Cutover OS for mid-tier European banks to launch EUDI wallet flows with post-quantum step-up auth and AI-fraud-safe recovery.
Mid-tier European banks are being forced to modernize authentication, device binding, and recovery flows at the same time three pressures collide: EUDI wallet rollout, AI-generated identity fraud, and post-quantum migration. Those flows are usually split across mobile banking teams, fraud ops, IAM vendors, HSM providers, and outside integrators, so nobody owns the full cutover path or the evidence needed for audit and launch approval.
Why now
- European Digital Identity Wallet rollout turns wallet capability into a near-term bank launch program instead of a vague standards roadmap.
- AI-enabled identity fraud is shifting authentication budgets toward safer recovery and step-up controls, so banks have immediate fraud ROI rather than only future compliance value.
- Government and industry post-quantum timelines mean banks must identify brittle signing and authentication dependencies before wallet launches harden them into production.
- Banks in more than 25 countries already buy specialized post-quantum and digital-identity software, which lowers the adoption barrier for a vendor-led cutover layer.
Catalyst. Wultra's round shows banks are already funding wallet capability because EUDI rollout, AI-enabled identity fraud, and post-quantum migration timelines are colliding now.
The idea
The product connects to a bank's mobile-auth stack, identity-proofing vendors, HSM or signing infrastructure, fraud engine, and wallet program backlog to map every step that will break or slow down a wallet launch. It creates a cutover plan for specific journeys—onboarding, account recovery, and high-value payment step-up—showing which components need PQ-safe signing, stronger device binding, or different escalation logic before launch. Teams get a test harness that replays synthetic fraud and recovery scenarios against proposed wallet flows and produces evidence packs for security, risk, and regulator-facing review. The first release wins by compressing months of cross-vendor discovery and manual project management into a single approval-ready program for one bank and one journey. Over time, the company becomes the control layer banks use whenever they add new wallet credentials, relying parties, or cryptographic standards.
What's different. Wallet SDK vendors help banks ship features, and incumbent MFA vendors secure one control point, but neither owns the cross-vendor cutover across recovery, device binding, signing, and audit evidence. Consulting firms can manage the program, yet they do not leave behind a living dependency graph, reusable test harness, or continuous crypto-agility layer. That makes the product both a faster launch tool today and a durable control plane for the next wave of identity changes.
| Beachhead | Mid-tier European retail banks with 1-5 million digital customers, app-based soft-token authentication, and a 2026-2027 EUDI wallet issuer or relying-party launch, starting with account recovery and high-value payment step-up |
|---|---|
| Wedge | A wallet-auth cutover workflow that inventories every vendor and crypto dependency in onboarding, device binding, and recovery, then ships a dual-stack rollout plan with PQ-ready step-up policies, attack-test harnesses, and audit evidence for launch approval |
| Non-obvious insight | The winning wedge is not another consumer wallet or a pure cryptography SDK. EUDI rollout forces banks to reopen the ugliest seams in their identity stack—issuer authentication, device binding, recovery, and vendor handoffs—exactly when AI fraud and post-quantum timelines make those seams dangerous. A startup that owns the cutover and evidence layer can become the system of record for every future identity upgrade. |
| Venture-scale path | Start with EUDI wallet launch programs at retail banks, then expand into continuous crypto-agility monitoring, relying-party policy controls, recovery-risk orchestration, and regulated digital-identity infrastructure for insurers, telcos, wealth platforms, and government-adjacent services. |
| Primary user | Heads of digital identity and authentication at mid-tier European retail banks rolling out EUDI wallet support for onboarding, account recovery, or high-value transaction approval |
|---|---|
| Secondary user | Fraud, mobile-banking, and wallet-program teams responsible for device binding, step-up authentication, and recovery policy |
| Economic buyer | Chief digital officer or CISO |
| First customer | A Czech, Slovak, or Austrian retail bank with 1-3 million mobile customers, existing app-based soft-token login, and a funded EUDI wallet or digital-ID program focused on retail account recovery and high-value transaction approval |
|---|---|
| Buying trigger | A 2026-2027 EUDI wallet pilot, a security review after a deepfake or account-takeover spike, or a board-approved post-quantum migration program that exposes brittle recovery and signing dependencies |
| Current alternative | Internal program management, incumbent MFA and mobile-banking vendors, systems-integrator projects, and spreadsheet compliance matrices stitched across security, fraud, and digital-channel teams |
| Switching reason | This wedge finds cross-vendor breakpoints fast, proves which flows need stronger cryptography or recovery controls, and produces launch evidence that incumbent point vendors and consulting-heavy programs do not package into one operating layer |
| Pricing hypothesis | Annual platform subscription priced by active wallet-auth journeys and connected identity domains, plus paid cutover packages for each launch program |
Jobs to be done
| Job | Current alternative | Success metric |
|---|---|---|
| When a bank is preparing an EUDI wallet or digital-ID launch, help the identity lead see every recovery, device-binding, and signing dependency, so the team can approve one safe production cutover instead of juggling cross-vendor spreadsheets. | Program-management spreadsheets plus vendor workshops and integration documents | Weeks from wallet project kickoff to launch approval |
| When fraud or security leaders worry that deepfake-driven account recovery attacks will exploit new wallet flows, help them test step-up and recovery controls before launch, so they can reduce attack surface without stalling the rollout. | Manual tabletop exercises, point-vendor demos, and post-launch rule tuning | Reduced high-risk recovery exceptions and fewer launch-blocking findings in security review |
flowchart LR Buyer[Bank identity lead] --> Pain[Wallet launch blocked by fraud and crypto cutover risk] Pain --> Product[Wallet auth cutover OS] Product --> Outcome[Faster launch with safer recovery and PQ-ready authentication]
- Signal · 4/5Two same-day sources and a concrete funding round create a credible signal, though the evidence base is smaller than categories with broader independent coverage.
- Pain · 4/5Fraud, compliance timing, and brittle recovery flows make wallet and authentication cutovers materially painful for bank teams that have to ship safely.
- Wedge · 5/5One bank, one wallet journey, and one cutover workflow make the entry product highly specific and directly researchable.
- Defense · 4/5The dependency graph, test harnesses, and bank-specific cutover data should compound beyond what point vendors or short-term consultants retain.
- Scale · 4/5The beachhead is narrow, but the same control layer can expand across more bank journeys and broader regulated identity infrastructure.
