Skip to content
All writing

European eID: 32 notified schemes, and which ones a SaaS can actually use

· last verified · 7 min read

If you have looked into letting European users sign in with their national electronic identity, you have probably formed one of two impressions: that there are a handful of these schemes, or that eIDAS means any EU citizen can use theirs anywhere. Both are wrong, and the second one is wrong in a way that will waste a quarter of your engineering year if you build on it.

This is the map we assembled before committing to build eID support. Every figure below comes from a primary source — the Commission’s own register, the regulation text, or the scheme operator’s own pricing page — and each carries the date we checked it.

There are 32 notified schemes, not six

32
electronic identity schemes formally notified under eIDAS, across 26 countries, as listed in the European Commission’s own register. The country count is our tally of the register’s rows.
European Commission — notified eID schemes register · source · verified 2026-07-30

The register covers the obvious ones — Germany’s eID, Italy’s SPID and CIE, Denmark’s MitID, Belgium’s itsme, Sweden’s BankID, Estonia’s ID-card — and a long tail most integration guides never mention: Portugal’s Chave Móvel Digital and Cartão de Cidadão, ID Austria, Croatia’s NIAS, Czechia’s mojeID, Bulgaria’s Evrotrust, Norway’s Buypass, Slovenia’s eID card, and the Polish, Latvian, Lithuanian, Slovak, Maltese, Cypriot, Luxembourgish and Romanian schemes.

Four EU/EEA countries have notified nothing: Ireland, Greece, Hungary and Iceland. All four have working national identity systems; none has gone through notification. Switzerland cannot notify at all, being outside the EU and EEA — and its federal E-ID was postponed on 30 June 2026, with the trust infrastructure now expected in the first half of 2027.

The trap: “notified” does not mean “available to you”

This is the single most expensive misunderstanding in the category, and the regulation is unambiguous about it. eIDAS mutual recognition binds public sector bodies only:

When an electronic identification using an electronic identification means and authentication is required under national law or by administrative practice to access a service provided by a public sector body online in one Member State, the electronic identification means issued in another Member State shall be recognised…
Regulation (EU) No 910/2014, consolidated text · source · verified 2026-07-30

Article 7(f) then leaves the terms of access for everyone else — that is, for every commercial company — to the notifying Member State. So each country decides separately whether a private business may accept its citizens’ national eID, and several say no.

The inverse is also true, and equally counter-intuitive: some of the schemes with the largest real-world usage are not notified at all. Smart-ID, used across Estonia, Latvia and Lithuania, has never been notified by any country. Estonia’s own authority is explicit that it was assessed nationally instead:

Smart-ID is not a “notified” scheme but it has been “evaluated” for national use, which means that an expert group formed by RIA found that based on the methodology described in the eIDAS Regulation, Smart-IDs issued to persons with Estonian national identification numbers meets the criteria of “high” assurance level.
Estonian Information System Authority (RIA) · source · verified 2026-07-30

The same applies to the Finnish bank IDs and Mobiilivarmenne — every one registered at substantial, none notified — to the Czech Bank iD with its five million users, and to the Dutch iDIN. Notification is a legal act between a Member State and the Commission. It is not a measure of whether anyone uses the thing.

Private-sector access to national eID schemes, by tierFour tiers. Nine countries publish a tariff and admit commercial services. Seven admit them without publishing a price. Six are narrow or conditional. Three — the Netherlands, Spain and Ireland — are closed to commercial relying parties by statute.Open, price publishedPT · IT · SI · EE · LV · LT · FI · DK · CZOpen, price on requestPL · BG · DE · BE · AT · SE · NONarrow or conditionalFR · HU · GR · HR · RO · SKClosed to commercial servicesNL · ES · IE
Access is decided country by country under Article 7(f), not once at EU level. Sourced per country in the article below.

What it actually costs, where the price is published

National eID is not a free API. Every scheme is operated by a bank consortium, a state agency or a licensed private company, and every one charges per authentication. What varies enormously is whether the price is published at all — and for a surprising number of countries, it is not.

