The EUDI Wallet Runs on Trust Services And Trust Services Run on HSMs

Press Release Date: 22 May 2026 22 May 2026
Table of Contents

By the end of 2026, every EU member state must deliver a digital identity wallet to its citizens. Behind each wallet is an ecosystem of qualified trust services, credential issuers and validation providers, all of which require hardware-backed
cryptographic infrastructure. In this blog post, we explain where Hardware Security Modules fit in the EUDI wallet architecture and what organizations building this infrastructure need to consider.
 

Not an App, An Ecosystem

Much of the public discussion around the European Digital Identity Wallet focuses on the mobile app that citizens will use to store their ID, sign documents, or verify their age online. That is the visible surface. But behind every wallet interaction is a multi-layered trust infrastructure that must be built, certified, and operational before any of this becomes possible.


The Architecture and Reference Framework (ARF) published by the European Commission describes this ecosystem in detail, and while the ARF continues to be refined as member states and the Commission work toward implementation, the core trust service architecture and its cryptographic requirements are well established. It includes Qualified Trust Service Providers (QTSPs), who issue qualified electronic signatures, seals, and electronic attestations of attributes. It includes Qualified Electronic Signature Remote Creation (QESRC) Providers — Qualified Trust Service Providers (QTSPs) that manage remote signing devices so that citizens can sign documents directly from their wallet without dedicated signing hardware. It includes PID Providers, the entities responsible for issuing Personal Identification Data at Level of
 

Assurance High, the EU’s most stringent identity verification standard. And it includes the
Wallet Providers themselves, who must issue cryptographically signed Wallet Unit Attestations to prove each wallet instance is authentic and operating within a certified security boundary.


None of these actors can fulfill their role without a secure environment for generating, storing, and managing cryptographic keys. The relevant question for organizations in this ecosystem is not what the wallet will look like for citizens, but whether the backend infrastructure required to serve those citizens is ready.


Where HSMs Fit in the Wallet Architecture

At the core of the ARF’s security model is the Wallet Secure Cryptographic Device (WSCD), the tamper-resistant component responsible for protecting cryptographic keys and executing sensitive cryptographic operations. The ARF defines four possible architectures for the WSCD: a component integrated into the smartphone’s operating system, an internal Secure Element such as an eSIM, an external device such as a smartcard, and a remote device accessed over a network. For this last category, the ARF is explicit: the remote WSCD is described as “a remote device, such as a Hardware Security Module (HSM).”
 

An important distinction follows from this. For individual citizens performing personal signing on their own device, a smartphone’s embedded Secure Element may serve as the WSCD. HSMs are not required in every wallet instance. But for the backend infrastructure that serves those wallet instances — the trust services, the credential issuance systems, the remote signing platforms — HSMs are the foundational component.


The use case with the most direct HSM dependency is remote qualified electronic signature creation. When a citizen uses their wallet to create a qualified signature through a remote QTSP, the signing key is not stored on the citizen’s device. It is held in a remote QSCD managed by the QTSP — and for remote deployments, that QSCD is an HSM. The implementing regulation (CIR 2024/2981, Annex IV) requires this WSCD to be certified at Level of Assurance High under Implementing Regulation 2015/1502. This is a legal prerequisite for offering remote qualified signing services within the EUDI wallet ecosystem.


PID Providers face a parallel requirement. Issuing identity credentials at the highest assurance level requires cryptographic operations like signing credentials and managing issuance keys within a certified secure environment. The cryptographic keys used to sign PID attestations carry the full weight of government-issued identity, and protecting them in a certified HSM is the established practice for this assurance level.


Wallet Providers carry their own obligation. Every wallet instance must present a Wallet Unit Attestation — a cryptographic proof that the wallet is genuine and has not been tampered with. Wallet Providers sign these attestations from their backend infrastructure using keys that must be protected at the highest level. At scale, potentially serving millions of wallet instances across a member state, this requires HSM-backed signing and key management.
 

Beyond these primary roles, HSMs support the broader trust ecosystem: timestamping services producing qualified electronic timestamps, validation services signing credential status responses, and the PKI infrastructure underpinning certificate issuance across the wallet ecosystem.
The EUDI wallet may live on a citizen’s smartphone, but the trust it depends on lives in data centers; in the HSMs that protect the keys, sign the credentials, and prove the authenticity of every component in the chain.
 

The Scale of the Infrastructure Challenge

The timeline makes the scale of this challenge concrete. By the end of 2026, every EU member state must make at least one EUDI wallet available to its citizens. By late 2027, regulated private sector services — including banks, telecom operators, and major online platforms — must accept wallet-based authentication. The infrastructure serving these interactions needs to be operational before the first citizen relies on it.


In practice, the rollout will not happen uniformly. Several member states already have wallet solutions in advanced development or production, while others are still in early planning stages. Not all countries will offer full qualified electronic signature capabilities at launch — some plan to start with basic identity and authentication, adding trust services over time. But the QTSPs and Wallet Providers that are ready to offer remote signing services in the first wave of deployments will shape the competitive landscape for European digital trust services. The ARF envisions a unified European market for QESRC Providers, meaning these trust services will operate across borders — and the organizations that establish certified infrastructure early will be positioned to serve not only their home market but the member states that follow.