- Mobile-banking and authentication vendors already embedded at European banks
- Banking system integrators and digital-identity consultancies
- HSM, fraud, and wallet-issuer infrastructure providers
- Discover and model wallet-related authentication dependencies
- Orchestrate cutover plans, testing, and evidence generation for launch approval
- Maintain vendor connectors and bank-specific control policies
- Cross-vendor wallet and authentication dependency graph
- PQ migration playbooks and attack-test libraries for recovery and step-up flows
- Connectors into mobile-auth, fraud, HSM, and digital-identity stacks
- Turn wallet rollout into an approval-ready cutover plan across identity, fraud, and cryptography vendors
- Reduce recovery and step-up fraud risk while preparing authentication flows for post-quantum migration
- Produce reusable audit evidence and dependency maps instead of one-off consulting decks
- White-glove first cutover for one bank and one journey
- Security and fraud workshops that convert discovery into a funded pilot
- Multi-year expansion as additional wallet and authentication journeys move into scope
- Founder-led sales to heads of digital identity, security, and digital channels at European banks
- Partnerships with regional banking system integrators and digital-identity consultancies
- Design-partner programs with wallet, IAM, and mobile-banking vendors
- Mid-tier European retail banks launching EUDI wallet issuer or relying-party flows
- Fraud and authentication teams responsible for recovery and step-up controls in mobile banking
- Security and identity product engineering
- Solutions architecture and regulated-customer deployment
- Enterprise sales, compliance, and partner management
- Annual software subscription based on active wallet-auth journeys and connected systems
- Paid cutover services for first launch programs
- Expansion modules for continuous crypto-agility monitoring and relying-party policy control
Market
| TAM | $217.5M Estimate 290 fit banks (= 4,834 EU credit institutions × ~6% fit ratio for mid-tier retail banks with 1-5M digital customers and active EUDI timing) × $0.75M blended annual platform-plus-cutover spend. |
|---|---|
| SAM | $22.5M Estimate 30 reachable beachhead banks across CEE/DACH and adjacent first-wave pilot markets × $0.75M annual spend. |
| SOM | $4.5M Estimate 6 live bank customers by year 3 × $0.75M annual spend, assuming a narrow one-journey landing motion before broader expansion. |
Executive takeaways
- The strongest wedge is a bank-side cutover and evidence layer, not another wallet, MFA token, or cryptography SDK.
- Urgency is real because wallet rollout, deepfake fraud, and post-quantum planning are colliding in the same bank journeys.
- Competition is crowded at the control-point level, but no obvious vendor owns cross-vendor dependency mapping, dual-stack rollout, and launch evidence.
- The beachhead should stay narrow: one bank, one journey, one approval packet, starting with account opening, login, or high-value payment approval.
Market definition
Software for European retail banks that inventories authentication and wallet dependencies, stages a dual-stack cutover, pressure-tests recovery and step-up flows, and generates approval-ready evidence for EUDI-related launches.
Customer and buyer
Primary users are heads of digital identity and authentication, mobile-banking security leads, and fraud teams at mid-tier European retail banks. The economic buyer is usually the CISO or chief digital officer, with digital-channel and payments leaders as strong technical sponsors.
Buying triggers
- Wallet rollout has moved from standards work into bank-facing launch planning, with service-provider workflows, pilots, and account-opening use cases now concrete enough to trigger programs. [1][2][3][6][7]
- Banks are being pushed to prepare for wallet-based strong customer authentication, turning login and transaction approval into a near-term platform decision rather than a distant policy watch item. [9][10]
- Deepfake-driven identity fraud and account-takeover pressure make recovery and authentication controls easier to fund than compliance-only projects. [16][20][21][22]
- Post-quantum guidance has become phased migration planning, which forces earlier mapping of cryptographic dependencies inside authentication stacks. [23][24][28][29]
Willingness to pay
Willingness to pay is credible because banks already fund specialist identity vendors, and the wallet business-case evidence points to lower onboarding and authentication costs plus better risk management as a practical ROI story. [11][12][17][30]
Category dynamics
Tailwinds
- Wallet rollout is moving from pilots and reference implementations into concrete bank-facing onboarding and SCA use cases.
- Banks can use wallet flows for account opening, login, and payment authorisation, which creates a practical first-journey wedge.
- PQC migration now has phased timelines and financial-sector guidance, making crypto-agility easier to turn into a funded workstream.
Headwinds
- Current SCA is fragmented across mobile apps, SMS OTP, push approvals, and device-specific flows, so change management is expensive.
- Adjacent incumbents already sell identity, authentication, and fraud tools into the same buyers, so a new entrant must prove neutrality and speed.
Validation signals
- Large Scale Pilots involve 550 private companies and public authorities across 26 Member States plus Norway, Iceland, and Ukraine, including explicit payments and banking use cases.
- POTENTIAL includes bank account opening as a core wallet use case, confirming that private-sector onboarding is a real deployment target rather than a theoretical scenario.
- NOBID tested wallet onboarding, bank account linking, and online-store payments across multiple stakeholders, showing practical coordination complexity.
- Wultra says it serves more than 70 clients across 25 countries and raised fresh capital around wallet, fraud, and post-quantum demand.
- Signicat reports a steep rise in deepfake-driven identity fraud, which gives banks a non-compliance budget justification for stronger authentication and recovery controls.
Regulatory & technical constraints
- Wallet-relying service providers must register in their Member State and handle PID and attestation validation correctly before production use.
- Remote onboarding, protocols/interfaces, relying-party registration, and trust-framework implementing acts all affect launch design and can change over time.
- Wallet-based SCA depends on standards-aligned device-bound keys, attestation handling, and interoperable interfaces rather than simple UI changes.
- Post-quantum migration requires cryptographic inventory and phased upgrades, so banks need sequencing that fits existing authentication estates.