Country / schemeWho may use itPublished price
Portugal — Chave Móvel DigitalPublic and private, no sector test€1,000–€4,000/year by volume band, then €0.05 per SMS authenticationPortaria n.º 77/2018, Diário da República · 2026-07-30
Italy — SPIDPrivate companies, no subject-matter test€0.40 per unique user per year (levels 1–2); first 1,000 users free per identity providerAgID — Allegato 4, corrispettivi SPID · 2026-07-30
Slovenia — SI-PASSExplicitly not limited to public bodies€148 one-off + €58/month + €0.0546 per authenticationSI-TRUST — SI-PASS price list, in force 1 June 2026 · 2026-07-30
Estonia, Latvia, Lithuania — Smart-IDAnyone; a natural person or a legal entity may contract€0.109 per transaction, €60/month minimumSK ID Solutions — price list, valid from 1 June 2026 · 2026-07-30
Finland — Trust NetworkAny service; relying parties do not registerStatutory maximum of €0.03 per identification transactionTraficom / NCSC-FI — electronic identification · 2026-07-30
Denmark — MitIDOnly through a certified broker — direct connection is not possible0.078 DKK per authentication requestDigitaliseringsstyrelsen / MitID · 2026-07-30
Czechia — Bank iDPrivate companies, after a compliance review30,000 CZK activation, then 0.49 CZK per login or 10 CZK per user per yearBank iD — price list, effective 1 January 2026 · 2026-07-30
Germany — Online-AusweisfunktionAnyone who can show a legitimate interest — a bound decision, no size test€102 state fee; the authorisation-CA and eID-service costs are not published§ 21 Personalausweisgesetz · 2026-07-30
Absence of a published price is not evidence that a scheme is free. For Belgium, Austria, Poland, Romania, Slovakia, Croatia, Hungary, Greece, Bulgaria, Latvia, Luxembourg, Malta and Cyprus we could not find a relying-party tariff at all — which usually means it is negotiated, not that it is zero.

Three countries are closed to commercial services by law

Not by policy, by statute — which is why no amount of commercial negotiation opens them.

  • Netherlands (DigiD). The Wet digitale overheid restricts a public identification means to access to services provided by administrative bodies and designated organisations. Logius adds three cumulative conditions, the first being that you perform a public task established in law.
  • Spain (Cl@ve). The 2014 order reserves adhesion to other public administrations. The private sector appears in the Cl@ve rules only as a potential identity provider — never as a relying party.
  • Ireland (MyGovID). A “specified body” may use a person’s public service identity only in performing its public functions, and using or seeking a PPSN outside the designated categories is a criminal offence.

France sits in between: private companies qualify for FranceConnect in exactly two cases — services related to a change-of-address procedure, or where a regulatory text requires you to verify your users’ identity. The French administration is explicit that an obligation resting on your customers rather than on you is not sufficient.

Two schemes do not speak any federation protocol

If you are planning to add these as generic OpenID Connect providers, two of them will stop you. Swedish BankID is a JSON/REST API over mutual TLS — you hold a client certificate issued through a bank or a reseller. The German eID is EAC v2 against the card chip through an eID server, with a state-granted authorisation certificate. Neither is OIDC or SAML, and no amount of configuration makes them so.

Everything else reachable by a private company arrives as OIDC or SAML, directly or through a broker — which is why a broker is usually the right first move even when direct integration is theoretically possible.

The EU Digital Identity Wallet is a registration regime, not an open API

Regulation (EU) 2024/1183 entered into force on 20 May 2024, and Member States must offer a wallet by the end of 2026. Two provisions are routinely misread.

First, Article 5b requires a relying party that intends to rely on wallets to register in the Member State where it is established, declaring its intended use and the data it will request. “One integration, all of Europe” is not what the regulation says.

Second, the duty on private services to accept wallets — Article 5f(2) — is far narrower than the headlines suggest. It bites only where strong user authentication is already required of you by Union or national law or by contract; micro and small enterprises are exempt outright; and acceptance is only ever on the user’s voluntary request.

