Expert View 4 min read

How Ukraine adapts to new eIDAS 2.0 electronic signature standards

Starting in 2026, the European eIDAS 2.0 regulation will fundamentally transform approaches to digital identification and electronic trust services, posing new challenges for Ukrainian...

Starting from 2024, the European Union has launched a new phase of digital identity development through the updated eIDAS 2.0 regulation (EU 2024/1183). Its practical implementation will proceed in stages until 2026–2027 and is already setting new requirements for IT systems that handle electronic identification and trust services.

For Ukrainian companies, this means not just regulatory changes, but the necessity of strategic adaptation to the standards of the EU single digital market. In this context, electronic signature within the eIDAS framework becomes a key tool for ensuring legally binding cross-border interaction. At the same time, its full recognition in the EU depends on technical and regulatory interoperability, as well as international agreements between Ukraine and the European Union.

eIDAS 2.0: a new level of digital identification

The basic 2014 eIDAS regulation laid the foundation for electronic identification and trust services in the EU, ensuring mutual recognition between member states. However, it was primarily focused on government services and did not account for modern scenarios of digital identity usage in business and mobile ecosystems.

The updated eIDAS 2.0 addresses these limitations. Its central element is the EU Digital Identity Wallet — a digital wallet that allows users to store and transmit verified attributes: documents, certificates, access rights, and other data.

This signifies a transition from an "identification as a service" model to an "identity as a platform" model, where the user controls their data, and businesses receive a standardized mechanism for verifying it.

The regulation also clarifies requirements for trust services, including qualified electronic signatures, seals, time stamps, and delivery services. The main focus is not on changing cryptography, but on increasing the level of trust, security, and mutual interoperability of systems.

Ukraine and eIDAS 2.0: current status and challenges

Ukrainian legislation in the field of electronic trust services is already largely harmonized with eIDAS 1.0. However, the transition to eIDAS 2.0 requires deeper integration — both at the regulatory level and at the level of technical implementation.

The key challenge is not just compliance with standards, but achieving mutual recognition. This requires:

  • compliance of Ukrainian trust service providers (QTSP) with EU requirements;
  • integration into the European Union Trusted Lists (EUTL);
  • conclusion of international agreements on mutual recognition.

Without these conditions, the Ukrainian electronic signature may be technically compatible but will lack automatic legal force in the EU.

QES in the context of eIDAS: what really matters

The Qualified Electronic Signature (QES) remains a key element of trust services. It is based on a qualified certificate and ensures the legal validity of documents.

For operations in the European context, it is important not only to use QES but to ensure:

  • compliance with formats (XAdES, CAdES, PAdES);
  • support for signature verification in cross-border scenarios;
  • integration with European trust services.

It is interoperability, rather than the mere fact of using QES, that becomes a critical factor for business.

What will change for business and IT systems

eIDAS 2.0 affects not only the electronic signature but the entire architecture of digital services. Specifically:

  • support for digital attributes and wallet integrations is required;
  • approaches to user identification are changing;
  • requirements for security and auditing are increasing;
  • the need to work with European trust infrastructures is emerging.

This means that adaptation is not just an update to a signature module, but a revision of the entire logic of identity management.

Conclusion: this is not compliance, but strategy

eIDAS 2.0 is not just another regulatory requirement. It is an infrastructural change that is shaping the new EU digital economy.

Companies that begin adaptation now will gain access to the single market for digital services. Those who ignore these changes risk being left outside this ecosystem.