Competition
Competition is fragmented by layer. Wallet hubs and identity-proofing vendors help banks connect to EUDI flows; mobile authenticator and transaction-signing vendors secure specific control points; fraud platforms improve runtime decisions. The whitespace is a neutral bank-side workflow that maps cross-vendor breakpoints, stages the cutover, and packages evidence for risk, security, and launch approval.
| Competitor | Stage | Wedge | Pricing | Strength | Weakness vs. us |
|---|---|---|---|---|---|
| Wultra | scale-up | Post-quantum bank authentication, mobile-first MFA, and a digital identity wallet gateway for regulated institutions. | Custom enterprise pricing. | Very explicit bank, wallet, and PQC positioning, plus real specialist traction across multiple countries. | Owns important control points but not the neutral cross-vendor cutover and approval workflow the startup proposes. |
| Signicat | incumbent | Pan-European identity proofing, eID and wallet hub, and orchestration for regulated industries. | Custom enterprise pricing. | Broad identity-method coverage, strong banking positioning, and an obvious path into wallet connectivity. | Oriented toward identity access and orchestration rather than the brownfield bank cutover layer across recovery, device binding, and crypto-agility. |
| OneSpan | incumbent | Bank authentication, mobile authenticators, and transaction-signing infrastructure with EUDI readiness messaging. | Custom enterprise pricing. | Deep bank footprint and strong control over transaction authentication and tamper-evident approval. | Product-centric rather than workflow-centric, leaving room for a launch-specific dependency and evidence layer. |
| Entersekt | scale-up | Context-aware digital account authentication, 3-D Secure, and fraud-prevention for retail and commercial banks. | Custom enterprise pricing. | Strong runtime transaction integrity and fraud story for digital banking flows. | Less explicit on EUDI wallet readiness and post-quantum migration, and not positioned as the bank-side cutover system of record. |
Why incumbents do not win by default
- Mobile authentication and transaction-signing vendors. These vendors secure login and payment approval well, but they do not automatically become the cross-vendor program layer that inventories every dependency and prepares the launch packet.
- Identity hubs and wallet orchestration suites. Identity hubs can connect banks to wallet and eID methods, but they are not positioned as brownfield cutover systems for recovery, device binding, and crypto-agility across mixed stacks.
- Fraud and risk-auth platforms. Risk-aware authentication platforms help block attacks at runtime, yet they still leave banks to coordinate rollout sequencing, recovery redesign, and audit evidence across multiple suppliers.
- Consultants and internal program offices. Pilots and business-case work show that cross-organisation coordination is necessary, but project management alone does not leave behind a reusable dependency graph, test harness, or continuous control layer.
Business plan
Wallet Auth Cutover OS should launch as a bank-side cutover and evidence layer for EUDI-related authentication changes, not as another consumer wallet, MFA app, or cryptography SDK. The first customer is a Czech, Slovak, or Austrian retail bank with 1-3 million mobile customers, existing app-based soft-token authentication, and a funded 2026-2027 wallet or digital-ID program. Budget is most likely to release when a wallet pilot, a fraud review after a deepfake or account-takeover spike, or a board-level post-quantum workstream exposes cross-vendor dependencies across mobile auth, fraud, IAM, and signing systems. The initial product should stay read-only and focus on one journey—account recovery first, with high-value payment step-up as the immediate expansion path—by mapping dependencies, simulating attack and fallback paths, and generating an approval packet for risk and security sign-off. Research supports real urgency and specialist-software spend, but the modeled base market is still narrow at about $217.5M TAM, $22.5M SAM, and $4.5M year-3 SOM before adjacent expansion. The best scale path is to turn each launch packet into recurring crypto-agility monitoring, relying-party policy controls, and additional wallet-auth journeys inside the same bank. The biggest disconfirming risks are regulatory timing drift, incumbent or integrator compression, and whether banks will fund a neutral cutover layer instead of extending existing programs. Public inputs do not identify named target banks, exact budget owners, or whether recovery reliably beats payment approval as the first paid journey, so the first 6-9 months must prove buyer ownership, deployment speed, and paid cutover conversion.
Problem
- Mid-tier European banks must change wallet onboarding, recovery, device binding, and step-up authentication while EUDI rollout, deepfake fraud, and post-quantum migration all hit the same stack.
- Those changes span mobile-banking teams, IAM, fraud ops, HSM or signing vendors, wallet providers, and integrators, so banks lack a single workflow that finds breakpoints, sequences the cutover, and produces audit-ready launch evidence.
Solution
- Connect read-only to the bank's mobile-auth, fraud, wallet, and signing stack to build a dependency graph for one named journey, starting with account recovery, and generate a dual-stack cutover plan that shows where stronger device binding, PQ-safe signing, or fallback logic is required.
- Replay synthetic fraud and recovery scenarios against the planned journey and package the results into an approval packet for security, risk, compliance, and launch stakeholders so the bank can approve production without replacing incumbent systems.
Why we win
- The company owns the neutral cross-vendor cutover and evidence layer that wallet vendors, MFA providers, fraud tools, and consultants do not leave behind today.
- The first deal is attached to a named launch program and one approval packet, which is a faster proof point than asking banks to buy a bank-wide identity transformation upfront.
- Each deployment compounds a reusable graph of dependencies, control gaps, simulation outcomes, and approval artifacts that improves expansion and is hard for any single incumbent to recreate across mixed stacks.
| Beachhead | Mid-tier retail banks in CEE/DACH with 1-3 million mobile customers, app-based soft-token authentication, and a funded 2026-2027 EUDI issuer or relying-party launch, beginning with account-recovery cutover for retail banking journeys. |
|---|---|
| Wedge rationale | Account recovery is the narrowest entry point that combines immediate fraud pain, wallet-readiness pressure, and cross-vendor dependency sprawl. It creates faster proof than a broad wallet platform sale because one bank can tie budget to a concrete blocked journey, a known launch date, and a single approval packet. |
| Sequencing | Start with read-only discovery, simulation, and evidence generation on one common bank stack because trust barriers are high and banks already own the runtime control points. After 2-3 paid cutovers prove that launch approval can be shortened without replacing incumbents, add high-value payment step-up, continuous crypto-inventory monitoring, and partner-led distribution through vendors and regional integrators. |
| Not yet | Consumer wallet distribution or bank-issued wallet UX software · Full bank-wide IAM or fraud-platform replacement · Inline transaction decisioning before the read-only cutover motion is repeatable · Expansion outside EU-regulated identity programs before the bank wedge converts |
| Wedge | Sell a paid launch-readiness cutover for one account-recovery journey inside a live wallet or strong-customer-authentication program, then expand to high-value payment step-up once the first approval packet is accepted. |
|---|---|
| Channels | Founder-led outbound to heads of digital identity, authentication, and security at CEE/DACH retail banks · Integration and referral partnerships with mobile-auth, signing, and wallet vendors already embedded in target banks · Regional systems integrators and digital-identity consultancies that run wallet-readiness and security workshops |
| Funnel targets | Target-account intro→qualified design partner 15-20%, qualified design partner→paid cutover 35%+, paid cutover→annual platform 60%+, first production logo→second-journey expansion within 12 months 50%+. |
