Table of contents:
The keyboard had barely cooled down after the latest changes made to the revised edition of this article, when the Minister of Economy, Digitalization, Entrepreneurship and Tourism came out with a statement that sets the frame perfectly:
"We can propose anything in our digitalization strategies, but if we do not answer the question of with whom we are going to carry out this digital transformation, it will not happen."
The elephant in the room: last week’s cyberattack on the IT systems of the National Agency for Cadastre and Land Registration (ANCPI), the cloning of the ghișeul.ro website, and the attack on the Private Beneficiaries Procurement application of the Ministry of Investments and European Projects (MIPE).
A week after the attack, all of ANCPI’s IT systems remain unavailable, and the institution assures the public that the data has not been compromised and that services will be resumed gradually. Speaking on Radio România Actualități, the director of the National Cyber Security Directorate (DNSC), Dan Cîmpean, states that the presumed perpetrators, the ByteToBreach group, are financially motivated actors, active for approximately one year, who cause damage, encrypt or delete databases, and then demand ransoms.
Beyond the chronology of the incident, the DNSC director’s statements outline the theme of this article: the internal capacity of the state. Dan Cîmpean explained that attackers usually exploit a succession of vulnerabilities (compromised credentials, weak passwords, outdated software), which the Directorate flags daily through alerts, but which it cannot remedy because DNSC does not have access to institutions’ systems. Direct responsibility for administration therefore falls to each institution individually and, although the Directorate detects between 20,000 and 50,000 events representing potential attacks every day, the defense, Cîmpean says, “is a marathon,” a constant effort that the specialists of each entity must undertake.
Security depends on the people and teams within each institution who administer and operate the systems, and where the state does not have these people (for various reasons; because it cannot recruit, pay, or retain them), the vulnerability is evident.
The question “how, and with whom, do we carry out digitalization?” has several angles, beyond the cybersecurity aspect mentioned above, and becomes all the more pressing given that the immediate agenda includes perhaps the most ambitious and most sensitive project that Romania is obligated to deliver: the European digital identity wallet, a project that will bring together in a single application the identity and other official attributes of citizens, exactly the type of system that we cannot afford to build and operate without competent and responsible people.
The electronic wallet ecosystem is designed as a system of checks and balances across multiple layers. We review, by way of example:
- mandatory prior certification
- cryptographic protection of identity
- verification and authorization of relying parties
- continuous oversight and incident transparency
- and, probably the strongest element: a mechanism for withdrawal from circulation
If a wallet is compromised or ceases to meet security requirements, the Member State is required to suspend its provision and use without delay, to inform the affected users, the other Member States and the Commission, and if the breach is not remedied within the period set out by the regulation, the wallet is withdrawn from the market and its certification revoked.
On Friday, 17 July, at an official meeting organized by the Government of Romania on the topic of the EUDI wallet, we learned that the project will be carried out, in its first phase, exclusively with resources allocated by each institution and without conducting public procurement, taking into account the mapping of human resource and infrastructure needs. Support for implementation will come from the European Commission, through the NiScy team, to adapt the German solution for Romania, and from ENISA for developing the certification scheme.
It was mentioned that this is a highly technical project, including from a regulatory standpoint, a framework that is under development and changes recurrently (the implementing acts will be revised annually, for example). With whom exactly will we adapt and ensure the relevance of the national wallet?
This is a topic we addressed in depth in a piece published last week, anticipating that the project would start without dedicated human resources.
In order to build digital transformation projects that are secure, sustainable, and relevant to citizens, the state must develop its internal capacity and its ability to collaborate with the private sector in ways that allow it to keep, within its own walls, the core expertise, that nucleus of people able to define what is being built and why, to critically assess what it receives from vendors, to operate and ensure the security of systems once delivered, and to accumulate, from one project to the next, the institutional memory without which every digitalization effort always starts from scratch.
Next, we turn to the EUDI wallet: what this wallet is, what citizens’ expectations are regarding it, and what stands between us and benefiting from everything such an instrument can offer.
What is the electronic digital identity wallet?
“An application containing all my personal documents (ID card, driver’s license, diplomas, medical history, etc.) that I could use in my dealings with institutions or the private sector,” that is, precisely an electronic wallet of the kind represented by the European digital identity wallet, is the priority that Romanians (53.7%) identified in terms of digitalization, in March 2026.
In June 2026, although the percentage had dropped, the electronic wallet remained at the top of these identified priorities.
