Skip to main content
Didit Raises $7.5M to Build the Infrastructure for Identity and Fraud
Didit
Back to blog
Blog · October 6, 2026

CIE ID integration: accepting Italy's CieID as a business

How a business accepts CIE ID: the CieID user flow, levels 1 to 3, the CIE federation for private service providers, AML article 19, age and gambling rules, what is not published, and fallbacks.

By DiditUpdated
cie-id-integration-cover.png

In short

CIE ID is how Italians sign in online with the Carta d'Identità Elettronica (CIE), the chip identity card issued by the Ministry of the Interior, through the CieID app and the "Entra con CIE" button.[1][4] A private business can join the CIE federation as a service provider, directly or through an aggregator, using SAML2 or OpenID Connect under the federation's operating manual; admission carries fit-and-proper requirements.[6]

  • EU-notified at Low, Substantial and High since 13 September 2019.[2]
  • CIE at level 2 (Substantial, by our reading) or level 3 meets remote identification under Italian anti-money laundering (AML) law.[8]

Last reviewed: 5 October 2026 · Not legal advice

To let Italian customers sign up with their identity card, you need CIE ID. CIE is a chip card; CieID is the app and login that turn it into an electronic ID (eID).[1][4] The Ministry of the Interior's federation admits private service providers, so a bank or a gaming operator can add "Entra con CIE" to its sign-up.[6]

What CIE ID is: the card and the CieID app

The CIE is issued by the Ministry of the Interior and produced by IPZS (Istituto Poligrafico e Zecca dello Stato). The current card, CIE 3.0, has been issued since 4 July 2016; first- and second-generation cards were issued before that date.[1]

CIE

Italy's electronic identity card and the CieID sign-in

On request
CountryItaly
OperatorMinistry of the Interior issues the card; IPZS produces it[1]
CIE 3.0 sinceIssued since 4 July 2016[1]
Users67,074,990 cards issued (live counter, read 5 October 2026), cumulative issuance including renewals, not unique holders[5]
CredentialChip card with an 8-digit PIN, used through the CieID app or a card reader, at levels 1, 2 and 3[1][4]
Level of assuranceLow, Substantial and High; notified under eIDAS, the EU eID regulation, on 13 September 2019[2]
Data returnedSet by the federation's technical rules; the exact list is not verified in our sources (see below)[6]
Legal basisCIE federation under the Ministry of the Interior decree of 8 September 2022[6]; the digital identity system of Digital Administration Code Article 64[8]
Didit statusOn request

Adoption: how many people hold a CIE

The Ministry's counter, read on 5 October 2026, showed 67,074,990 cards issued.[5] That includes renewals, so it is not a count of people. We found no published count of CieID sign-ins, app users or adult coverage as of 5 October 2026.

67.07 MCumulative cards issued, not unique holders
3Sign-in levels: Low, Substantial, High
13 Sep 2019CIE notified under eIDAS
12 MIT-Wallet activations, per IPZS on 23 July 2026

The IT-Wallet figure is indirect: the wallet is opened with CieID or SPID,[13] and IPZS reported on 23 July 2026 "12 million activations over the past year and a half".[14]

What the user sees

The strip below is the level 3 flow, the one the Ministry documents: install CieID (not shown), register the card (screen 1), choose "Entra con CIE" (screen 2), confirm on a phone (screen 3) or a computer (screen 4).[3][4]

Levels 1 and 2 are lighter: level 1 is a username and password, and level 2 adds a second factor such as a one-time code or a QR scan; level 3 is the one that needs a card reader or an NFC (near-field communication) phone.[1]

CieID app

Register your card

Enter your 8-digit PIN, then hold the card to the back of the phone.

Read the card

1Once: the user registers the card in CieID with the PIN and an NFC read.[4]

Open an account

Verify your identity

Sign in with your electronic identity card.

Entra con CIE

2On your sign-up page, the user taps "Entra con CIE".[3]

CieID app

Confirm the sign-in

Confirm with your CieID code or biometrics.

Confirm

3Confirm on a phone: the user confirms in CieID with the app code or biometrics.[3]

Entra con CIE

Scan with CieID

On a computer, scan the code, then read the card with your phone.

4Confirm on a computer: "desktop con mobile" pairs a QR code with the phone's NFC read, or a contactless reader with the CIE software is used.[3]

Open an account

Identity confirmed

5The user returns to your service with a signed response.