| Pricing | Start with a fixed paid cutover package for one journey plus an annual subscription priced by active wallet-auth journeys and connected identity domains, because the buyer is paying to clear a named launch and then keep the control layer live. Initial working assumption is $150k-$250k for the first cutover and $400k-$600k ARR for the first production environment, which roughly matches the researched $750k blended bank-year spend once services and software are combined. |
| MVP | MVP should support read-only ingestion from one common mobile-auth, wallet, fraud, and signing stack; dependency mapping for one account-recovery journey; a dual-stack cutover plan; synthetic fraud and fallback simulation; and an approval packet that includes attestation, registration, and post-quantum inventory checkpoints. It should deliver approval-ready output without taking inline control of credentials or replacing wallet orchestration software. |
|---|---|
| 6 months | Complete 2-3 paid recovery cutovers on the first common stack, ship the dependency graph, simulation harness, and approval-packet template, and prove that the median kickoff-to-review packet stays at or below 60 days. |
| 12 months | Add high-value payment step-up as the second journey, launch continuous crypto-inventory monitoring and a living rules library for relying-party and attestation requirements, and convert the first production banks into multi-year subscriptions. |
| 24 months | Become the bank-side system of record for wallet-auth cutovers across recovery, payment approval, login, and onboarding, then extend the same control layer into adjacent regulated identity programs such as insurers or wealth platforms. |
| Key bets | Banks will approve a read-only cutover and evidence layer faster than any new inline control plane. · Account recovery will win budget faster than login or account opening because fraud pressure is immediate and measurable. · One common regional stack will appear often enough to standardize connectors and keep deployments productizable. · Approval packets plus simulation telemetry will create expansion into second journeys and recurring crypto-agility monitoring. |
| Revenue streams | Annual subscription for the wallet-auth cutover and evidence layer · Paid cutover packages for each new launch program or regulated journey · Expansion modules for continuous crypto-agility monitoring, relying-party policy control, and additional identity domains |
|---|---|
| Unit of value | Active wallet-auth journey under managed cutover and evidence control |
| Target gross margin | 70% |
| Expansion levers | Add second and third journeys such as payment approval, login, and onboarding inside the same bank · Expand from one bank entity or country program to additional business units and connected identity domains · Upsell continuous crypto-inventory monitoring and rules updates as wallet obligations evolve |
| North-star metric | Production wallet-auth journeys approved and launched with an accepted evidence packet and no unresolved high-risk recovery gaps |
|---|---|
| Input metrics | Median days from kickoff to approval-packet acceptance · Paid cutover to annual subscription conversion rate · Percentage of critical dependencies mapped before launch · Number of high-risk recovery or step-up gaps fixed before go-live · Second-journey expansion rate inside production banks |
| Moats to build | Dependency graph across mobile auth, wallet, fraud, and signing stacks by journey and vendor owner · Synthetic fraud, fallback, and launch-readiness telemetry from real bank cutovers · Reusable approval packets and rules libraries for EUDI, attestation handling, and phased PQ migration · Integration footprint with incumbent vendors that makes the product the neutral system of record across mixed stacks |
| Kill criteria | Fewer than 6 of the first 20 target banks can name a funded wallet or SCA cutover inside 12 months. · More than 2 of the first 5 pilots require over 60 days or more than 2 bespoke connectors to produce an approval packet. · Fewer than 3 of the first 5 paid cutovers convert to annual subscriptions above $400k ARR. · More than 60% of late-stage opportunities are absorbed by incumbent vendor extensions or SI-led projects. |
Milestones
- Sign 3 paid cutovers with CEE/DACH mid-tier banks.
- Deliver the first approval-ready account-recovery packet within 60 days on the initial common stack.
- Convert at least 2 paid cutovers into annual subscriptions and expand 1 bank into high-value payment step-up.
- Ship the first rules library for relying-party, attestation, and PQ inventory requirements.
- Reach 4-5 production bank logos and at least 2 partner-sourced deployments.
- Add continuous crypto-inventory monitoring and support for a second and third wallet-auth journey.
- Keep median kickoff-to-approval-packet time at or below 60 days as deployments scale.
- Reach 6 live bank customers and the modeled year-3 SOM.
- Expand at least half of production banks into a second journey or additional identity domain.
- Enter one adjacent regulated segment only after the bank deployment playbook and partner motion are repeatable.
flowchart LR Wedge[Account-recovery cutover wedge] --> MVP[Read-only dependency map and evidence MVP] MVP --> Proof[Approval packet accepted and launch accelerated] Proof --> Expansion[More journeys plus recurring crypto-agility control layer]
Founding team
| Role | Start timing | Rationale |
|---|---|---|
| Founder CEO | Month 0 | Own buyer discovery, founder-led bank sales, pricing, and the launch-approval narrative until the motion converts on its own. |
| Founding eng | Month 0 | Build the dependency graph, simulation harness, evidence generator, and first integrations on the chosen bank stack. |
| Identity security solutions architect | Month 2 | Turn early pilots into repeatable approval packets, deployment playbooks, and customer-side control mappings that clear security review faster. |
| Integrations engineer | Month 4 | Productize connectors into mobile-auth, fraud, signing, and wallet vendors so deployments stop depending on founder-written scripts. |
| Second platform engineer | Month 7 | Harden telemetry, rules updates, and recurring monitoring modules needed for annual subscriptions and second-journey expansion. |
| Partnerships lead | Month 10 | Add partner-sourced pipeline only after the first paid cutovers prove a repeatable bank motion and a clear complement to incumbents. |
Experiment roadmap
| Horizon | Experiment | Hypothesis | Success metric | Owner |
|---|---|---|---|---|
| 0–90 days | Journey and buyer mapping interviews | The beachhead will show one repeatable trigger, one common buyer committee, and one first journey that consistently releases budget. | 15 target-bank interviews, 10 qualified accounts, and 8 accounts with a named sponsor plus launch or fraud trigger inside 12 months. | Founder CEO |
| 0–90 days | Concierge dependency-map pilot | Even one recovery journey will expose enough undocumented vendor dependencies to justify a dedicated cutover workflow. | 3 design partners each reveal 20 or more mapped dependencies and at least 1 previously unknown launch-blocking gap. | Founding eng |
| 90–180 days | Synthetic fraud and approval-packet pilot | Security and risk stakeholders will treat simulated attack and fallback evidence as materially better than spreadsheet-based launch reviews. | 2 design partners accept the evidence packet as a valid production-review input and identify at least 1 remediated high-risk gap before go-live. | Identity security solutions architect |
| 90–180 days | Paid cutover packaging test | Banks will fund a fixed-scope cutover before committing to a broader annual platform purchase. | 3 signed paid cutovers in the target price range with explicit conversion terms into annual subscriptions. | Founder CEO |
| 6–12 months | Repeatable 60-day deployment | The first common stack can be productized enough to keep deployments short and gross margins intact. | 4 of the first 5 pilots reach an approval-ready packet in 60 days or less with no more than 2 bespoke connectors each. | Integrations engineer |
| 12–18 months | Partner-sourced launch motion | Mobile-auth vendors and regional integrators can source qualified paid cutovers without materially worse conversion than founder-led deals. | 25% of qualified pipeline comes from 2 active partners and partner-sourced paid cutovers convert to production at 50% or better. | Partnerships lead |
Risk assessment
- R1Wallet rollout timing drifts by country or bank, weakening a compliance-only urgency story. — Sell fraud-safe recovery and faster approval as the first ROI and prioritize banks that already have funded launch programs.
