Estonia's Information System Authority (RIA) closed applications on 29 June 2026 for a €21.65 million competitive-dialogue tender to build and operate the country's EU Digital Identity Wallet (EUDI Wallet) — the mobile successor to the card-based digi-ID that underpins both domestic e-government and the e-Residency program's roughly 142,000 digital residents. The contract runs 96 months, covering software development plus five years of live service, with RIA screening down to three to five bidders for the second stage of dialogue, per Biometric Update's reporting on the procurement.
A Deadline Most of Europe Will Miss
The tender exists because of a hard EU rule, not Estonian initiative alone. Under the eIDAS 2.0 Regulation's implementing acts, every member state must offer at least one certified EUDI Wallet, and — critically — all public-sector bodies across the EU must be able to accept it by the end of 2026. Private-sector obligations for regulated industries (banking, telecom, energy, transport, healthcare) follow a year later, in 2027. That is a genuinely tight runway: RIA only launched the procurement in May 2026, meaning Estonia is contracting a build-and-operate partner roughly six months before its own government is legally required to accept the finished product.
Not a Cold Start
Estonia's advantage is that it isn't building identity infrastructure from scratch — it's re-platforming one that has run since 2002. The country's X-Road data-exchange layer, its Mobile-ID and Smart-ID authentication tools, and the 2025-launched Eesti app already give citizens control over who accesses their data and when. RIA has also been piloting cross-border wallet functionality since at least early 2026 through the EU-funded POTENTIAL Consortium, testing a mobile driving licence with support from the Transport Administration and firms like Bolt, alongside starting parallel development of the Estonian EUDI Wallet itself. Where several member states are essentially standing up a new eID system to meet the 2026 mandate, Estonia is asking a vendor to extend an existing one.
The Case for the Mandate
Brussels' push deserves a fair hearing before any criticism. Europe's digital identity landscape today is a genuine mess of incompatible national schemes, private logins (Google, Facebook, banks' own ID apps), and no common way to prove you are who you say you are across a border. That fragmentation is a real tax on cross-border commerce, education mobility, and public-service access — a Portuguese student can't easily use a national eID to enrol at a German university, and a small business can't sign a contract across borders without separate verification each time. A single, interoperable, EU-recognized wallet — one that is opt-in, free for citizens, and built to a common technical standard rather than owned by a single Big Tech platform — is a legitimate public good. Estonia itself is proof that state-run digital identity, done well, can be trusted infrastructure rather than a surveillance risk: two decades of the digi-ID system show citizens will use government identity tools at scale when the tools are transparent about data access and genuinely useful.
Where Proportionality Should Bite
The legitimate goal doesn't fully justify the execution. Setting a single EU-wide hard deadline for public-sector acceptance — with no visible mechanism for states that are behind — invites exactly the compressed, high-risk procurement RIA is now running: an eight-year, single-lot, no-divided-lots contract awarded via competitive dialogue in roughly seven months, covering a system that has to work not just domestically but across the entire European Economic Area on day one. Estonia's RIA explicitly cited 'technical and security interdependencies' as the reason it declined to split the contract into lots — a reasonable engineering call, but one that concentrates delivery risk in a single vendor relationship with limited room for course correction before the 2026 mandate lands. States without Estonia's eID head start face the same deadline with none of the existing plumbing — a mismatch the regulation doesn't obviously account for.
Why e-Residency Raises the Stakes
This isn't only a domestic IT refresh. Estonia's e-Residency program has issued digital identities to more than 142,000 people across roughly 180 countries, who use the digi-ID to run over 43,000 Estonian companies remotely — signing documents, filing taxes, and authenticating into EU-recognized services from outside the EU entirely. Any migration bug, certification delay, or vendor failure in the EUDI Wallet build doesn't just inconvenience Estonian residents; it disrupts a global base of non-resident digital-ID holders who chose Estonia specifically because its identity infrastructure was reliable. RIA's public wallet page is careful to note the EUDI Wallet won't retire existing eID tools outright, which is the right call — a hard cutover for a live population this large, on an EU-mandated clock, would be an unforced error.
The Real Test Is Delivery, Not Design
The EUDI Wallet is the right policy instrument for the problem it targets: interoperable, sovereign, opt-in digital identity instead of fragmented national logins or dependence on platform ID. Estonia is the best-positioned member state to hit the 2026 deadline precisely because it treated digital identity as core infrastructure twenty years before Brussels made it a regulation. The open question is whether an eight-month, single-vendor procurement can absorb the technical risk of a first-of-its-kind, EU-wide interoperable system without slipping — and whether Brussels has a real contingency for the member states that, unlike Estonia, will not make it across the line by December.