The level 3 flow: register the card once, then confirm each sign-in.[3][4]

The CieID app runs on Android 6 or iOS 13 and later.[4]

Register the card once with the 8-digit PIN, which arrives in two halves, at the application and with the card;[1][4] phone sign-ins then use the app code or biometrics.[3]

User and CieID app Your service CIE identity provider
1Taps "Entra con CIE"
2Request (SAML2 or OIDC)
3Asks to confirm

Code, biometrics or card read

4Confirms
5Signed response
6Account opened

Simplified: a CIE sign-in from the business's side.[3][6]

What a CIE ID sign-in returns to a business

The card's own page defines three levels.[1]

CIE levelHow the user signs ineIDAS level (our reading)Enough for Italian AML remote identification
Level 1Username and passwordLowNo
Level 2Adds a second factor, such as a one-time code or a QR scanSubstantialYes
Level 3Card read by a reader or an NFC smartphoneHighYes

The notification lists three eIDAS levels; the per-level match is our reading, not official.[1][2] Confirm the level with the federation.

The operating manual sets the technical rules; we did not verify the exact attributes.[6]

DataWhat we can confirm on 5 October 2026What to do
Identity attributesSet by the federation's rules; exact list not verifiedConfirm the list; request only what you need
Italian tax codeNot confirmed in our sourcesConfirm before using it as your customer key
AddressNot confirmed in our sourcesPlan a separate address source for AML files
PortraitNot confirmed in our sourcesPlan a selfie and face match if you need one
Level of assuranceLevels 1 to 3, mapped to Low, Substantial, HighAsk for level 2 or 3 for AML onboarding

What a CIE sign-in gives you.[1][2][6]

Level of assurance and legal standing

Per the Commission's overview of notified eID schemes, Italy notified the CIE scheme on 13 September 2019 at Low, Substantial and High, published as 2019/C 309/09 and updated by C/2025/4227.[2]

In national law, the CIE federation ("Entra con CIE") rests on the Ministry of the Interior decree of 8 September 2022,[6] and the digital identity system sits in Article 64 of the Digital Administration Code (CAD, Legislative Decree 82/2005).[8]

CIE and AML customer due diligence in Italy

Article 19(1)(a)(2) of Legislative Decree 231/2007 lists several alternative means that meet the identification duty without physical presence. Two are digital identities of at least "significativo" level: one in the CAD Article 64 system, or one under a scheme on the Commission's eIDAS notification list. The others are a qualified signature certificate and secure electronic identification procedures that are regulated, or authorised or recognised by AgID.[8] "Significativo" is the Italian word; eIDAS says "substantial", and the article uses it for both identity limbs. By our reading, CIE meets both identity limbs, so, reading level 2 as Substantial, level 2 or 3 qualifies.[2][8]

Article 19(1)(a)(2)Legislative Decree 231/2007

"L'obbligo di identificazione si considera assolto, anche senza la presenza fisica del cliente, nei seguenti casi: [...] 2) per i clienti in possesso di un'identità digitale, con livello di garanzia almeno significativo, nell'ambito del Sistema di cui all'articolo 64 del predetto decreto legislativo n. 82 del 2005 [...]"

Source: Normattiva, Legislative Decree 231/2007, Article 19[8]

The AMLR from 10 July 2027

The EU Anti-Money Laundering Regulation (AMLR, Regulation (EU) 2024/1624) applies from 10 July 2027.[9] Article 22(6)(b) allows verification through "electronic identification means which meet the requirements of Regulation (EU) No 910/2014 with regard to the assurance levels 'substantial' or 'high'".[9] Our reading, not a regulator's, and resting on our level mapping: CIE at level 2 or 3 fits. In its final draft standards of 30 September 2026, not yet law, the Anti-Money Laundering Authority (AMLA) says the two Article 22(6) means "are still the default option", with alternatives only when neither can be used.[10]

CIE ID integration: how a business connects

The "Federazione CIE" admits public and private service providers and aggregators. Members use SAML2 or OpenID Connect under the Ministry's "Manuale Operativo per gli erogatori di servizi pubblici e privati".[6] The Ministry lists every enabled service provider in a public register.[7]

Private entities must meet fit-and-proper requirements ("requisiti di onorabilità", Article 5(2) of the decree) through a self-declaration under DPR 445/2000, rechecked at least every four years. A private entity already admitted to SPID can rely on that admission.[6] See also SPID integration.

