A mandate aimed at the state, not the citizen
On July 23, 2026, Italy's Official Gazette published Serie Generale n. 169, carrying a June 17, 2026 decree from the Department for Digital Transformation that formally launches the IT-Wallet System. The decree implements Article 64-quater of the Digital Administration Code (CAD), a provision introduced by decree-law 19/2024 and converted into Law 56/2024. What makes this rollout notable is where the compulsion sits: every public administration, public-service manager, and publicly controlled company must register as an "authentic source" — a certified issuer of digital credentials such as degrees, licenses, or ISEE income status — within twelve months, by August 3, 2027. Citizens face no such deadline. Wallet adoption for individuals stays voluntary, opening for registration from August 3, 2026, alongside the continued validity of physical documents.
The case for compelling government first
There is a real argument for this design, and it deserves stating plainly before critiquing it. Italy's prior digital-identity rollouts — SPID in particular — stumbled for years because adoption on both sides of the transaction was optional, leaving citizens holding a digital identity that half of government offices still couldn't accept. Forcing supply-side participation while leaving demand-side adoption voluntary is a defensible sequencing fix: it guarantees that once a citizen chooses to use IT-Wallet, the credential will actually be recognized everywhere in the public sector, rather than working at some counters and not others. The Garante per la Protezione dei Dati Personali, Italy's privacy authority, gave a conditional favorable opinion on the underlying decree schemes, but only after extracting commitments: a subsequent Department decree must define technical and organizational safeguards following a data protection impact assessment, wallet providers and credential issuers must maintain strict logical separation between IT-Wallet data and other service data to prevent profiling, and the Department had to report back on rollout details by March 31, 2026. That is a regulator doing its job — conditioning a mandate on privacy engineering rather than either rubber-stamping it or blocking it outright.
Where the design still cuts corners
The steelman only goes so far. A twelve-month compliance clock for "every local authority and public administration" is not calibrated to Italy's actual administrative landscape, which includes thousands of small comuni with minimal IT staff alongside INPS, the Ministry of Transport, and other large national bodies. The Department for Digital Transformation's own project page describes large national institutions — MIT, MEF, INPS — as the entities "sharing information" so far; it does not yet describe how a small municipality with no dedicated technical staff is expected to stand up authentic-source registration by the same date as a national ministry. Nothing in the published guidance that we could verify specifies implementation funding, technical assistance, or a graduated timeline for smaller bodies. A mandate with a hard date and no differentiated support risks the same outcome regulators elsewhere have produced when they impose uniform compliance costs on entities of wildly different capacity: the well-resourced comply on schedule, and the rest either miss the deadline with no real consequence or divert scarce staff time from services residents actually use day to day.
The second gap is enforcement and transparency. Public reporting so far — including Il Sole 24 Ore's coverage of the gazette publication — describes the August 3, 2027 deadline and a related February 3, 2028 date by which the State Printing Works (IPZS) must be issuing electronic certificates tied to CIE identity verification, but nothing we could confirm addresses what happens to a public body that simply misses the window. Without a published penalty structure or an interim compliance dashboard, "mandatory" risks becoming aspirational for the parts of government least equipped to meet it — precisely the entities whose non-compliance would matter most to a resident trying to pull a digital ISEE certificate from their town hall.
The right instinct, executed too thinly
Italy deserves credit for sequencing this mandate correctly — government first, citizens by choice — and for building it inside the EU's eIDAS 2.0 framework rather than as a parallel national scheme, which should ease interoperability as the EU Digital Identity Wallet regulation comes online across member states. The Garante's conditional sign-off, with its data-minimization and separation requirements, is the kind of proportionate check that should accompany any state identity infrastructure, not an obstacle to route around. But proportionate regulation cuts both ways: imposing a uniform national deadline on administrative bodies with radically different capacity, without publishing funding, technical support, or consequences for non-compliance, converts a well-designed policy into an unfunded mandate that a meaningful share of local government will likely miss. The Department for Digital Transformation should publish an implementation-support plan and an interim compliance tracker before August 2027 arrives — otherwise the citizens this mandate is meant to eventually serve will find that "authentic sources" are authentic in name only at the town-hall level where they need them most.