Skip to main content
Didit Raises $7.5M to Build the Infrastructure for Identity and Fraud
Didit
Back to blog
Blog · October 6, 2026

Estonian eID for business: Smart-ID, Mobile-ID and ID card

The Estonian eID for business: Smart-ID, Mobile-ID and the ID card compared, the AML and gambling rules, what users see, routes by sector, and the fallback for people without an Estonian eID.

By DiditUpdated
eid-verification-estonia-cover.png

In short

The Estonian eID comes in three forms: Smart-ID (797,395 users in Estonia on 5 October 2026), the ID card (about 1.2 million valid cards in July 2026) and Mobile-ID (219,000 people in July 2026, by RIA's count).[2][3] A business should accept Smart-ID first, then Mobile-ID, and keep a document route for everyone else.

  • The ID card and Mobile-ID are part of Estonia's eID scheme notified to the EU at level High; Smart-ID is not notified but is rated "high" nationally.[1][2]
  • The anti-money-laundering act accepts a notified eID or a qualified trust service for remote due diligence.[7]
  • Private companies may use TARA, the state login gateway, only with its cross-border eIDAS scopes (Belgium, Portugal and Sweden in production).[6]

Last reviewed: 5 October 2026 · Not legal advice

Estonia offers three forms of electronic identity (eID). The ID card with a chip is, in RIA's words, the "primary document that carries electronic identity, which is compulsory according to the law"; Smart-ID is a phone app, and Mobile-ID keeps the keys on a special SIM card.[2]

Every Estonian eID at a glance

Estonia's eID scheme, notified to the EU on 7 November 2018, covers the ID card, the residence permit card, Digi-ID, the e-Resident's Digi-ID, Mobile-ID and the diplomatic card, all at level of assurance (LoA) High.[1] Smart-ID sits outside it; the Information System Authority (RIA) rates it "high" for people with an Estonian personal code.[2]

eIDOperatorUsersCredentialLevel and EU statusData a business getsPrivate-sector accessDidit status
Smart-IDSK ID Solutions, a private company[9]797,395 in Estonia (5 October 2026)[3]Phone app with PIN1 and PIN2, qualified certificates[2]"High" nationally; Not EU-notified[1][2]Names, personal code, date of birth[6]Contract with SK ID Solutions or a broker[16]Live
Mobile-IDState-backed; SIM from Telia, Elisa or Tele2[4][5]219,000 (RIA, July 2026); more than 220,000 per id.ee, 6 August 2026[2][4]Keys on a special SIM card[2]High, EU-notified since 7 November 2018[1]Names, personal code, date of birth, verified phone number[6]Mobile-ID service API or a broker[16]Live
ID card, residence card, Digi-IDPolice and Border Guard Board; RIA sets the requirements[2]About 1.2 million valid ID cards (July 2026)[2]Chip card with PIN1 and PIN2[2]High, EU-notified since 7 November 2018[1]Names, personal code, date of birth, optional eesti.ee e-mail[6]Not through TARA; a direct card integration or a broker[6]Coming soon
e-Resident's Digi-IDPolice and Border Guard Board[2]13,828 new e-residents in 2025 (not the total of holders)[17]Chip card[2]High, EU-notified[1]Names and personal code; a second document is needed for remote due diligence[7]As the ID cardComing soon
Estonian EUDI WalletNot announced in our researchNot launched (5 October 2026)Not yet definedMust be High under eIDAS 2[19]Person identification data[19]Relying-party registration[19]Coming soon

The last column is Didit's own status for each eID.

Note

TARA, RIA's state login service, accepts the ID card, Smart-ID, Mobile-ID and EU eIDs, but private-sector clients may only use its cross-border eIDAS scopes, not the domestic eIDs.[6] For domestic logins they connect to each eID directly or through a broker.

The Estonian eID timeline: from 2018 to 2027

  1. 7 November 2018NotifiedID card, Digi-ID and Mobile-ID enter the EU list at High.
  2. 2 July 2022New Mobile-IDMobile-ID replaces Mobiil-ID on the EU list.
  3. 1 May 2025Digi-ID endsDigi-ID is no longer issued to residents, only to e-residents.
  4. November 2025New certificatesSK ID Solutions stops issuing ID-card certificates.
  5. 29 April 2026NFC sign-upSmart-ID registration with the ID card moves to NFC.

The Estonian eID from notification to NFC registration.[1][2][9][12]

NFC registration replaced the card reader so scammers can no longer trick people into typing ID-card PINs on calls.[12]

  1. 2026Smart-ID+QR and app-to-app login rolls out to users.
  2. 24 December 2026EUDI WalletEvery Member State must offer one.
  3. 19 May 2027SIM swapOld Mobile-ID SIMs stop working.
  4. 10 July 2027AMLR applieseID becomes a named route for verification.
  5. 24 December 2027AcceptancePrivate firms required by law or contract to use strong user authentication for online identification must accept the wallet on the user's request, except micro and small enterprises.