Direct

Join the CIE federation yourself

  • You run SAML2 or OpenID Connect
  • You follow the operating manual
  • You file the fit-and-proper declaration

You hold the membership

Aggregator

Connect through a CIE aggregator

  • The aggregator is the federation member
  • You sign a contract with the aggregator
  • Your contract sets price and terms

The aggregator holds the membership

Multi-eID provider

One integration, many eIDs

  • CIE next to other national eIDs
  • One response format across schemes
  • Document fallback in the same flow

We do not name providers

Three ways to connect to CIE.[6]

Price and lead time

CIE has no public price list for service providers as of 5 October 2026, and no official statement that they pay nothing; aggregator prices, lead times and test timetables are not published either.

Use cases and sector rules

Use caseWhat the rules saySource
KYC (Know Your Customer) and AML onboardingLevel 2 or above; see the AML sectionNormattiva[8]
Online gambling accountsAccording to Informazione Fiscale, the customs and monopolies agency (ADM) allows accounts opened with SPID or CIE (level 2+) without a document copy from 13 November 2025Informazione Fiscale
Age checks for adult sitesPublic systems, CIE included, only where double anonymity is met; CIE's compliance is unconfirmedAGCOM[11]
SigningAccording to the Ministry's CieID page, the app offers CieSign, which it describes as an advanced electronic signature (FEA)Ministry of the Interior[4]

No CIE-specific telecom rule appears in our primary sources.

Age checks. AGCOM Resolution 96/25/CONS sets how adult sites serving Italy verify age, from 12 November 2025 (three months after the list for sites in other Member States).[11] Under "double anonymity", the age-proof provider must not learn the site and the site gets no identity data. SPID, CIE and wallets are usable "solo laddove soddisfatti i requisiti [...] sul doppio anonimato" (only where the double-anonymity requirements are met). AGCOM's Annex A finds SPID not fully compliant, as its request carries the site's domain; for CIE our sources hold no finding either way.[11] AGCOM's list held 79 services on 29 September 2026.[12]

Limits and fallbacks

  • Minors. Cards are issued to children: validity is 3 years under age 3 and 5 years from 3 to 18.[1] Their use of CieID with private services is not documented in our sources.
  • Foreigners and non-residents. Our sources hold no primary statement on CIE for foreign residents or Italians abroad.
  • The PIN. The card PIN, delivered in two halves, is needed to register the card in CieID; CieID offers PUK recovery.[1][4]
  • Card cost and renewal. A card costs a fixed €16.79 plus municipal fees and, for adults, lasts about ten years, ending on a birthday.[1]
  • Outages and security. No CIE outage or incident appears in our primary sources.

IT-Wallet, opened with CieID or SPID, reached 10.1 million activations by 17 February 2026.[13] See the EU Digital Identity (EUDI) Wallet page and IT-Wallet for businesses.

For everyone else, the document route reads the passport or ID card chip over NFC, checks liveness and matches the face; under AMLA's draft standards it is a justified alternative when the customer cannot use an eID.[10] How NFC chip verification works explains the chip check.

1Offer CIE and SPID first to Italian users

Request level 2 or above for AML onboarding.

The user completes CIE at the level you asked for

Yes

Use the signed response

Store the level you received.

No

Fall back to the document route

NFC chip reading, liveness and face match; record why.

2Screen and decide

Sanctions and politically exposed person (PEP) screening.

Our recommended design: eID first, document route as fallback.

CIE ID integration checklist

  • Choose the route: direct federation membership, aggregator or multi-eID broker.[6]
  • Read the operating manual before you design the data model.[6]
  • Confirm in writing the attributes you will receive.
  • File the fit-and-proper self-declaration, or rely on your SPID admission.[6]
  • Set level 2 as the minimum for AML onboarding.[8]
  • Support both the phone flow and the desktop flow.[3]
  • Keep CIE out of adult-content age gates unless double anonymity is met.[11]
  • Build a document fallback for users without a card.

How Didit helps with eID verification in Italy

Didit adds CIE on request. In Italy today, Didit verifies users with the document route: NFC chip reading, liveness and face match, plus AML screening. The digital ID wallets docs show how the eIDs Didit runs today sit next to the document route. CIE is not one of them yet.