Few European digital policy projects have been prepared with as much thoroughness as the European digital identity wallet, which every Member State must make available free of charge to its citizens and residents by the end of 2026, under the eIDAS 2 Regulation. The Regulation comes with lessons learned after eIDAS 1 failed to fully realize its potential, but it preserves the same objective: that all citizens and residents of the Union should be able to prove who they are, securely, in the online environment as well. Romania, unlike other states, does not yet have such a national solution, but the good news is that the requirements imposed at the European level are new, so even states with mature national solutions will have to substantially adapt their wallets (as is the case with Poland, which is developing, in parallel with the existing wallet it has been working on for more than 10 years, a wallet that meets the requirements of EUDI wallets, with the transition to the latter to take place gradually). So Romania can still catch the train.
In theory, the EUDI wallet is an application that contains a person’s identity and official documents in electronic format, through which they can present them to public institutions or private actors.
Four principles distinguish it from a simple photographic reproduction of the identity document:
Its use is voluntary, no one can be compelled to resort to it, nor discriminated against for refusing to do so.
The selective disclosure mechanism allows the holder to prove a single attribute, such as "having reached the age of eighteen," without disclosing either their name, personal numeric code, or address; it is practically a kind of revolution of current practice, in which a photocopy of the ID card exposes the entirety of one's personal data for the need to prove a single fact.
The wallet includes a qualified electronic signature, legally equivalent to a handwritten signature and free of charge for natural persons for non-professional purposes.
Beyond identification data, the list of attributes that can be stored in the wallet is very long and can include both attributes from the state (e.g. a driving license) and from private parties (e.g. a loyalty card).
The wallet's usefulness can be divided into 2 main categories (non-exhaustive list):
Authentication and presentation of attributes
A single solution for authentication across all state platforms and, starting at the end of 2027, those of private actors in sectors subject to strong authentication requirements, such as banks and telecommunications operators, as well as major online platforms. Do you need to prove that you are over 18 and that you have a loyalty card in order to buy alcohol online and get a discount? It is enough to select these two attributes directly from the wallet.
Presentation in physical interactions, without having to carry around the documents and the folder full of papers.
A traffic stop where you need to present your ID and driving license, but you don't have them on you? You can present both documents directly from the electronic wallet application on your phone, with the same legal value as the physical documents.
Compared to the previous eIDAS Regulation, the novelty of eIDAS 2 was the shift toward piloting and technical support for Member States, through the organization of pilot projects and the development of the technical reference architecture framework for wallets, alongside the reference implementation of the EUDI wallet, which is based on a modular architecture and contains reusable components developed in incremental steps that can be reused across multiple projects.
The EUDI wallet is that point of no return in the digitalization of the state. One of the excuses used so far for only partially digitalizing certain flows has been precisely the lack of an electronic identity solution with a high level of assurance (ROeID having the substantial level of assurance, hence ANAF’s refusal to integrate the solution as an authentication method in its systems). These assessments essentially indicate the degree of certainty regarding the user’s identity. In other words, I, as an institution, cannot commit to eliminating your visit to the counter (whose purpose is to ensure that you are indeed the person requesting a given service), because I cannot be sure that you are who you say you are. The EUDI wallet resolves this issue, since the solution’s level of assurance is high and the obligation of institutions to integrate and accept it is codified in the regulation. So, a single solution, not separate accounts for each state platform, and no excuse for not digitalizing flows end to end.
We therefore examine what exactly European citizens expect from electronic wallets and how Romania can avoid missing the opportunity to implement it.
Citizens' expectations
According to a Eurobarometer survey, 63% of citizens of the Union want a single, secure digital identification solution for online services, while 72% want to know how their personal data is being processed. The IATA Global Passenger Survey conducted in 2025 confirms this trend: 78% want to have, in the same solution, a digital wallet, passport, and loyalty cards in order to book, pay, and go through various procedures at the airport.
2,800 citizens from all Member States took part in a recent study that revealed different priorities for the use of the EUDI wallet. The 41 possible uses of the wallet received scores relative to an average of 100: a score of 200 means twice as important as the average, one of 50 means half.
Five uses clearly stood out, and three of them relate to health:
Each group evidently has its own priorities, although health dominates everywhere.
Students put access to important documents, such as their school record (194), first, even ahead of the health insurance card. Business people value, alongside health and the electronic signature, opening a bank account in another EU country and paying through the wallet. For those over 50, registering passport data and filing tax returns become equally important.
Expats, those who live and work in another EU country, particularly value opening a cross-border bank account and electronic prescriptions, thus reflecting the concrete challenges of life away from one's home country.
Frequent travelers predictably emphasize paying through the wallet and registering passport data, alongside the ever-present medical component.
Retirees are the only segment in which some functions exceed a score of 200: accessing the medical record reaches 256, and the insurance card and electronic prescriptions also pass 240. For them, a specific need also appears: proof of retiree status or disability (214).
The message from citizens is fairly clear and maps out priorities by segment, since the sample is not statistically representative of the EU population, and some uses are simply less relevant to certain groups (for example, a retiree will not be enrolling in university).