Where private relying parties that provide services, with the exception of microenterprises and small enterprises … are required by Union or national law to use strong user authentication for online identification or where strong user authentication for online identification is required by contractual obligation … those private relying parties shall … and only upon the voluntary request of the user, also accept European Digital Identity Wallets…
Regulation (EU) No 910/2014, consolidated text · source · verified 2026-07-30
The exact compliance dates are arithmetic on the entry into force of the implementing acts, not dates the Commission publishes. We quote the Commission’s own wording — “by the end of 2026” — rather than a specific day, because anything more precise is our inference rather than their statement. See Regulation (EU) 2024/1183.

What this means if you are building

  1. Pick countries, not “Europe”. There is no pan-European switch. Each country is a separate contract, a separate legal check and sometimes a separate protocol.
  2. Start where the door is open and the price is published. Portugal, Italy, Slovenia and the Baltics all publish a tariff and admit commercial services without a sector test.
  3. Use a broker for the Nordics first. Denmark makes it mandatory; Sweden and Norway make direct integration expensive enough that it rarely pays before real volume.
  4. Do not store the national identifier. Several countries restrict processing of national identification numbers beyond what the GDPR requires — Denmark’s Data Protection Act restricts private-sector CPR processing specifically. A scheme-scoped pseudonym is almost always the right thing to persist.
  5. An eID login is not KYC. It can be an input to customer due diligence. It does not discharge anyone’s anti-money-laundering obligations, and the obliged entity is you, not your identity provider.

Adetio is building eID as a per-tenant capability on exactly this model: you hold the relationship with the scheme or the broker, we provide the integration, the session model, the account linking and the pseudonymisation. That keeps the per-authentication cost on the contract where it belongs, and it means we are never a regulated intermediary standing between you and your users’ identity. The European eID product page has the current state; it is honest about what is live and what is not.

Sources

  1. European Commission — notified eID schemes register https://ec.europa.eu/digital-building-blocks/sites/spaces/EIDCOMMUNITY/pages/48762251/Overview+of+pre-notified+and+notified+eID+schemes+under+eIDAS · verified 2026-07-30
  2. Regulation (EU) No 910/2014, consolidated text https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:02014R0910-20241018 · verified 2026-07-30
  3. Estonian Information System Authority (RIA) https://www.ria.ee/sites/default/files/documents/2025-10/Estonian-eID-ecosystem.pdf · verified 2026-07-30
  4. Portaria n.º 77/2018, Diário da República https://files.diariodarepublica.pt/1s/2018/03/05400/0131101315.pdf · verified 2026-07-30
  5. AgID — Allegato 4, corrispettivi SPID https://www.agid.gov.it/sites/default/files/repository_files/allegato_4_dt_166_corrispettivi_spid_idp_2019_0.pdf · verified 2026-07-30
  6. SI-TRUST — SI-PASS price list, in force 1 June 2026 https://nio.gov.si/api/files/10607b41-780c-4473-8e3a-4d49f43fc725/file?download=true · verified 2026-07-30
  7. SK ID Solutions — price list, valid from 1 June 2026 https://www.skidsolutions.eu/price-list/ · verified 2026-07-30
  8. Traficom / NCSC-FI — electronic identification https://kyberturvallisuuskeskus.fi/en/our-activities/regulation-and-supervision/electronic-identification · verified 2026-07-30
  9. Digitaliseringsstyrelsen / MitID https://www.mitid.dk/en-gb/broker/prices/ · verified 2026-07-30
  10. Bank iD — price list, effective 1 January 2026 https://bankid.cz/files/Bank-iD_SeP_Priloha-c.-5-cenik.pdf · verified 2026-07-30
  11. § 21 Personalausweisgesetz https://www.gesetze-im-internet.de/pauswg/__21.html · verified 2026-07-30
  12. Regulation (EU) 2024/1183 https://eur-lex.europa.eu/eli/reg/2024/1183/oj · verified 2026-07-30