What changes in 2026 and 2027.[4][9][19][20]

Smart-ID+ drops the personal-code entry: a QR scan on a computer, an app-to-app jump on a phone.[11] RIA adopted it for state e-services, and each service opts in.[10] Mobile-ID SIMs must be replaced before 19 May 2027; RIA says the update "is related to amendments to the eIDAS Regulation" that entered into force in 2024, and warns that fraudsters may impersonate mobile operator staff during the swap.[4]

Article 5a(1) of eIDAS 2, Regulation (EU) 2024/1183, says "each Member State shall provide at least one European Digital Identity Wallet within 24 months" of its implementing acts entering into force.[19] The first entered into force on 24 December 2024, so the deadline is 24 December 2026. Our research found no published launch date for an Estonian wallet as of 5 October 2026. See the EUDI Wallet guide.

The rules for eID verification in Estonia

Under the Identity Documents Act the ID card is compulsory for citizens, and the Police and Border Guard Board issues it; a digital signature carries equal weight with a handwritten one.[2]

Anti-money laundering: section 31 of RahaPTS

The Money Laundering and Terrorist Financing Prevention Act (RahaPTS) sets rules for remote identification by credit institutions, financial institutions and notaries. When due diligence is not done in person, section 31(3) allows two tools.[7]

§ 31(3)Rahapesu ja terrorismi rahastamise tõkestamise seadus

"1) e-identimise süsteemi, millest on teatatud [...] (EL) nr 910/2014 [...] artikli 9 kohaselt ja mis vastab [...] artikli 8 lõike 2 punktis b või c sätestatud usaldusväärsuse tasemele" [...] "2) kvalifitseeritud usaldusteenust"

Source: Riigi Teataja, RahaPTS[7]

In short: an eID scheme notified under eIDAS at Substantial or High, or a qualified trust service. The ID card and Mobile-ID meet the first test.[1] Smart-ID is not notified. Full Smart-ID accounts carry qualified certificates,[3] so a firm could argue the second route for it. That is our reading, unconfirmed by any official statement as of 5 October 2026; ask the Financial Supervision Authority.

Rule in § 31What it requires
§ 31(1)A § 31(3) tool, or a remote video tool that meets § 31(31), when the customer lives outside the EEA or monthly outgoing payments exceed EUR 15,000 (person) or EUR 25,000 (company)[7]
§ 31(11)A § 31(3) tool for customers from high-risk third countries[7]
§ 31(4)With the e-Resident's Digi-ID, a second identity document at the same time[7]

Today

Notified eID

  • ID card, Mobile-ID
  • Level Substantial or High

RahaPTS § 31(3)(1)

Today

Qualified trust service

  • Qualified certificates
  • Could be argued for Smart-ID: our reading, unconfirmed as of 5 October 2026

RahaPTS § 31(3)(2)

From 10 July 2027

AMLR eID route

  • eIDAS eID at Substantial or High
  • Or an identity document

AMLR Article 22(6)

The three legal routes for remote identification with an Estonian eID.[7][20]

From 10 July 2027 the EU Anti-Money Laundering Regulation (AMLR), Regulation (EU) 2024/1624, applies; its Article 22(6)(b) accepts "electronic identification means which meet the requirements of Regulation (EU) No 910/2014 with regard to the assurance levels 'substantial' or 'high'".[20] The Anti-Money Laundering Authority (AMLA) final draft standards of 30 September 2026, not yet law, say eID qualifies "regardless of whether they are notified" if it meets those levels.[21] Adopted in that form, they would cover Smart-ID. Our guide to eID verification explains the AMLR route.

Gambling and age rules

Under the Gambling Act (HasMS) wording in force since 1 January 2026, under-21s may not play games of chance or remote games of chance; lotteries and toto are 18+ (§ 34(2) and (3)).[8] Section 53(1) requires remote operators to ensure "iga mängija isikusamasuse tuvastamise", the identification of every player, record the name and personal code or date of birth, and keep minors out.[8] No Estonian eID returns an "over 18" or "over 21" flag through TARA: the business derives age from the date of birth.[6]

Watch out

Our research found no financial, gambling or telecom supervisor position on which eID to use, as of 5 October 2026. Mobile operators set their own Mobile-ID rules, age limits included.[5]

What the user sees with Smart-ID

The service shows a four-digit code, the Smart-ID app shows the same code with the service's name, and the user confirms with PIN1. Some services make the app offer three codes to pick from.[13] The strip shows the comparison-code flow, not Smart-ID+, and skips any identifier entry; screen 3 is the Smart-ID app, the rest the verification page. The PIN is never typed on the website.

Verify your identity

Choose how to verify

Sign in with the electronic ID you already use.

