BlogGuides
Website with SPID login: when it really matters and to whom

One click, and Google will show my articles more often in your results.
Anyone searching for "website with SPID login" has usually already heard that public administration in Italy stopped accepting its own credentials a few years ago, and wonders whether the same rule is about to reach their own business website. The short answer is that, for most private businesses, that rule never arrives: the obligation exists, but it targets a specific group of entities, and a shop, a practice or a hotel isn't one of them.
Who is legally required to offer it
Article 64 of Italy's Digital Administration Code requires access via SPID or CIE for online services that need digital identification. The obligation doesn't stop at public administration in the strict sense: article 2, paragraph 2 of the same Code extends its scope to "public service operators", a category that explicitly includes listed companies and publicly controlled companies when they provide services of public interest, not just the local energy, water or transport utilities people usually picture (source: Normattiva, Digital Administration Code, Legislative Decree 82/2005, articles 2 and 64, checked on 27 September 2026).
To gauge how seriously this rule is enforced, it helps to look at what already happened to public administration itself: from 28 February 2021, under the Semplificazioni decree (Decree-Law 76/2020), public administrations could no longer issue or renew their own credentials other than SPID, CIE or the National Services Card; old credentials stayed valid only until their natural expiry, and no later than 30 September 2021 in any case. Outside that boundary, meaning for an ordinary private business, there's no equivalent deadline, because there's no obligation for one to expire: adoption stays optional, always.
What offering it actually involves, if you're not required to
Adding a "log in with SPID" button isn't an afternoon's work. To do it, a business has to get accredited with Italy's Digital Agency (AgID) as a Service Provider, build a technical infrastructure that meets the system's specifications, and sign an agreement to join the SPID federation: a path built for structured companies, with validation timelines and organizational requirements a small business rarely already has in place.
There's also an ongoing cost, not just the upfront development one. AgID regulates the fees a private Service Provider pays to identity providers through a pay-per-use model set by Determination no. 166/2019, still the current reference today. For level 1-2 credentials, the most widely used, authentication is free up to 1,000 unique users per year for each identity provider, then costs 0.40 euros plus VAT for every additional user; registering a new user, instead, always costs 3.50 euros plus VAT, with no free threshold at all (source: AgID, Annex 4 to Determination 166/2019, "SPID Authentication Service Fees", checked on 27 September 2026). On a service with thousands of new registrations a year, that's a real cost, not a symbolic one.
Who it's worth it for anyway
The reason a private business chooses this route anyway, despite the cost and the complexity, is almost always the same: it needs to know with certainty who's on the other side of the screen before offering them a service, because getting someone's identity wrong would be expensive. That's the typical case in the financial and insurance sectors, where verifying a customer's identity isn't a convenience but a step sector-specific rules already require in some form, and SPID offers a way to do it with data already certified by an accredited identity provider, instead of building that verification from scratch.
For most small and medium businesses, a shop, a professional practice, a hotel, an e-commerce site, that need simply doesn't exist: the customer signs up with a name, an email and a password, and there's no identity mistake serious enough to justify the complexity of an AgID accreditation. Anyone still considering offering it, perhaps to give customers a faster way to log in, has a more realistic route than direct accreditation: relying on an aggregator already accredited by AgID, which acts as an intermediary toward the public infrastructure in exchange for its own fee. It's still an added cost to weigh against a benefit that, for a business like this, is often more perceived than real.
What changes in the coming years
One upcoming shift involves a different system from SPID, but points in the same direction. From 24 December 2027, the European eIDAS2 regulation (Regulation EU 2024/1183, article 5f) will require a range of regulated private sectors, including banks, insurance, telecommunications, energy, transport, healthcare and education, to accept the European Digital Identity Wallet, set to become Italy's IT-Wallet, whenever strong customer verification is needed. For now the obligation applies only to those specific sectors, not to private businesses in general, but it signals where digital identity rules are heading over time.
Where to start
If your business isn't a public service operator, you have no obligation today to add SPID login to your website. If you do have a concrete reason to want it anyway, the useful first step is working out whether that reason is really worth the per-user cost and the complexity of accreditation, or whether a client portal with its own credentials, which I wrote about in website with a client portal: when it's worth it, solves the same problem more simply. If you're not sure which case is yours, get in touch and we can talk it through.
Another digital obligation that follows the same logic, depending on what your website does rather than on your turnover, is website accessibility: I've written about it in website accessibility: when the law actually requires it.