Regulation

What is Architecture and Reference Framework (ARF)?

The Architecture and Reference Framework is the technical reference for the EU Digital Identity Wallet, produced by the European Digital Identity Cooperation Group together with the Commission as part of the Common Union Toolbox. It sets out the roles, protocols, credential formats and trust model that wallets, issuers and relying parties implement to interoperate. It is informative. What binds is the regulation and its implementing acts.

In detail

How it actually works

The ARF is where the regulation becomes something you can build. It names the actual standards: OpenID4VCI for issuance, OpenID4VP for remote presentation, and ISO/IEC 18013-5 for proximity presentation. Three attestation formats are recognised, ISO/IEC 18013-5 mdoc, SD-JWT VC and W3C VCDM v2.0. It also says how trust lists, registration and revocation fit together.

It is versioned and still moving. Implementers track ARF releases the way they would track a protocol draft, because rulebooks and profile details keep getting refined ahead of the acceptance deadlines.

Attestation rulebooks used to live in its annexes. As of v3.0.0 the PID and mDL rulebooks have moved to a separate catalogue, and the ARF now describes what a rulebook has to contain rather than carrying them.

Defined in

European Digital Identity Cooperation Group, EUDI Wallet ARF v3.0.0 (23 July 2026)

Why it matters

What this changes for you

This is the gap between "we support verifiable credentials" and "we interoperate with EU wallets". A verifier that implements the generic standards but not the ARF profiles will fail against real wallets.

Authbound handles the protocols, formats, trust lists and revocation checks behind these terms. See what people build with them.