Smart-ID

1The user picks Smart-ID.

Verify your identity

Check the code

4821

The same code appears in your Smart-ID app.

2The page shows a four-digit code.

Smart-ID app (not Didit)

Enter PIN1

Only if the code and the service name match.

3In the Smart-ID app's own screen, the user types PIN1.

Verify your identity

You are verified

  • Full nameShared
  • Date of birthShared
  • Personal codeShared
  • AddressNot shared

4Signed attributes land on the session.

Video pending: flow-app-code

An app sign-in with a comparison code, start to finish.

In 2019, fake bank pages collected Mobile-ID PINs to open Smart-ID accounts behind victims' backs; since 1 July 2019 "a separate notification and a code are now sent to the device connected to the person's Mobile-ID", and the code must also be entered to create a Smart-ID account.[18] See the Smart-ID and Mobile-ID guides.

Choosing an Estonian eID by use case

SectorOffer firstLegal hook
Banks and fintechSmart-ID and Mobile-ID, documents as fallbackRahaPTS § 31; AMLR from 10 July 2027[7][20]
CryptoSmart-ID and Mobile-IDRahaPTS § 31 if you are an obliged entity
GamblingSmart-ID or Mobile-ID, age from the date of birthHasMS § 34 and § 53[8]
TelecomSmart-ID, then the ID cardNone in our research
MarketplacesSmart-ID for sellers, documents for the restYour own risk assessment
MobilitySmart-ID, plus a driving licence checkNone in our research

1Offer Smart-ID and Mobile-ID first

The user has an Estonian personal code and an eID

Yes

Sign in with the eID

Signed name, date of birth and personal code.

No

Verify with a document

Chip reading, liveness and face match.

2Screen and decide

Sanctions and PEP lists.

A routing rule for most Estonian sign-ups.

People without an Estonian eID

In Estonia and Latvia, Smart-ID is limited to people with an Estonian or Latvian national ID number. Residence permit holders and e-residents can register too.[14] Mobile-ID needs an ID card to apply.[2]

  • e-residents. For Smart-ID, TARA cannot tell e-residents from residents.[6] With the e-Resident's Digi-ID, RahaPTS asks for a second document.[7]
  • Minors. Smart-ID has no age limit of its own, but registration paths do (Mobile-ID from 15, a biometric document from 6), and under-18 accounts need a parent's authorisation.[15]
  • Customers from other EU countries. They bring their own eIDs; Smart-ID also has users in Latvia and Lithuania and is used in Belgium.[3][9] See eID in Latvia, eID in Lithuania and the eID schemes by country table.

Launch checklist for Estonia

  • Decide whether RahaPTS § 31 applies to you, and which § 31(3) route you rely on.[7]
  • Plan for Smart-ID+: QR on desktop, app-to-app on mobile.[11]
  • Require a second document for e-resident Digi-ID onboarding.[7]
  • Derive age from the date of birth for gambling and age-gated goods.[8]
  • Keep a document route with chip reading for everyone else.
  • Track the EUDI Wallet deadlines of 24 December 2026 and 24 December 2027.[19]

How Didit helps with Estonian eID verification

Smart-ID and Mobile-ID are live on Didit for Estonia. The user approves a comparison code in the app; Didit never asks for the PIN. Turn them on in the console under Workflows, ID Verification, Countries, Wallets accepted, or with the workflows API.

A sign-in returns the full name, date of birth, Estonian personal code, the level of assurance (labelled High) and a signature check; no address, no portrait. Only completed sign-ins are billed; Smart-ID and Mobile-ID cost $0.20 each (pricing page). The Estonian ID card is on Didit's roadmap, and EUDI Wallet acceptance is coming soon. See all digital ID wallets.

Everyone else falls back in the same workflow to document capture with NFC chip reading, liveness and face match. A document fallback is billed separately, and eID sign-ins sit outside the free monthly checks. A full KYC check costs $0.33, NFC verification $0.15 and AML screening $0.20. Age estimation at $0.10 can run first, with an eID or a document for borderline cases.

Screenshot pending: hosted-flow-wallet-chooser

The user picks Smart-ID in the Didit flow.

Screenshot pending: hosted-flow-smartid-code

The comparison code the user checks in the Smart-ID app.

Screenshot pending: console-wallets-accepted

Turning Smart-ID and Mobile-ID on for Estonia in the Didit console.

Didit provides

  • Smart-ID and Mobile-ID sign-in
  • The document route
  • Signed attributes and evidence

Stays with you

  • The risk assessment and § 31 route
  • The onboarding decision

Accept Smart-ID and Mobile-ID in your sign-up today

Turn on the Estonian eIDs and the document route in one workflow, and pay only for completed checks.