- R2Incumbent authentication vendors or systems integrators claim the cutover scope as an extension of existing projects. — Position as the neutral mixed-stack evidence layer, prove faster approval on one journey, and use the strongest incumbents as channels where possible.
- R3Integration and security-review friction make deployments too slow or too custom for seed-stage economics. — Start read-only, narrow the first stack, standardize connectors, and refuse bespoke inline-control work until the core motion is repeatable.
- R4Budget ownership stays fragmented across CISO, digital, fraud, and payments teams, stretching sales cycles. — Anchor every sale to one named journey, one approval packet, and one accountable sponsor before entering procurement.
- R5The base bank wedge is too small to support venture outcomes if expansion does not materialize quickly. — Track second-journey expansion and recurring monitoring uptake in the first production logos before increasing burn or broadening geography.
| Risk | Likelihood | Impact | Mitigation |
|---|---|---|---|
| Wallet rollout timing drifts by country or bank, weakening a compliance-only urgency story. | Medium | High | Sell fraud-safe recovery and faster approval as the first ROI and prioritize banks that already have funded launch programs. |
| Incumbent authentication vendors or systems integrators claim the cutover scope as an extension of existing projects. | High | High | Position as the neutral mixed-stack evidence layer, prove faster approval on one journey, and use the strongest incumbents as channels where possible. |
| Integration and security-review friction make deployments too slow or too custom for seed-stage economics. | Medium | High | Start read-only, narrow the first stack, standardize connectors, and refuse bespoke inline-control work until the core motion is repeatable. |
| Budget ownership stays fragmented across CISO, digital, fraud, and payments teams, stretching sales cycles. | High | Medium | Anchor every sale to one named journey, one approval packet, and one accountable sponsor before entering procurement. |
| The base bank wedge is too small to support venture outcomes if expansion does not materialize quickly. | Medium | High | Track second-journey expansion and recurring monitoring uptake in the first production logos before increasing burn or broadening geography. |
| Title | Head of Digital Identity at a mid-tier CEE/DACH retail bank |
|---|---|
| Profile | A Czech, Slovak, or Austrian retail bank with 1-3 million mobile customers, app-based soft-token authentication, and a funded 2026-2027 wallet or digital-ID launch that exposes brittle recovery flows across mobile, fraud, and signing systems. |
| Trigger | A wallet pilot, fraud review after a deepfake or account-takeover spike, or post-quantum migration workstream reveals that account recovery cannot clear production review on the current stack. |
| Buyer | CISO or Chief Digital Officer |
| Initial contract | $150k-$250k paid cutover for one account-recovery journey, converting to roughly $400k-$600k ARR once the bank keeps the control layer live and expands into high-value payment step-up. |
What must be true
- At least half of qualified target banks must have a named wallet or SCA launch with budget and an accountable sponsor inside 12 months.
- Account recovery must repeatedly win the first paid scope over login, account opening, or payment approval in early buyer discovery.
- The product must deliver an approval-ready dependency map and evidence packet in 60 days or less on the first common stack.
- At least 3 of the first 5 paid cutovers must convert to annual subscriptions above $400k ARR.
- The neutral cutover layer must beat incumbent-vendor or SI-led alternatives in at least 40% of competitive evaluations.
Open diligence questions
- Which first journey consistently releases budget fastest in target accounts: account recovery, payment approval, login, or onboarding?
- Which executive actually controls the budget for wallet-auth cutover in the beachhead: CISO, chief digital officer, fraud lead, or payments owner?
- Which vendor stack combinations dominate the first 20 target banks and therefore determine integration order?
- What evidence, simulation output, and governance artifacts are required for a bank to treat the approval packet as launch-ready?
- Can incumbent vendors and regional integrators be turned into channels before they use their installed base to compress the category?
| Call | Watch |
|---|---|
| Conviction | Compelling timing and wedge clarity, but conviction stays moderate until the company proves a named budget owner and repeatable sub-60-day deployments. |
| Why believe | Banks already buy specialist identity vendors, and no obvious incumbent owns the cross-vendor cutover plus evidence workflow this plan targets. |
| Why doubt | The base market is modest and the product can collapse into services work or incumbent add-ons before a durable standalone category forms. |
| Next diligence | Confirm 3 paid bank cutovers where the approval packet shortens launch readiness, survives security review, and converts to $400k+ ARR. |
Financial model
| Year 1 revenue | $870K EBITDA $-784K · Cash EOP $1.72M |
|---|---|
| Year 2 revenue | $2.82M EBITDA $-431K · Cash EOP $1.29M |
| Year 3 revenue | $4.11M EBITDA $33K · Cash EOP $1.32M |
| ARPU (annual) | $720K |
|---|---|
| Gross margin | 70% |
| CAC | $438K Payback 10.4 months |
| LTV / CAC | 6.4x LTV $2.80M |
| Round | pre-seed · $2.5M |
|---|---|
| Runway | 24 months |
| Milestone | Reach 5 production bank logos, 2 partner-sourced deployments, repeatable <=60-day approval packets on one common stack, and the first payment step-up expansion before the seed round. |
Model sanity
- Revenue engine. Base-case revenue comes from moving from 3 paid banks at Y1 exit to 5 production logos at Y2 exit and 6 live banks at Y3 exit at about $720K of blended annual spend per bank-year.
- Must go right. The company has to keep the first common-stack deployments near the 60-day target so it can reach 5 production logos before adding much more delivery headcount.
- Model breaks if. If the business slips toward the downside case of 5 Y3 banks, $680K ARPU, and 68% gross margin, cash turns slightly negative before the next round.
- Next-round proof. The seed narrative is credible once 5 production logos, 2 partner-sourced deployments, and the first payment step-up expansion are live with a visible cash buffer still on the balance sheet.
