Cross-Border Trust

A national wallet proves who a person is. Nothing in it proves that two institutions in different countries can trust each other, that a role or an agent may act for an institution, that shared data is authentic and carries the same meaning on both sides, or what happens to a consent decision after data has been shared.

Digital identity has three trust boundaries, not one. A citizen proving identity to an institution inside one country is solved in design, and that is exactly what the national wallets are built for. Recognition across EU member states is solved in design too, through trusted lists published by member states and by the Commission. The third boundary is not solved: two institutions in different jurisdictions verifying each other directly, and everything that happens after data has left the building. That is the boundary Verimesh is built for.

Three boundaries, three different problems

Citizen to institution, inside one country

Solved in design

A person presents a state-issued credential to a hospital, a bank or an authority, and the verifier checks it against a registry the state operates. This is exactly what a national wallet is for, and that is what it is built to do.

Across member states

Solved in design

A credential issued in one member state is recognised in another because trust anchors are published in lists: member states sign their own trusted lists, and the Commission maintains a list of those lists and signs lists of trusted entities for the wallet ecosystem. A verifier resolves the chain to get an answer.

Institution to institution, across jurisdictions

Not solved

Two organisations in different legal systems need to verify each other, not a citizen. And it is more than that: an institution must be able to confirm, at the policy level, that a person, a role, or an AI agent is acting inside a scope granted to it, that the data it shares is authentic and carries its meaning with it, and that the receiving party checks the request against its own credential chain. And once data has moved, a consent decision has to keep travelling with it. None of this is what a citizen wallet was designed to answer.

Three roots of trust

The difference is easiest to see by asking a single question of each system: when a verifier needs to know whether to trust something, what does it ultimately consult?

National wallet / EU wallet ecosystem / Verimesh One state root of trust · Commission list of trusted lists · Each party is its own root of trust National wallet One state root of trust Credential on the holder's device Verifier resolves the state registry EU wallet ecosystem Commission list of trusted lists Member-state trusted lists Relying parties Verifier resolves the published chain Verimesh No shared root Institutions verify each other directly Each party is its own root of trust Vereign AG, three roots of trust

Click to expand diagram

National wallet / EU wallet ecosystem / Verimesh One state root of trust · Commission list of trusted lists · Each party is its own root of trust National wallet One state root of trust Credential on the holder's device Verifier resolves the state registry EU wallet ecosystem Commission list of trusted lists Member-state trusted lists Relying parties Verifier resolves the published chain Verimesh No shared root Institutions verify each other directly Each party is its own root of trust Vereign AG, three roots of trust

Nation states are natural monopolies for official identification, and there are few of them, so the centralised model is the right shape for a national wallet. The wider world is not like that. There are millions of organisations, each with its own departments, devices, agents, and services, and they exchange data with one another constantly. That landscape needs a different architecture, one built for many peers rather than one issuer.

Where this stands today

The specifics below carry dates, and dates move. This is the one section that does.

  • No third-country wallet recognition exists

    Recognition of a non-EU wallet would run through an international agreement plus equivalence acts under the eIDAS third-country mechanism. No such agreement or act exists for any country. Not for Switzerland, and not for anyone else.

  • The Swiss-EU package does not cover digital identity

    Bilaterals III contains no digital-identity element. The only live track is mutual recognition of qualified electronic signatures, where no instrument exists yet.

  • Switzerland paused its own connection work

    The February 2026 federal budget decisions suspended Swiss work on connection to international e-ID systems, EU interoperability included.

  • The two trust layers have no published mapping

    On one side, access certificate authorities with Commission-published lists of trusted entities. On the other, a base registry and a trust registry under the Swiss trust protocol. No published correspondence between them exists. This is the divergence least likely to close on its own, because who may publish a trust anchor is a legal question before it is a technical one.

  • Legal persons are being moved out of the citizen wallet

    The EU architecture framework removed wallets for legal persons, stating that it did so in view of the development of a separate business wallet. The Commission has since proposed amending the regulation so that the wallet covers natural persons only. That proposal is before the European Parliament and carries no application date of its own, so no date should be read into it. The direction is what matters: organisational identity is being given its own instrument.

Why format independence matters

An issuer whose credential of record is canonical, with wallet formats produced on demand at the edge, is not exposed to the credential-format and export-path part of this. Adding a second export target is a change to an export path, not a re-issuance of everything already issued. That is a property of the design rather than a feature to buy.

Stated plainly: no dual export path is built today, and the mapping to the ISO mobile-document format has had no design work. Format independence is how Verimesh is architected, not something running in production.

Where Verimesh stands

In production today

The Verimesh gateway and central CA run in production inside Swiss healthcare at HIN, and SEAL already carries the everyday message traffic. First institutions are migrated and using it, with the rest of the network onboarding through 2026. That deployment is the foundation the cross-organisational model builds on.

Where we are headed

The next step is direct institution-to-institution exchange across borders, with each side verifying people, roles, and agents against its own credential chain and the shared data carrying its meaning with it. Verimesh is built for exactly this, and we are onboarding institutions onto it now. If that is the boundary you work across, let us talk.

Working across a boundary the wallets do not cover?

If your problem is two institutions in different jurisdictions, or consent that has to survive after disclosure, that is the conversation we have every week.

Swiss Data Protection GDPR Compliant Open Source AGPLv3+ Swiss Hosting