A full KYC check costs $0.33, NFC verification $0.15 and AML screening $0.20.

Didit provides

  • Document checks with NFC chip reading, liveness and face match
  • AML screening against sanctions, PEP and watchlists
  • The evidence of every check

Stays with you

  • The risk assessment and the AML policies
  • The onboarding decision
  • The choice of which eIDs to accept

Bring CIE to your sign-up

Tell us you need CIE; the document route works in Italy today.

Talk to us about CIEStart free

Key takeaways

  • Private businesses join the CIE federation directly or through an aggregator, over SAML2 or OpenID Connect.
  • Level 2 or above is the AML threshold (Article 19, above).

Frequently asked questions

Can a private company accept CIE ID?

Yes, directly or through an aggregator, subject to fit-and-proper requirements.[6] The Ministry's public register of enabled service providers shows who already accepts it.[7]

How much does CIE ID cost for a business?

No CIE price list was found as of 5 October 2026. SPID, by contrast, publishes a pay-per-user model under AgID rules. Ask each aggregator whether it charges per user or per sign-in.

What data does a CIE sign-in return?

The federation's technical rules define the attributes, and we did not verify the exact list for this guide.[6] Confirm the tax code, address and portrait with the federation or your aggregator before you rely on any of them.

Does CIE satisfy AML customer due diligence in Italy?

Yes, at level 2 (Substantial, by our reading) or level 3, on the digital-identity limbs of Article 19(1)(a)(2) of Legislative Decree 231/2007 (see the AML section).[8] Record the level.

What level of assurance does CIE have?

Low, Substantial and High. Italy notified the CIE scheme to the European Commission on 13 September 2019.[2]

Can minors use CIE ID?

Children are issued cards.[1] How minors use CieID with private services is not documented in our sources as of 5 October 2026.

Can foreigners use CIE ID?

We found no primary statement on CIE for foreign residents as of 5 October 2026. Plan a document route for foreign customers.

How long does a CIE integration take?

No lead time is published as of 5 October 2026. The work is SAML2 or OpenID Connect under the operating manual, plus the fit-and-proper declaration.[6]

How do I test a CIE integration?

No public sandbox or test timetable is documented as of 5 October 2026; the operating manual is the only documented starting point.[6] Ask the federation or your aggregator whether a test identity provider and test cards exist before you set a release date.

Will CIE count under the AMLR from 2027?

Our reading is yes at level 2 or 3, subject to our level mapping above: from 10 July 2027, Article 22(6)(b) accepts eIDAS means at Substantial or High.[9]

Sources

  1. La carta, Ministry of the Interior, Carta d'Identità Elettronica.
  2. Overview of pre-notified and notified eID schemes under eIDAS, European Commission, updated 2 February 2026.
  3. Entra con CIE, Ministry of the Interior.
  4. CieID, Ministry of the Interior.
  5. Carta d'Identità Elettronica, cards issued counter, Ministry of the Interior, read 5 October 2026.
  6. Federazione CIE, Manuale operativo, Ministry of the Interior.
  7. Federazione CIE, enabled service providers, Ministry of the Interior.
  8. Legislative Decree 231/2007, Article 19, Normattiva.
  9. Regulation (EU) 2024/1624 (AMLR), Articles 22 and 90, EUR-Lex.
  10. Final Report, draft RTS under Article 28(1) AMLR, AMLA, 30 September 2026.
  11. Delibera 96/25/CONS and Annex A, AGCOM, 8 April 2025.
  12. List version 5, AGCOM, 29 September 2026 (first list 30 October 2025).
  13. IT-Wallet supera quota 10 milioni di attivazioni, Department for Digital Transformation, 17 February 2026.
  14. The IT-Wallet System Opens Testing to Private Companies, IPZS, 23 July 2026.

Compare CIE with other national eIDs on the eID verification page, or read what eID verification is.

Need CIE for Italian users

Talk to us about CIE. Chip reading, liveness and face match work in Italy today.

Talk to us about CIEStart free

Infrastructure for identity and fraud.

One API for KYC, KYB, Transaction Monitoring, and Wallet Screening. Integrate in 5 minutes.

Ask an AI to summarise this page