- Revenue (line, area)
- Cash EOP (dashed)
- EBITDA (bars, gray = loss)
- Founder CEO
- Founding eng
- Identity security solutions architect
- Integrations engineer
- Second platform engineer
- Partnerships lead
- Product engineer
- Deployment success engineer
- Compliance / program ops
- Account executive
| Y3 revenue | Y3 EBITDA | Cash low point | Description | |
|---|---|---|---|---|
| Downside | Wallet-auth programs convert more slowly and banks stay longer in recovery-only scope, leaving the company at 5 live banks by Y3 exit with lower ARPU and weaker delivery leverage. | |||
| Base | The base case converts the first paid cutovers into a 5-logo production footprint by Y2 exit, then adds a sixth live bank and first meaningful second-journey expansion in Y3. | |||
| Upside | Reference customers and partner referrals pull one extra bank forward, lift blended scope per bank, and let the company reuse more of the common stack. |
| Variable | Downside | Upside | Cash impact | Revenue impact |
|---|---|---|---|---|
| hiring pace | Product, deployment, compliance, and AE hiring all pull forward by about 6 months because delivery stays too bespoke. | Compliance and AE hiring can both slip about one quarter without hurting delivery because the first stack stays templated. | ||
| churn | Retention behaves like the company exits Y3 with 5 live banks instead of 6 because one early logo stalls before broader expansion. | Retention and expansion behave like the company exits Y3 with 7 live banks because the first logos embed the workflow into launch governance. | ||
| ARPU | Blended annual bank-year revenue settles at $680K because buyers hold the company at recovery-only scope for longer. | Blended annual bank-year revenue reaches about $760K as step-up and monitoring attach earlier. | ||
| sales cycle | A quarter of extra security review and procurement slippage pushes each major logo inflection back by roughly one quarter. | Reference accounts and partner intros pull one bank forward by roughly a quarter in both Y2 and Y3. | ||
| gross margin | Gross margin stays at 68% because approval packets, integrations, and governance work remain too manual. | Gross margin reaches 72% as more of the connector and rules-library work is reused across banks. | ||
| CAC | Effective CAC rises as S&M intensity climbs about 1.5 points of revenue from heavier bank travel, workshops, and risk-review handholding. | S&M intensity falls about 1 point of revenue as partner introductions warm up the pipeline. |
Scenarios
| Scenario | Y3 revenue | Y3 EBITDA | Cash low point | Description | Key changes |
|---|---|---|---|---|---|
| Downside | $3.20M | $-592K | $-66K | Wallet-auth programs convert more slowly and banks stay longer in recovery-only scope, leaving the company at 5 live banks by Y3 exit with lower ARPU and weaker delivery leverage. |
|
| Base | $4.11M | $33K | $1.21M | The base case converts the first paid cutovers into a 5-logo production footprint by Y2 exit, then adds a sixth live bank and first meaningful second-journey expansion in Y3. |
|
| Upside | $5.10M | $698K | $1.73M | Reference customers and partner referrals pull one extra bank forward, lift blended scope per bank, and let the company reuse more of the common stack. |
|
Sensitivity
| Variable | Downside | Base | Upside |
|---|---|---|---|
| ARPU | Blended annual bank-year revenue settles at $680K because buyers hold the company at recovery-only scope for longer. | Blended annual bank-year revenue stays at $720K as half of production banks add a second journey or monitoring by Y3. | Blended annual bank-year revenue reaches about $760K as step-up and monitoring attach earlier. |
| CAC | Effective CAC rises as S&M intensity climbs about 1.5 points of revenue from heavier bank travel, workshops, and risk-review handholding. | Modeled CAC stays near $438K per new production logo in a founder-led plus partner-assisted motion. | S&M intensity falls about 1 point of revenue as partner introductions warm up the pipeline. |
| churn | Retention behaves like the company exits Y3 with 5 live banks instead of 6 because one early logo stalls before broader expansion. | The base path assumes 1.5% monthly churn while still reaching 6 live banks by Y3 exit. | Retention and expansion behave like the company exits Y3 with 7 live banks because the first logos embed the workflow into launch governance. |
| sales cycle | A quarter of extra security review and procurement slippage pushes each major logo inflection back by roughly one quarter. | Paid cutovers still convert on the plan's timeline once the first common stack is proven and the approval packet lands inside 60 days. | Reference accounts and partner intros pull one bank forward by roughly a quarter in both Y2 and Y3. |
| gross margin | Gross margin stays at 68% because approval packets, integrations, and governance work remain too manual. | Gross margin stays at the 70% business-plan target. | Gross margin reaches 72% as more of the connector and rules-library work is reused across banks. |
| hiring pace | Product, deployment, compliance, and AE hiring all pull forward by about 6 months because delivery stays too bespoke. | Hiring follows A21 and waits for evidence that the common stack and partner motion are repeatable. | Compliance and AE hiring can both slip about one quarter without hurting delivery because the first stack stays templated. |
Key assumptions (26)
| ID | Name | Value | Unit | Source |
|---|---|---|---|---|
| A1 | Model start month | 2026-07 | YYYY-MM | [business-plan.yaml date] first full operating month after the 2026-06-30 plan date. |
| A2 | Opening cash after pre-seed close | 2500 | USDK | [business-plan.yaml fundingAsk.targetFundingRangeUsd; business-plan.yaml fundingAsk.runwayMonths] modeled at the low end of the stated $2.5-3.5M range so the company can fund a full proof window and still hold a procurement buffer. |
| A3 | Revenue unit | Active paying bank logo/program | definition | [business-plan.yaml businessModel.unitOfValue; business-plan.yaml milestones] customer count tracks active paying bank logos, while second-journey expansion is reflected in ARPU rather than a second customer count. |
| A4 | Blended annual revenue per active bank-year | 720 | USDK/account-year | [business-plan.yaml gtm.pricing; research.yaml bottomUpSizingDrivers] midpoint pricing implies about $700K per bank-year; base case lifts to $720K once at least half of production banks add payment step-up or monitoring by Y3, while still staying below the researched $750K bank-year. |
| A5 | Revenue recognition timing | Midpoint customer count within each month or quarter | policy | [startup-finance heuristic] new bank programs are assumed to land halfway through the period on average, so recognized revenue uses midpoint active-customer count. |
| A6 | Y1 month-end customer path | 0,0,0,1,1,1,1,2,2,2,3,3 | active paying bank logos | [business-plan.yaml milestones 0-12 months; experimentRoadmap Paid cutover packaging test] reaches 3 paid bank programs by Y1 exit after landing logos around months 4, 8, and 11. |