Public debate about the European wallet often slides toward its cross-border dimension. Yet national examples show that the most frequent use cases are, above all, domestic ones. The wallet replaces, before anything else, the original and copy of the identity document required at any counter, at the bank, at the notary, with the telecommunications operator, or when signing an employment contract, with the legal entity receiving only the necessary data, attested by the state. It then offers, as already mentioned, a single authentication method across the entire range of digital public services, allows proof of age without revealing other data when purchasing age-restricted products or accessing online platforms; it puts official documents within everyone’s reach, including in the absence of signal, following the Italian model; and it turns the free qualified signature into a tool for everyday transactions, from rental contracts to powers of attorney between private individuals.
What stands between us and the opportunities of an identity wallet?
From an almost-empty new app that we could barely use anywhere … not much. From a well-implemented and genuinely useful identity wallet? Less than one might think at the technical level, and more than we would like at the organizational level.
The starting point is a European obligation, as already mentioned, one that can come bundled with sanctions and reputational consequences. Romania does not yet have an operational wallet, although important steps were taken on the governance side in the first half of the year. Through Prime Minister’s Decision No. 183/2026, of 12 May 2026, the RO EUDIW Committee was established, an interinstitutional advisory body chaired by one of Romania’s deputy prime ministers, with the Ministry of Economy, Digitalization, Entrepreneurship and Tourism (MEDAT) and the Ministry of Internal Affairs (MAI) as permanent members, with the participation of the Special Telecommunications Service (STS). By its nature, it is a space for consensus in which decisions are not binding unless subsequently codified into primary or secondary legislation.
In June 2026, through a press release yet to be transposed into legislation, the Government also allocated the main roles within the ecosystem’s architecture. MEDAT becomes the supervisory authority and single point of contact for cross-border cooperation. MAI is the provider of the mobile application (RO Wallet) and of the backend infrastructure, issues the person identification data (PID), and supplies the age-verification attestations. STS holds four technical roles: access certification authority, provider of registration certificates, administrator of the relying-party register, and provider of the attestation scheme.
The allocation, however, also has notable gaps: for the moment, no role is listed for RENAR (the national accreditation body), for the Authority for the Digitalization of Romania (ADR, which remains the supervisory authority for qualified trust service providers), for the National Cyber Security Directorate (DNSC, the natural author of the national certification scheme), or for the National Authority for the Supervision of Personal Data Processing (ANSPDCP, a potentially implicit role for personal data protection, but one that would deserve to be made explicit).
Establishment of the RO EUDIW Committee
Decision No. 183/2026 (12 May) creates an advisory body (a space for consensus) led by a deputy prime minister.
Allocation of the Main Roles
The key roles within the RO Wallet ecosystem were divided as follows:
Institutions without a defined role for now
For the moment, key entities are not featured in the architecture, such as:
On the technical side, Romania has chosen to adopt and implement the German EUDI wallet solution, developed as open source. The argument is solid as a reuse-first strategy: free access to the source code, to the certification schemes, and to reusable components, without the cost of building from scratch. Nor, for that matter, are we starting from zero when it comes to certain solutions that can underpin the wallet: since June 2025, the national issuance of electronic identity cards has begun (over 1.5 million issued within a year), and since December 2025 MAI has launched eIDentity, the dematerialized version of the identity card, which allows selective disclosure and data sharing through a QR code valid for ten minutes. Both are, however, heavily underused, precisely because of the lack of integration with public and private services, a warning worth keeping in mind.
Adopting the German solution reduces the initial cost, but it does not reduce the internal capacity the state needs: someone still has to integrate the wallet solution, operate it at production scale, and maintain it over time.
The aforementioned meeting on the topic of the wallet, the second in the series of meetings with private actors and civil society on this subject, brought additional information:
publication of wallet documentation on GitHub + information website + definition of UI/UX
testing of the first version of the wallet + interoperability testing sandbox + cross-border interoperability tests
launch of a beta version for a limited group of users + certification aspiration (the chances of this happening are close to 0)
official wallet launch
We have a roadmap, we have an announcement that there will be an opening for private wallets one year after the launch of the national wallet, as well as an opening for integrating private attributes into the national wallet, and also a legislative framework that is due to be put out for public consultation (“transparență decizională”) in August.
As mentioned in the introduction, the longer we delay addressing the issue of human resources within the Government (at the very least, acknowledging that we have an acute shortage of specialized human resources), the harder it will become, and we will also lose the potential transfer of expertise from teams such as NiScy, who will support the initial development. What do we do once this support ends?
The main risk is not occupying yet another embarrassing spot in a ranking (something we seem accustomed and resigned to), but the lack of adoption, that is, solutions that exist but are not used. Or usable. Not to mention the security aspect, which is evident in light of recent events.