For organizations entering this market, the infrastructure lead time is significant. Deploying HSM infrastructure, key management systems, and PKI components, and achieving QTSP certification, is not a project that can be completed in a few months. Organizations that can leverage pre-certified cryptographic components — HSMs that already hold Common Criteria certification recognized under eIDAS, with established track records in qualified trust service environments — can reduce their path to operational readiness considerably.


The regulation requires this infrastructure. But the path from regulatory mandate to operational deployment is where the real decisions are being made — and the choices organizations make now, while the framework is still taking shape, will determine their position when it solidifies.


What to Look for in Your HSM Infrastructure

If your organization is building or upgrading cryptographic infrastructure for the EUDI wallet ecosystem — whether as a QTSP, a Wallet Provider, a PID Provider, or a national identity agency — there are four capabilities your HSM platform should deliver from the outset.


eIDAS-specific certification: The implementing regulations require WSCD certification under Common Criteria, assessed against the requirements of Level of Assurance High. Until ENISA delivers an EU-wide certification scheme, which is not expected before the 2026 rollout, member states will rely on transitional national certification schemes. QTSPs should select HSM vendors whose certifications are already recognized across relevant national frameworks, as this reduces the burden of composite evaluation and accelerates the path to QTSP certification. Utimaco’s CryptoServer GP HSM holds Common Criteria certification through STIC CCN and is designed for eIDAS-compliant qualified electronic signature operations through the CC eIDAS application package.


Multi-tenancy at scale: The wallet ecosystem is designed for cross-border trust service delivery. QTSPs will serve multiple wallet providers, credential types, and member states from shared infrastructure. The ARF itself acknowledges this, noting that one WSCD may be a part of multiple Wallet Units in the case of a remote HSM. Deploying separate physical HSM clusters for each tenant is neither economically sustainable nor operationally practical at European scale. Utimaco’s u.trust General Purpose HSM Se-Series and CSe-Series support up to 31 fully isolated, containerized tenants within a single device, allowing QTSPs to consolidate workloads without compromising the cryptographic isolation required for qualified trust services.


Crypto-agility for regulatory longevity: Any wallet infrastructure deployed in 2026 must remain compliant, secure, and upgradeable well into the next decade. With Cloudflare now targeting full post-quantum security by 2029, including authentication, the planning horizon for cryptographic infrastructure has accelerated. Qualified electronic signatures created through the wallet may carry legal validity for years, while the underlying cryptography must remain trustworthy long after issuance. Utimaco’s Quantum Protect application package enables in-field activation of NIST-standardized post-quantum algorithms on existing Se-Series and CSe-Series hardware, without requiring device replacement. All algorithms are NIST CAVP validated.


Flexible deployment models: Not every organization in the wallet ecosystem will build and operate its own HSM infrastructure. Some QTSPs will deploy on-premises in their own certified data centers. Others need managed, cloud-hosted options that meet eIDAS certification and data sovereignty requirements. Utimaco offers its HSM solutions on-premises, as Trust as a Service in certified European data centers where customers retain sole control of their cryptographic keys, and as Qualified Electronic Signature as a Service for organizations that need fully managed signing capabilities.

These four capabilities are interdependent. A QTSP that achieves certification but cannot scale across tenants will be operationally constrained. One that scales but lacks crypto agility will face a forced migration as requirements evolve. Building on a platform that meets all four from day one positions your organization not only for the end of 2026 deadline, but for the decade of European digital identity that follows.
 

Getting Started

The end of 2026 deadline is approaching. Whether your organization is preparing to offer qualified trust services, deploying Wallet Provider infrastructure, or building PID issuance capabilities; the cryptographic foundation you choose now will shape your certification timeline, your operational scalability, and the longevity of your investment.
 

Test eIDAS-compliant HSM capabilities today. The CC eIDAS Simulator lets you explore Utimaco’s qualified electronic signature functionality in your own environment, free of charge.

Talk to our specialists. Our team can help you assess your current cryptographic infrastructure against EUDI wallet requirements and design a deployment path matched to your timeline and sovereignty needs.
 

Explore CC eIDAS Simulator | Contact Sales

 

About the Author

Amani

Amani Karchoud

Product Marketing Manager, Utimaco

디지털 미래를 보호할 준비가 되셨나요?

중요한 보안 인프라를 위해 Utimaco를 신뢰하는 500개 이상의 글로벌 기업 및 정부 기관과 함께하세요.

영업팀에 문의

How can we help you?

Talk to one of our specialists and find out how Utimaco can support you today.
You have selected two different types of downloads, so you need to submit different forms which you can select via the two tabs.

Your download request(s):

    By submitting below form you will receive links for your selected downloads.
    Loading...

    Your download request(s):

      For this type of documents, your e-mail address needs to be verified. You will receive the links for your selected downloads via e-mail after submitting below form.
      Loading...

      About Utimaco's Downloads

      Visit our Downloads section and select from resources such as brochures, data sheets, white papers and much more. You can view and save almost all of them directly (by clicking the download button).

      For some documents, your e-mail address needs to be verified. The button contains an e-mail icon.

      Download via e-mail

       

      A click on such a button opens an online form which we kindly ask you to fill and submit. You can collect several downloads of this type and receive the links via e-mail by simply submitting one form for all of them. Your current collection is empty.