised, this would have a very serious, debilitating effect on the ability to rely on the wallet unit; |
|---|
| (9) | ‘provider of person identification data’ means a natural or legal person responsible for issuing and revoking the person identification data and ensuring that the person identification data of a user is cryptographically bound to a wallet unit. |
|---|
Article 3
Member States shall submit the information set out in the Annex to the Commission and to the Cooperation Group through a secure electronic channel made available by the Commission.
Member States shall submit the information required under paragraph 1 at least in English.
Where there are any changes to the submitted information, including changes to the certification status of the wallets, Member States shall submit the updated information through the channel referred to in paragraph 1.
Article 4
This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union.
Provenance and validity dates, identifier, hash
| as of | 2025-05-06 → this version applied |
| valid | 2025-05-06 → open publisher-asserted |
| type | REG_IMPL Commission Implementing Regulation (EU) 2025/849 of 6 May 2025 laying down rules for the application of Regulation (EU) No 910/2014 of the European Parliament and of the Council as regards the submission of information to the Commission and to the Cooperation Group for the list of certified European Digital Identity Wallets |
| language | en |
| published | 2025-05-06 |
| lex_id | eu-eurlex:32025r0849:2025-05-06 |
| record sha256 | 608476072526dd8b508661b0a334c3753297e98f95c5404ab7b552a3e4e136cd |
New here? What am I looking at?
This is a consolidated text: the original law with every later amendment merged in, as the official publisher produced it for a given date. Laws are amended constantly, so “the law” has no single text, only a text per date. That date is the banner above.
It has no legal force. Only the version published in the official gazette (Mémorial / Official Journal) is authentic, the publishers say so themselves, and so do we. Lex reproduces their text without altering a byte, and links the source on every page. This is legal information, never legal advice: it reports what the text said, never what it means for your situation.
“Valid from → to” = the window in which this text applied. “Open” = still current as far as the publisher has consolidated. Each article carries its own hash so you can prove it was not tampered with , here is how.
timeline next version (2025-05-06) →
| tier | A, publisher-supplied validity dates |
| history begins | publisher |
| index built | 2026-08-07T19:46:23Z · corpus 8d5e859 |
| stamp signature | valid (ECDSA-P256) |