Estonia Estonia X-Road digital infrastructure

Estonia's EU-Mandated SIM Swap Revives a Mobile-ID Service the State Already Tried to Retire

RIA's deadline forces 220,000+ Mobile-ID users to swap SIM cards by May 2027 under amended eIDAS rules, patching a legacy system Estonia tried to scrap in 2022.

Estonia's Mobile-ID Compliance Squeeze People of Internet Research · Estonia 220,000+ Mobile-ID Users Affected Estonians who must replace SIM car… May 19, 2027 SIM Replacement Deadline RIA-set date after which unreplace… 2.5x Smart-ID's 2022 User Lead Smart-ID already had 2.5x more use… 3,000+ X-Road Connected Services Digital services running on Estoni… peopleofinternet.com
Estonia's Mobile-ID Compliance Squeeze People of Internet Research · Estonia 220,000+ Mobile-ID Users Affected May 19, 2027 SIM Replacement Deadline 2.5x Smart-ID's 2022 User Lead 3,000+ X-Road Connected Services peopleofinternet.com

Key Takeaways

Estonia's Information System Authority (RIA) announced on August 6, 2026 that everyone still using Mobile-ID — a digital-signature and login service tied to a special SIM card — must get a new SIM before May 19, 2027 or lose access entirely. RIA says the change is required by amendments to the EU's eIDAS Regulation, which "entered into force in 2024" and impose updated compliance requirements on trust services like Mobile-ID (RIA). More than 220,000 Estonians are affected.

The Steelman: Harmonized Trust Services Are the Point of eIDAS

The EU's case for tightening trust-service rules is not frivolous. Regulation (EU) 2024/1183, adopted in April 2024, rebuilt the eIDAS framework around the European Digital Identity Wallet and imposed stricter conformity requirements on qualified trust services — certificate issuance, signature creation, and the cryptographic devices behind them (EUR-Lex). Estonia's entire e-governance model runs on the assumption that a digital signature is exactly as legally binding as a handwritten one, cross-border, without a notary in the loop. That guarantee only holds if every national trust-service provider — including whichever telco issues a Mobile-ID SIM — meets a common, currently-verified security bar. If Brussels lets national providers coast on hardware certified under a decade-old standard, the entire premise of mutual recognition across 27 member states erodes quietly, one uninspected SIM at a time. A mandatory refresh cycle, however disruptive, is how a currency of trust stays a currency.

The Legacy System Estonia Already Tried to Kill

What makes this deadline notable is not the compliance logic — it's the target. Mobile-ID is not a thriving product RIA is future-proofing; it is a service the state tried to walk away from five years ago. In 2021, RIA ran a tender to replace Mobile-ID with a non-SIM-based alternative, aiming to go live by mid-2022. The incumbent provider, SK ID Solutions, declined to bid, arguing the technical requirements were unreasonable — and pointed out that it had already built the answer itself: Smart-ID, a software-only identity app that needs no special hardware at all. At the time, Smart-ID had 610,034 users against Mobile-ID's 251,668 — already 2.5 times the adoption (ERR News). RIA's own account of that failed tender says it "drew a blank" on alternatives and simply kept extending the legacy contract.

Five years on, Mobile-ID has shrunk to roughly 220,000 users while Smart-ID has grown further, and instead of a managed sunset, RIA is now spending 2026-27 orchestrating a nationwide SIM-swap logistics exercise for a service that was already the minority option when the state first tried to retire it.

Proportionality, Not Principle, Is the Real Question

This is where the pro-innovation case gets specific: the objection isn't to eIDAS harmonization itself, it's to spending scarce regulatory and operator capacity hardening a shrinking legacy rail instead of accelerating migration to the software-based alternative that already serves most Estonians and imposes zero SIM-swap cost. RIA's own advisory acknowledges the operational externality of this approach: it separately warns that the transition period creates a fraud window, with scammers likely to impersonate mobile operators and phish for PINs during the swap (RIA) — a security risk generated by the compliance exercise meant to reduce security risk.

Why This Matters Beyond One SIM Card

Estonia's eID system isn't cosmetic — it's the authentication layer sitting in front of X-Road, the data-exchange backbone connecting more than 3,000 digital services across government and industry (e-Estonia). Every login and every signed transaction through that pipeline depends on a trust service being both secure and cheap enough to maintain at scale. When a shrinking legacy credential absorbs disproportionate compliance attention relative to its user base, it's a tax on the digital-government model other countries look to Estonia to prove out.

What Should Happen Instead

RIA says usage "principles" won't change for the user — you'll still tap a PIN and sign. But the smarter compliance path was signaled by Estonia's own 2021 tender: fold this deadline into an active migration campaign toward Smart-ID or the incoming EU Digital Identity Wallet, rather than spending operator and RIA bandwidth re-certifying hardware for a service the state has spent five years trying to exit. Proportionate regulation means matching enforcement effort to where the users — and the risk — actually are.

Key Takeaways

Sources & Citations

  1. RIA: Mobile-ID users will need to replace their SIM cards
  2. Regulation (EU) 2024/1183 (EUR-Lex)
  3. ERR News: No solution for Mobile-ID continuation
  4. ERR News: State hoping to introduce new solution to replace Mobile ID
  5. e-Estonia: X-Road