EUDI/BundID-Readiness
EUDI/BundID Readiness
With eIDAS 2.0, digital identity is becoming a mandatory requirement: By the end of 2026, each EU Member State must generally provide at least one EUDI Wallet. Public-sector bodies must accept it for online services that require electronic identification and authentication. Germany plans to launch its wallet on January 2, 2027 . From the end of 2027, the acceptance obligation will also apply to private companies under certain conditions.
This raises two essential questions for every organization operating applications: How can BundID (“DeutschlandID”) and the EUDI Wallet be integrated in a technically robust manner? And how can organizations subsequently authorize, at a granular level, which users may access which functions and data at which level of assurance? Authentication is only half the equation. The real architectural challenge lies in authorizing access to applications and APIs.
This statement of work combines a compact readiness assessment with an intensive architecture workshop and delivers a decision-making basis, including a blueprint, within two weeks. The blueprint builds on architectures that umbrella.associates has already implemented successfully, including in the context of federal IT cooperation.
Scope of Services:
Preparation (Week 1, Days 1–3)
At the outset, the relevant information is collected using a structured questionnaire, and the documents provided are reviewed. Particular attention is given to the existing applications and online services, current authentication methods such as BundID integrations or proprietary identity providers, and the existing authorization architecture. Planned initiatives are also included in the analysis.
Workshop Day 1 (Week 1, Day 4)
The next step is to explain the legal and technical foundations of eIDAS 2.0 and the EUDI Wallet, including the relevant deadlines. The different levels of assurance and the role of electronic attestations of attributes are also addressed. For each application, an assessment is then made as to whether integration via BundID or direct integration of the EUDI Wallet is the more appropriate option. Finally, the applications are prioritized according to legal obligations, practical benefits, and the anticipated implementation effort.
Workshop Day 2 (Week 1, Day 5)
A target architecture for authorization is then developed. This includes a suitable role and attribute model as well as granular control over access to APIs, data, and individual functions within the applications. It also defines how policies can be managed centrally and enforced technically.
The target architecture takes into account the interaction with existing components and established standards such as OAuth 2.1 and OpenID Connect, as well as policy-based authorization approaches. Requirements relating to operations, data sovereignty, and digital sovereignty are also incorporated. European solution options such as cidaas are considered as part of this process.
Development (Week 2)
During the second week, the results are consolidated into a blueprint, a readiness assessment, and a prioritized roadmap. The project concludes with a remote presentation of the results to the decision-making level and the architecture team.
Project Deliverables
At the end of the project, you will receive:
- A readiness assessment for each application reviewed, including the actions required for the deadlines at the end of 2026, in January 2027, and at the end of 2027.
- An architecture blueprint for authentication and granular authorization, including a component view and interfaces.
- A decision paper on the preferred integration approach—BundID or direct EUDI Wallet integration—including an assessment of effort, risk, and long-term viability.
- A roadmap and management slides containing milestones, dependencies, and indicative effort estimates.
Are you wondering whether your organization is already EUDI/BundID-ready? Let us find out together.