The Eurostat data for 2025 is telling: only just over 10% of Romanians have used an eID solution for personal purposes (even though the ROeID solution was available at the time the data was collected) and barely 1.58% to access public sector services. Romania repeatedly ranks last in the EU on the use of e-government services in the Digital Decade indicator, with a score of about one-third of the European average.
of Romanians used an eID solution for personal purposes in 2025
used eID to access public sector services
The diagnosis of digitalization has repeated itself word for word for almost a decade, from the OECD’s Public Governance Scan of 2016 to the 2023 assessment and the report produced by Digital Nation and Edge Institute in 2025, or the European Commission’s annual reports: fragmented mandates, lacking coordination, diffuse responsibility. The cases of the electronic identity card, eIDentity, ROeID, or even more mature solutions such as ghiseul.ro (a reasonable estimate of the number of users would be around 15% of the adult population) show that Romania can produce digital solutions that nevertheless end up unused or underused.
Repeating the same pattern with the EUDI wallet would most likely produce the same result, at a higher financial and opportunity cost.
We can treat this obligation under eIDAS 2 as a mere compliance requirement, or we can set a more ambitious goal, the only one that indicates the success of such a project: a wallet that millions of Romanians actually use. The target for the wallet must be of a different order of magnitude, far more ambitious than what we have now, such as 5 million Romanians who frequently use the wallet within the first 5 years. Absent such ambition, embraced and measured, “success” will once again be reduced to “we delivered something on time.”
What stands between us and these opportunities is, therefore, the capacity to deliver. The central recommendation of the Edge Institute report is the establishment of a dedicated task force for the EUDI wallet, placed at the center of government, in proximity to the deputy prime minister responsible for state modernization, and built on the foundation of the already existing RO EUDIW Committee.
The distinctive feature of the proposal is that it brings together, under the same umbrella and with a single point of responsibility, the technical delivery and the strategic dimension, instead of splitting them between institutions. In the short term, the structure would itself take on the function of Wallet Provider, assuming responsibility for the product’s development and roadmap; over time, it would have the potential to evolve into a permanent structure for delivering government digital solutions, one that would take on responsibility for other programs before anchoring a reformed Authority for the Digitalization of Romania placed at the center of government.
To function, it needs a legal basis (its mandate and reporting line fixed in the law implementing eIDAS 2), a stable multi-year budget line (which can be supplemented with European funds, for instance by adjusting the project financed through POCIDIF), and flexibility in recruitment.
This task force is, therefore, divided into two teams.
The technical team delivers and operates the wallet: leadership and architecture, backend and credential issuance, identity verification and the hardware cryptographic component, mobile development, and a testing-certification function.
The strategic team ensures adoption and relevance: it integrates ministries as attribute providers, brings in private actors as relying parties and attestation providers, tracks the evolving regulatory framework and the relationship with the European Commission, and, last but not least, turns usage data into roadmap decisions.
That this is the right solution is confirmed by the comparative experience of several countries, with France, Poland, and Sweden being just three of these examples.
Poland has been sustaining, for almost a decade, an internal team that has grown to 70 people, organized into five teams, serving around 11 million users and 2 million daily authentications, and it is now preparing a two-track migration toward the eIDAS 2-compliant version.
Sweden recently began building the DIGG team (January 2025) with just two part-time employees and has grown to 36–40 people, building institutional capacity before scaling delivery.
Yes, a technical and strategic team needs consistent resources and funding, but we will not make it through without ambitious measures. To be clear: the wallet is, literally, a wallet. An empty application that only gains value once you populate it, once you fill it with digital attestations: the equivalent of certificates, diplomas, licenses.
Besides authentication, the wallet can also address digitization and digitalization.
In order to place attributes in your wallet, institutions will have to do two things they keep postponing. First, to digitize, that is, to convert into digital format the documents they currently keep on paper. Then, and more importantly, in order to generate attributes directly in digital format, they will need to digitalize their processes. The wallet is therefore healthy pressure on the state to finally put its procedures in order.
And in the end, the wallet is a bridge. A bridge between the citizen and the other shore, where the state and the private sector await, because the idea is for the two of them to work together, for the citizen’s benefit, on strengthening that same bridge, rather than each building 10 different bridges of their own that never meet, leaving the citizen to travel back and forth between the two shores hundreds of times.
The wallet that Romania must deliver can be built. Whether it will reach millions of real users in the short term, not hundreds of thousands, whether it will be trustworthy, secure, sustainable, and useful, however, depends on the internal capacity that the state chooses to build around it, both technical and strategic. This is, in the end, the only real distance between us and the wallet's opportunities.
Back to:
Descoperă mai mult
de la Edge Institute
Trimitem saptamanal articole, idei, rapoarte si studii despre digitalizarea României
Folosim platforma Beehiiv pentru trimiterea newsletterelor. Prin abonare, confirmi că accepți Termenii și Politica de confidențialitate Beehiiv.