7th Lendtech Congress 2026. CRA – AMLR mObywatel – mObywatel Europa (EUDI Wallet)
7th Lendtech Congress 2026 has concluded. We would like to thank the organisers for inviting DLK Legal to take part in the event.
Dr Krzysztof Korus, Partner at DLK Legal, presented selected issues concerning onboarding and applications in the lending sector (information current as at 25 September 2026).
CRA Regulation (EU) 2024/2847
From 11 September 2026, manufacturers report actively exploited vulnerabilities and severe incidents having an impact on the security of the product — simultaneously to the CSIRT designated as coordinator and to ENISA, through the EU single reporting platform. This applies to entities making a mobile application, a browser plug-in or a desktop client available to their customers. A manufacturer also includes a party that makes an application available under its own name or trademark, irrespective of who wrote the code.
The obligation also covers the back-end, provided that it constitutes a remote data processing solution within the meaning of Article 3(2) CRA — that is, where without it the application does not perform one of its functions. An optional back-end, or one that merely enhances functionality, is not covered.
The remaining CRA obligations apply from 11 December 2027. The provisions on notified bodies (Chapter IV) apply from 11 June 2026.
The reporting obligation extends to products (here: applications) placed on the market before 11 December 2027 (Article 69(3) CRA). Existing applications therefore remain within the scope of reporting even where they will not be subject to the remaining requirements of the Regulation, in particular where no substantial modification of the application has taken place after 11 December 2027.
Poland has not yet designated a market surveillance authority competent for the CRA, nor has it introduced provisions on penalties. The deadline under the Regulation is 11 December 2027.
The obligation to put in place and enforce a coordinated vulnerability disclosure policy (Annex I, Part II, point 5) arises only on 11 December 2027, while the public-facing element — contact details for reporting vulnerabilities, included in the information and instructions to the user — follows from Annex II. Nevertheless, many entities have already made such a procedure available.
AMLR Regulation (EU) 2024/1624
The AMLR applies from 10 July 2027. For the use of mObywatel in KYC this does not entail any fundamental change.
Article 22(6)(b) AMLR confirms that identity may be verified by means of electronic identification at the substantial or high assurance level. The mObywatel profile (Polish state – operated digital identity app and system), operated through the national eID node, falls within that catalogue at the substantial level. The AMLR itself does not impose an obligation to make that method available to customers — whether in branch or online — although the draft RTS on customer due diligence submitted by the EBA in 2025 suggests otherwise.
The current draft RTS on customer due diligence (Article 28(1) AMLR) provides that mechanisms other than eIDAS means may be used for KYC in the online environment only where an eIDAS KYC means is not available or its use cannot reasonably be expected. Although, on a literal reading, the condition is the actual availability of the means on the customer’s side, it is to be expected that in commercial practice it will be the customer who decides which mechanism to use. And since a proportion of customers will prefer an eIDAS means, obliged entities will most likely be unable to avoid integrating with at least one leading eIDAS means at the substantial or high assurance level. As the number of customers holding an eIDAS means grows, obliged entities will progressively lose the ability to justify alternative methods.
The solution proposed by the EBA and AMLA has met with wide criticism in the consultations, including from the European Banking Federation and from providers of verification solutions. The objections raised concerned the conflict with the equal standing of the methods set out in Article 22(6) AMLR, the breach of the principle of technology neutrality (recital 74 AMLR), its prematurity in light of the state of eIDAS 2.0 deployment, and the risk of excluding customers holding documents that do not meet interoperability standards.
It is therefore advisable to await the final text of the RTS on customer due diligence before reconfiguring online processes around eIDAS. That said, this direction should be expected to hold: despite the criticism directed at the EBA draft, AMLA carried the solution over into its own draft.
The obligation to accept the mObywatel document for identity verification in relations involving the mutual physical presence of the parties follows from the Polish AML Act as amended by the Act of 26 May 2023 on the mObywatel application (Article 83 in conjunction with Article 7(2) of the Act on the mObywatel application). That obligation will most likely be maintained, but the matter will be settled only by the Polish act accompanying the AMLR. The pending draft amendment to the AML Act, available on the website of the Government Legislation Centre, does not concern the AMLR.
Regulation (EU) 2024/1183 — eIDAS 2.0 and the EUDI Wallet (European Digital Identity Wallet)
mObywatel Europa — mObywatel at the high assurance level, equipped with European Digital Identity Wallet functionality — is already at the certification stage; a test environment (sandbox) is also available. The other Member States are likewise working on their own wallets. It is possible that in some of them, alongside national wallets, wallets will also be issued by private entities, subject to appropriate certification.
To migrate to mObywatel Europa, existing mObywatel users will have to complete additional authentication, for example using an identity card with an electronic layer, in order to reach the high assurance level required for the wallet.
The provisions on the EUDI Wallet do not impose on obliged entities any obligation to accept it for KYC purposes.
Where, however, a lending institution or another entity is at the same time a payment service provider, or applies strong customer authentication (SCA) on another basis, it will act in two capacities: as the issuer of the SCA attestation issued to the user’s wallet (not expressly required by Article 5f(2) eIDAS, but in practice unavoidable), and as a relying party which registers and obtains an access certificate in order to receive and verify presentations. In both capacities the obligation covers wallets issued in every Member State. That obligation concerns SCA only and does not translate into the use of the wallet for KYC — a point that merits particular attention, as many sources conflate the two.
Using the EUDI Wallet for SCA purposes requires it to be linked in advance to the provider. In the case of payment services, the link may be established at the level of the user or of a specific payment instrument — much as in commercial payment wallets, to which individual cards and other payment methods are added separately.
In relation to payment transactions, the specification provides, alongside the flow initiated by the issuer (issuer-requested flow; in EMV terminology, Issuer-Captured Transaction), also a variant initiated by a third party (third-party-requested flow; in EMV terminology, Merchant-Captured Transaction). In the latter, authentication takes place directly between the payer and the payee, and the complete set of transaction data together with the authentication result is sent to the payer’s provider solely for authorisation purposes; that communication takes place outside the EUDI Wallet infrastructure, over existing payment networks and open banking interfaces.
For the lending sector, the EUDI Wallet is significant for two further reasons. First, mObywatel Europa will enable qualified electronic signatures to be created. Beyond KYC, this therefore resolves the problem of the written form of the consumer credit agreement, removing the need to resort to powers of attorney and other workarounds. Second, larger employers and benefit-paying institutions (for example the Social Insurance Institution, ZUS) could consider issuing attestations of earnings or benefits into the wallet in the form of attributes. Were they to use qualified trust service providers for that purpose, such an attestation would acquire evidentiary value comparable to a certificate in written form.
Proposed posts
7th Lendtech Congress 2026. CRA – AMLR mObywatel – mObywatel Europa (EUDI Wallet)
25.09.2026
7th Lendtech Congress 2026 has concluded. We would like to thank the organisers ...
7th Lendtech Congress 2026. CRA – AMLR mObywatel – mObywatel Europa (EUDI Wallet)Recommended: VII Kongres Lendtech, 24.09.2026, CIC Warszawa
17.09.2026
On behalf of the organizers and myself, we would like to recommend the following...
Recommended: VII Kongres Lendtech, 24.09.2026, CIC WarszawaFuture Finance Poland Report Titled “Digital Payment Security”
26.06.2026
Yesterday (June 25, 2026), the Future Finance Poland report titled Digital Paym...
Future Finance Poland Report Titled “Digital Payment Security”