The 2026 Identity Stack: How EUDI, My Number 2.0, and NIST 800-63-4 Are Rewiring the Trust Layer
EUDI Wallets, Japan's My Number 2.0, and NIST 800-63-4 all land in 2026. A briefing on the deadlines and the systems being built on top of them.
By the end of December 2026 every EU Member State has to offer its citizens a digital identity wallet. Japan’s redesigned My Number Card ships in the fiscal year that starts 1 April 2026, with private apps allowed on the chip for the first time. In the United States, NIST’s SP 800-63-4 has, since July 2025, accepted mobile driver’s licences and verifiable credentials as identity evidence.
All three use the same formats: ISO/IEC 18013-5 and W3C verifiable credentials. A supplier’s Scope 3 attestation or a Japanese executive’s employment credential issued in one of them can be checked by a verifier in another.
EU: wallets by December 2026
The European Digital Identity Framework, Regulation (EU) 2024/1183, entered into force in 2024. By the end of December 2026 every Member State must offer at least one EU Digital Identity (EUDI) Wallet to its citizens, free of charge. The first set of implementing regulations was published on 4 December 2024, which started the 24-month national-availability clock.
The wallet is a mobile container for verifiable attestations: residency, a professional licence, a degree, tax status. The holder presents any subset of them to any verifier in the EU. Use is voluntary for citizens. Acceptance is mandatory for specified private-sector relying parties (banks, telcos, healthcare providers) and for Very Large Online Platforms by late December 2027.
Some Member States are on track. The Netherlands has signalled limited functionality at launch. Bulgaria, per public reporting, has barely started. The deadline does not move for any of them: by the close of 2027, any platform offering authenticated services to EU residents has to accept an EUDI Wallet presentation. Every consumer-facing onboarding flow in Europe gets rebuilt around that requirement, and since the EU is roughly a fifth of the global digital economy, most multinational platforms will build wallet acceptance once and switch it on everywhere.
Japan: My Number Card, fiscal 2026
Japan’s My Number Card predates the EUDI Wallet; issuance began in 2016. The changes arriving in fiscal 2026 alter what the card is for.
By January 2026 roughly 80 percent of Japan’s population held a My Number Card, with more than 100 million issued. Among major economies only Estonia, Singapore and India, in different ways, operate national ID at comparable scale. Until now the card could only ever be a government-issued credential.
The Digital Agency is moving on several fronts. From fiscal 2026 (which begins 1 April 2026), a redesigned My Number Card ships with the gender field removed from the surface and stored only in the chip, plus furigana, Romanized names and Gregorian-calendar birthdates aligned to international identity norms. The card moves onto Android in 2026 after a 2025 iOS launch, alongside a new “Myna App” the Digital Agency plans to use as the consumer-facing surface for tax filing, healthcare credentials and administrative procedures.
The larger change is the authorisation of Toshiba Digital Engineering to install applications into the unused IC chip space on the card. The government notice lets regulated private-sector apps run on My Number, so the card can carry attestations from other issuers: employment credentials, professional licences, healthcare proofs, and in time anything an accredited issuer can sign.
The EUDI Wallet works the same way, on a phone instead of a chip card: the citizen holds a portable container and accredited issuers and verifiers exchange attestations through it. The card already serves as a health insurance credential in Japan; the 2026 push extends that to nursing care and wider medical records access.
United States: SP 800-63-4
In July 2025 the National Institute of Standards and Technology published the final version of SP 800-63 Revision 4, the reference for digital identity assurance in the United States. It took almost four years, two public drafts and nearly 6,000 individual comments.
Two of the changes affect companies outside the US.
NIST now accepts mobile driver’s licences (mDLs) and verifiable credentials as valid identity evidence. US federal agencies, banks and any organisation that benchmarks against NIST can treat an ISO/IEC 18013-5 mDL or a W3C-format verifiable credential the way they treat a passport scan or in-person identity proofing, which moves those formats out of pilot programmes and into compliance requirements.
The document also replaces the checklist regime with a risk-based Digital Identity Risk Management framework and steers organisations away from one-time passwords toward passkeys and hardware-bound credentials with phishing resistance built in. SMS one-time passwords no longer meet the bar.
As of early 2026, 21 US states plus Puerto Rico have mobile driver’s licences accepted by the Transportation Security Administration at airport checkpoints; 41 percent of Americans live in states where mDLs are active; 76 percent live in states with programmes live or in development. ISO/IEC 18013-5 has become the working international standard, with adoption under way in Australia, New Zealand, South Korea and the Gulf states.
Uses beyond login
ESG and sustainability disclosure. The next phase of CSRD compliance, ISSB IFRS S1/S2 reporting and SSBJ disclosure in Japan all require emissions figures and supplier attestations that an auditor can trace back to source. When a Tier 3 supplier presents a Scope 3 attestation to a Tier 1, the artefact that satisfies both an EU CSRD assurance review and an SSBJ disclosure note is a signed verifiable credential. Companies that build that machinery now will have it in place for 2028 reporting.
AI provenance. Regulators in Tokyo, Brussels, Seoul and Washington are tightening requirements on AI output labelling (see the Asian AI rulebook briefing). Proving that a piece of media was produced by a human, by a specific AI model, or under a specific licence again comes down to a verifiable credential. C2PA content credentials and EUDI Wallet attestations are moving toward the same vocabulary.
Cross-border services. EUDI Wallet acceptance becomes mandatory for the relying parties named in the regulation. Japanese companies operating in Europe will need to accept EUDI presentations by 2027. European companies onboarding Japanese executives will need to accept My Number-issued attestations.
Supply chain and trade finance. Bills of lading, letters of credit, certificates of origin and customs declarations can all be issued as verifiable credentials on the same standards stack.
The question for boards
The December 2026 and December 2027 dates are in the regulation. Executives still have to decide how early to move. A company can wait for the wallets to arrive and adapt, or it can take part in defining the credential schemas for its sector while they are still open.
Tech for Impact Summit 2027 will put that decision on the table, alongside privacy as a public good, collaborative-technology models of democratic governance and the wider Japan policy stack.
Speakers at T4IS2027 will include people from the agencies and companies building this layer.