Start freeTalk to usRead the docs

Key takeaways

  • The ID card and Mobile-ID are EU-notified at High; Smart-ID is rated "high" nationally but is not notified.
  • RahaPTS § 31(3) accepts a notified eID or a qualified trust service for remote due diligence.
  • Gambling in Estonia is 21+ for games of chance, and remote operators must identify every player.

Frequently asked questions

What is the Estonian eID?

The electronic identities Estonians use online: Smart-ID, the ID card and Mobile-ID. The ID card and Mobile-ID belong to the scheme Estonia notified to the EU at level High in 2018.[1] Smart-ID is a private app rated "high" by RIA.[2]

Which Estonian eID should a business accept first?

Smart-ID. It has 797,395 users in Estonia[3] and, according to ERR News, carries nearly 60 percent of logins. Add Mobile-ID next, and keep a document route for people without either.

Is Smart-ID recognised under eIDAS?

Not as a notified scheme. Smart-ID is not on the EU list of notified schemes as of 5 October 2026.[1] RIA rates it "high" nationally, for people with an Estonian personal code.[2] It fails the notified-eID test in RahaPTS § 31(3); using it under the qualified-trust-service test is our reading only, so check with the Financial Supervision Authority.

Does the Estonian AML law accept eID for remote onboarding?

Yes. RahaPTS § 31(3) accepts a notified eID at Substantial or High, or a qualified trust service.[7] Credit and financial institutions must use one, or a compliant video tool, for customers outside the EEA or above set payment thresholds.

Can e-residents be onboarded with their Digi-ID?

Yes, but RahaPTS § 31(4) requires a second identity document at the same time.[7] e-residents can also register Smart-ID, though TARA cannot tell them apart from residents.[6][14]

Is Mobile-ID being discontinued?

No. Users must replace their Mobile-ID SIM cards before 19 May 2027, or the service stops working for them.[4] RIA counted 219,000 users in July 2026, and id.ee put the figure at more than 220,000 on 6 August 2026.[2][4] Keep a fallback for users who miss the swap.

What data does an Estonian eID sign-in return?

Through TARA: the names, the personal code with a country prefix, and the date of birth.[6] On Didit, Smart-ID and Mobile-ID return the full name, date of birth, personal code, level of assurance and a signature check. No address and no portrait.

How old must a player be to gamble online in Estonia?

21 for games of chance and remote games of chance under the wording in force since 1 January 2026, and 18 for lotteries and toto (HasMS § 34(2) and (3)).[8] Remote operators must identify every player and record the name and personal code or date of birth.[8] An eID sign-in gives you a signed date of birth, so you compute the age yourself.[6]

Sources

  1. Overview of pre-notified and notified eID schemes under eIDAS, European Commission, read 5 October 2026.
  2. Electronic identity (eID), Information System Authority (RIA), figures as at July 2026.
  3. Smart-ID, SK ID Solutions, user counter read 5 October 2026.
  4. Mobile-ID users need to replace their SIM card, id.ee (RIA), 6 August 2026.
  5. Applying for and activating Mobile-ID, id.ee (RIA).
  6. TARA technical specification, Information System Authority (RIA).
  7. Money Laundering and Terrorist Financing Prevention Act (RahaPTS), § 31, Riigi Teataja, wording in force from 20 July 2026.
  8. Gambling Act (HasMS), Riigi Teataja, wording of 31 December 2025.
  9. 2025: advancing digital trust beyond borders, SK ID Solutions, 19 January 2026.
  10. Estonia's government adopts Smart-ID+ to strengthen security, SK ID Solutions, 28 January 2026.
  11. How does the new Smart-ID protect me from fraud, Smart-ID help.
  12. Smart-ID registration with the Estonian ID card via NFC, Smart-ID, 29 April 2026.
  13. One confirmation code or three, Smart-ID help.
  14. Can foreigners and non-residents use Smart-ID, Smart-ID help.
  15. Age limitations for using Smart-ID, Smart-ID help.
  16. Price list, SK ID Solutions, valid from 1 June 2026.
  17. e-residents generated record state revenue in 2025, e-Residency.
  18. It is more difficult for criminals to create Smart-ID accounts behind people's backs, id.ee (RIA), 20 March 2020.
  19. Regulation (EU) 2024/1183 (eIDAS 2), EUR-Lex, Official Journal of 30 April 2024.
  20. Regulation (EU) 2024/1624 (AMLR), EUR-Lex, Official Journal of 19 June 2024.
  21. Final Report, draft RTS under Article 28(1) AMLR, AMLA, 30 September 2026.

Compare every national eID on the eID verification page.

One workflow for the Baltics and beyond

Start with Smart-ID and Mobile-ID and keep documents as the fallback.

Start freeTalk to us

Infrastructure for identity and fraud.

One API for KYC, KYB, Transaction Monitoring, and Wallet Screening. Integrate in 5 minutes.

Ask an AI to summarise this page