Estonia's Information System Authority (RIA) closed a €21.65 million procurement on June 29, 2026, to find the company that will build the country's EU Digital Identity Wallet (EUDI Wallet) — the mobile credential every EU member state must offer citizens under the bloc's eIDAS 2.0 regulation by December 24, 2026. RIA opened the tender on May 18, 2026, using a competitive-dialogue procedure that will narrow applicants to three to five finalists before awarding a contract covering up to eight years, including five years of post-launch operation.
A Deadline Most States Are Missing
Estonia is not racing against an abstract standard; it is racing against peers who are visibly behind. Germany has said its state wallet will launch January 2, 2027, nine days after the legal deadline. The Netherlands has signaled it may miss the deadline entirely. Bulgaria had not begun serious development as of December 2025, and Lithuania only signed a contract for a national wallet sandbox in February 2026, according to reporting by Forbes. RIA's own materials describe only a handful of member states as on track to deploy certified, cross-border-functional wallets by year-end 2026.
Why a Hard EU-Wide Deadline Makes Sense
The fairest case for Brussels' rigid timeline is straightforward: a wallet is only as useful as its interoperability. If member states could set their own schedules, cross-border recognition — a French citizen using an Estonian-issued wallet to open a Latvian bank account, or vice versa — would arrive piecemeal and unpredictably, undermining the single market rationale for building a EUDI Wallet at all. Regulation (EU) 2024/1183, which entered into force May 20, 2024, ties the wallet's value explicitly to mutual recognition across all 27 states; a soft deadline invites the slowest state to set the pace for everyone. Security researchers also raised legitimate concerns before the regulation passed — over 500 experts from 39 countries warned early drafts could enable identity infrastructure "a repressive government could abuse" — and the final text's added pseudonym rights and dropped persistent-identifier requirements were a direct, credible response to those warnings, not cosmetic concessions.
Where the Rigid Timeline Bites
The cost of that uniformity is now visible in the procurement data itself. Certification schemes the wallets must pass remain unfinished in many capitals, and technical specifications from the EU's eIDAS Expert Group have kept shifting during the implementation window — a moving target that penalizes states starting from zero far more than states with existing infrastructure. A single missed December deadline in a large economy like Germany or the Netherlands does more damage to the interoperability goal than a flexible six-to-twelve-month grace period would have. Brussels chose a hard date over a phased one, and several of its largest members are now going to miss it anyway — the worst of both outcomes.
Estonia's Structural Advantage
Estonia's tender documents are explicit that the EUDI Wallet "does not replace the existing national electronic identification solutions" — RIA is building an EU-compliant layer on top of infrastructure that already works. That matters because Estonia isn't starting a digital-identity program in 2026; it is extending one that has issued ID cards to 99% of residents and processed roughly 800 million digital signatures, per e-Estonia's published figures. Where Bulgaria or the Netherlands must stand up trust infrastructure, certificate authorities, and citizen onboarding simultaneously, Estonia only has to make its existing eID ecosystem speak the EU's new wallet protocol. Margit Aus, head of the EUDI Wallet project at RIA, said the tender seeks "a comprehensive solution" enabling users to "securely store and present authentication data, use various types of attestation of attributes, and give digital signatures" — functions Estonia's population has been using in some form since the 2000s.
The Innovation Case
This is the strongest argument against treating eIDAS 2.0's deadline as a template for future EU digital mandates: uniform compliance dates work only when starting conditions are uniform, and they plainly are not. A regulation that rewards states for having already invested in interoperable digital public infrastructure — rather than one that simply penalizes laggards with the same fixed date regardless of starting point — would do more to spread genuinely good digital-identity practice across the bloc. Estonia's procurement is a useful proof of concept for what disciplined, incremental digital-government investment buys a country when a hard external deadline lands: instead of a crash program, RIA is running an eight-year vendor competition with room for extensions, built on rails laid over two decades. The lesson for Brussels isn't that deadlines are wrong — cross-border interoperability genuinely requires them — but that the next iteration of EU digital-identity policy should build in differentiated timelines or technical on-ramps for member states without Estonia's head start, rather than setting one date and hoping infrastructure catches up.