| A7 | Y2 quarter-end customers | Q1Y2 3; Q2Y2 4; Q3Y2 4; Q4Y2 5 | active paying bank logos | [business-plan.yaml milestones 12-24 months] base case reaches 5 production bank logos by Y2 exit, with Q1 held flat while the first paid cutovers convert and partner-sourced demand starts. |
| A8 | Y3 quarter-end customers | Q1Y3 5; Q2Y3 6; Q3Y3 6; Q4Y3 6 | active paying bank logos | [business-plan.yaml milestones 24-36 months; business-plan.yaml market.som; research.yaml market.som] reaches 6 live bank customers by Y3 exit, consistent with the plan's modeled SOM. |
| A9 | Gross margin target | 70 | percent | [business-plan.yaml businessModel.targetGrossMarginPct] modeled as 30% COGS on recognized revenue. |
| A10 | Monthly churn for unit economics | 1.5 | percent | [startup-finance heuristic] sticky bank infrastructure should churn slowly, but a narrow ICP and long deployment cycles justify a conservative enterprise-infrastructure churn assumption rather than near-zero churn. |
| A11 | Founder CEO loaded cash compensation | 150 | USDK/year | [business-plan.yaml team Founder CEO] startup-finance heuristic for below-market founder cash plus payroll taxes and benefits. |
| A12 | Founding eng loaded cash compensation | 210 | USDK/year | [business-plan.yaml team Founding eng] startup-finance heuristic for early security-infrastructure technical founder cash comp. |
| A13 | Identity security solutions architect loaded cash compensation | 190 | USDK/year | [business-plan.yaml team Identity security solutions architect] startup-finance heuristic for a senior bank-identity specialist with customer-facing security credibility. |
| A14 | Integrations engineer loaded cash compensation | 175 | USDK/year | [business-plan.yaml team Integrations engineer] startup-finance heuristic for connector-heavy enterprise integration talent. |
| A15 | Second platform engineer loaded cash compensation | 185 | USDK/year | [business-plan.yaml team Second platform engineer] startup-finance heuristic for an experienced platform engineer supporting rules libraries, monitoring, and telemetry. |
| A16 | Partnerships lead loaded cash compensation | 155 | USDK/year | [business-plan.yaml team Partnerships lead] startup-finance heuristic for an early channel and alliances operator in enterprise security software. |
| A17 | Product engineer loaded cash compensation | 180 | USDK/year | [business-plan.yaml product twelveMonth; milestones 12-24 months] startup-finance heuristic for the additional engineer needed to ship payment step-up and monitoring modules after recovery proof. |
| A18 | Deployment success engineer loaded cash compensation | 160 | USDK/year | [business-plan.yaml operations; milestones 12-24 months] startup-finance heuristic for a technical delivery hire that keeps implementations inside the 60-day target. |
| A19 | Compliance / program ops loaded cash compensation | 145 | USDK/year | [business-plan.yaml risks; investorMemo] startup-finance heuristic for governance, documentation, and bank-program coordination capacity once pilots scale. |
| A20 | Account executive loaded cash compensation | 185 | USDK/year | [business-plan.yaml gtm channels; milestones 12-24 months] startup-finance heuristic for one enterprise seller added only after partner-sourced demand starts to repeat. |
| A21 | Hiring cadence | Founder CEO and founding eng M1; architect M3; integrations M5; second platform M8; partnerships M11; product engineer M13; deployment success M14; compliance/program ops M18; account executive M25 | timing | [business-plan.yaml team; strategicChoices.sequencingRationale; product twelveMonth] GTM hires lag technical proof, with the first true sales hire added only after partner motion and repeatable delivery are in place. |
| A22 | Functional payroll allocation | Founder CEO 70% S&M / 30% G&A; founding eng 100% R&D; architect 65% R&D / 35% G&A; integrations 100% R&D; second platform 100% R&D; partnerships 80% S&M / 20% G&A; product engineer 100% R&D; deployment success 50% R&D / 50% G&A; compliance/program ops 100% G&A; account executive 100% S&M | allocation | [business-plan.yaml team rationales; operations] allocation follows who sells the wedge, who productizes the common stack, and who carries governance or deployment load. |
| A23 | Non-payroll operating spend | Y1 S&M 12K + 4% of revenue monthly, R&D 22K + 1.4K per average customer monthly, G&A 15K + 0.8K per average customer monthly; Y2 S&M 14K + 4.5% of revenue, R&D 26K + 1.6K per average customer, G&A 17K + 0.9K per average customer; Y3 S&M 16K + 4.5% of revenue, R&D 27K + 1.8K per average customer, G&A 18K + 1.0K per average customer | USDK/month | [startup-finance heuristic] covers bank travel, cloud test environments, security tooling, legal, audit, and procurement overhead for a narrow but high-friction enterprise motion. |
| A24 | Cash conversion policy | EBITDA approximates operating cash movement | policy | [startup-finance heuristic] no debt, capex, taxes, or material working-capital swings are modeled separately at this stage. |
| A25 | Blended CAC per new production bank logo | 438.3 | USDK/new logo | Calculated from modeled Y2-Y3 sales and marketing spend of 1314.9K divided by 3 net new production bank logos. |
| A26 | Next-round milestone | 5 production bank logos, 2 partner-sourced deployments, repeatable 60-day approval packets on one common stack, and the first payment step-up expansion | milestone | [business-plan.yaml milestones 12-24 months; business-plan.yaml fundingAsk.useOfFundsSummary] used to size the current round plus a six-month operating buffer. |
flowchart LR TargetBanks --> PaidCutovers PaidCutovers --> ProductionBanks ProductionBanks --> ExpansionJourneys ProductionBanks --> Revenue ExpansionJourneys --> Revenue Revenue --> GrossProfit GrossProfit --> Cash
Flags: The base case still concentrates more than $4.1M of Y3 revenue into only 6 bank customers, so one delayed expansion or non-renewal matters a lot. · CAC is high at about $438K per new production logo because founder-led bank sales, partner enablement, and procurement overhead remain heavy. · Gross margin only holds at 70% if connector reuse and approval-packet templating prevent the company from drifting into bespoke services work. · The funding ask is only at the low end of the business-plan range, and the downside case still turns cash slightly negative before the next round.
Top risks
- Regulatory timing drift. Country-by-country wallet rollout dates may slip, stretching sales cycles if the product depends only on compliance deadlines. Mitigation: Start with banks that already have funded launch programs and sell fraud-safe recovery plus faster approval as the first ROI, not compliance alone.
- Incumbent and integrator squeeze. Existing authentication vendors or systems integrators may claim they can extend current projects to cover the same workflow. Mitigation: Position as the cross-vendor cutover and evidence layer that complements incumbents, and prove value by reducing launch time across mixed stacks they do not unify.
- Integration liability. Touching identity and recovery infrastructure can create long deployments and high trust barriers for a young startup. Mitigation: Launch with read-only discovery, testing, and evidence generation for one journey before taking on inline orchestration or credential-sensitive controls.
Evidence
Cited sources (36)
- European Commission. Wallet for service providers · https://ec.europa.eu/digital-building-blocks/sites/spaces/EUDIGITALIDENTITYWALLET/pages/881984674/Wallet+for+service+providers
- European Commission. What are the Large Scale Pilot Projects · https://ec.europa.eu/digital-building-blocks/sites/spaces/EUDIGITALIDENTITYWALLET/pages/694487808/What+are+the+Large+Scale+Pilot+Projects
- European Commission. About the initiative · https://ec.europa.eu/digital-building-blocks/sites/spaces/EUDIGITALIDENTITYWALLET/pages/694487832/About+the+initiative
- European Commission. The European Digital Identity Regulation · https://ec.europa.eu/digital-building-blocks/sites/spaces/EUDIGITALIDENTITYWALLET/pages/915931811/The+European+Digital+Identity+Regulation
- European Digital Identity. Specification of Strong Customer Authentication (SCA) Implementation with the Wallet · https://eudi.dev/latest/technical-specifications/ts12-specification-of-strong-customer-authentication-%28sca%29-Implementation-with-the-Wallet/
- Luxembourg Government. POTENTIAL Consortium for a European digital wallet · https://gouvernement.lu/en/dossiers.gouv2024_mindigital%2Ben%2Bdossiers%2B2023%2Bpotential.html
- NOBID Consortium. NOBID wraps up pilot under the EU Digital Identity Wallet Programme · https://www.nobidconsortium.com/nobid-wraps-up-successful-pilot-under-the-european-digital-identity-wallet-programme/
- European Banking Federation. Facts & Figures 2025 · https://www.ebf.eu/ebf-media-centre/ebf-facts-and-figures-2025/
- Lissi. EUDI Wallet based Strong Customer Authentication and payment for Financial Services · https://www.lissi.id/blog/introducing-eudi-wallet-based-strong-customer-authentication-for-financial-services-for-payment
- OneSpan. Why European banks must act now on EUDI Wallets · https://www.onespan.com/cybersecurity/blog/why-european-banks-must-act-now-on-EUDI-wallets
- Mobey Forum. Mapping the Business Case: Banks and the European Digital Identity Wallet · https://paymentsindustryintelligence.com/wp-content/uploads/2025/05/Mapping-the-Business-Case-Banks-and-the-European-Digital-Identity-Wallet.pdf
- Wultra. Wultra Raises €6.8 Million in Series A Funding to Accelerate Global Expansion of Post-Quantum Digital Identity Solutions - Blog | Wultra · https://www.wultra.com/blog/wultra-raises-68-million-eur-in-series-a
- Wultra. Digital ID Wallet Gateway │ Wultra · https://www.wultra.com/products/digital-identity-wallet-gateway
- Wultra. Post-Quantum Authentication · https://www.wultra.com/post-quantum-authentication
- Wultra. Mobile-First Authentication │ Wultra · https://www.wultra.com/products/mobile-first-authentication
- Signicat. Fraud attempts with deepfakes have increased by 2137% over… · https://www.signicat.com/press-releases/fraud-attempts-with-deepfakes-have-increased-by-2137-over-the-last-three-year
- Signicat. EUDI Wallet solutions: Connect to Europe's digital identity… · https://www.signicat.com/use-cases/eudi-wallet
- Signicat. Banking industry · https://www.signicat.com/industries/banking-industry
- Signicat. eID and Wallet Hub · https://www.signicat.com/products/identity-proofing/eid-hub
- Deloitte. Generative AI is expected to magnify the risk of deepfakes and other fraud in banking · https://www.deloitte.com/us/en/insights/industry/financial-services/deepfake-banking-fraud-risk-on-the-rise.html
- World Economic Forum. Unmasking Cybercrime: Strengthening Digital Identity Verification against Deepfakes · https://reports.weforum.org/docs/WEF_Unmasking_Cybercrime_Strengthening_Digital_Identity_Verification_against_Deepfakes_2026.pdf
- SAS. Study: Deepfake fraud surges – and only 7% of organizations are firmly ready · https://www.sas.com/en_us/news/press-releases/2026/march/acfe-anti-fraud-technology-study-deepfakes.html
- NCSC. Timeline for PQC migration revealed · https://www.ncsc.gov.uk/news/pqc-migration-roadmap-unveiled
- NIST. Transition to Post-Quantum Cryptography Standards · https://csrc.nist.gov/pubs/ir/8547/ipd
- NIST. Module-Lattice-Based Key-Encapsulation Mechanism Standard · https://csrc.nist.gov/pubs/fips/203/final
- NIST. Module-Lattice-Based Digital Signature Standard · https://csrc.nist.gov/pubs/fips/204/final
- NIST. Stateless Hash-Based Digital Signature Standard · https://csrc.nist.gov/pubs/fips/205/final
- Europol. Prioritising Post-Quantum Cryptography Migration Activities in Financial Services · https://www.europol.europa.eu/cms/sites/default/files/documents/Post-quantum-cryptography-report.pdf
- FS-ISAC. The Timeline for Post Quantum Cryptographic Migration · https://www.fsisac.com/hubfs/Knowledge/PQC/PQC%20Timelines.pdf?hsLang=en
- OneSpan. Digipass Cloud (formerly OneSpan Cloud Authentication) · https://www.onespan.com/cybersecurity/products/onespan-cloud-authentication
- OneSpan. Mobile Authenticator Studio | OneSpan · https://www.onespan.com/cybersecurity/products/mobile-authenticator-studio/overview
- OneSpan. Digipass transaction signing authenticators · https://www.onespan.com/cybersecurity/products/digipass-transaction-signing-authenticators
- Entersekt. Retail & commercial banks - Solutions | Entersekt · https://www.entersekt.com/solutions/industries/retail-commercial-banks
- Entersekt. Digital account authentication - Platform | Entersekt · https://www.entersekt.com/platform/authentication
- European Digital Identity. Topic Z - Device-bound Attestations · https://eudi.dev/latest/discussion-topics/z-device-bound-attestations/
- European Digital Identity. AA - Support of Electronic Payments Customer Authentication (SCA) with the Wallet · https://eudi.dev/latest/discussion-topics/aa-support-of-electronic-payments-SCA-with-wallet/