Skip to content
Menu

BlogGuides

Website with SPID login: when it really matters and to whom

Close-up of hands typing on a laptop keyboard at a light wooden desk
Add as a preferred source on Google

One click, and Google will show my articles more often in your results.

Anyone searching for "website with SPID login" has usually already heard that public administration in Italy stopped accepting its own credentials a few years ago, and wonders whether the same rule is about to reach their own business website. The short answer is that, for most private businesses, that rule never arrives: the obligation exists, but it targets a specific group of entities, and a shop, a practice or a hotel isn't one of them.

Who is legally required to offer it

Article 64 of Italy's Digital Administration Code requires access via SPID or CIE for online services that need digital identification. The obligation doesn't stop at public administration in the strict sense: article 2, paragraph 2 of the same Code extends its scope to "public service operators", a category that explicitly includes listed companies and publicly controlled companies when they provide services of public interest, not just the local energy, water or transport utilities people usually picture (source: Normattiva, Digital Administration Code, Legislative Decree 82/2005, articles 2 and 64, checked on 27 September 2026).

To gauge how seriously this rule is enforced, it helps to look at what already happened to public administration itself: from 28 February 2021, under the Semplificazioni decree (Decree-Law 76/2020), public administrations could no longer issue or renew their own credentials other than SPID, CIE or the National Services Card; old credentials stayed valid only until their natural expiry, and no later than 30 September 2021 in any case. Outside that boundary, meaning for an ordinary private business, there's no equivalent deadline, because there's no obligation for one to expire: adoption stays optional, always.

What offering it actually involves, if you're not required to

Adding a "log in with SPID" button isn't an afternoon's work. To do it, a business has to get accredited with Italy's Digital Agency (AgID) as a Service Provider, build a technical infrastructure that meets the system's specifications, and sign an agreement to join the SPID federation: a path built for structured companies, with validation timelines and organizational requirements a small business rarely already has in place.

There's also an ongoing cost, not just the upfront development one. AgID regulates the fees a private Service Provider pays to identity providers through a pay-per-use model set by Determination no. 166/2019, still the current reference today. For level 1-2 credentials, the most widely used, authentication is free up to 1,000 unique users per year for each identity provider, then costs 0.40 euros plus VAT for every additional user; registering a new user, instead, always costs 3.50 euros plus VAT, with no free threshold at all (source: AgID, Annex 4 to Determination 166/2019, "SPID Authentication Service Fees", checked on 27 September 2026). On a service with thousands of new registrations a year, that's a real cost, not a symbolic one.

Who it's worth it for anyway

The reason a private business chooses this route anyway, despite the cost and the complexity, is almost always the same: it needs to know with certainty who's on the other side of the screen before offering them a service, because getting someone's identity wrong would be expensive. That's the typical case in the financial and insurance sectors, where verifying a customer's identity isn't a convenience but a step sector-specific rules already require in some form, and SPID offers a way to do it with data already certified by an accredited identity provider, instead of building that verification from scratch.

For most small and medium businesses, a shop, a professional practice, a hotel, an e-commerce site, that need simply doesn't exist: the customer signs up with a name, an email and a password, and there's no identity mistake serious enough to justify the complexity of an AgID accreditation. Anyone still considering offering it, perhaps to give customers a faster way to log in, has a more realistic route than direct accreditation: relying on an aggregator already accredited by AgID, which acts as an intermediary toward the public infrastructure in exchange for its own fee. It's still an added cost to weigh against a benefit that, for a business like this, is often more perceived than real.

What changes in the coming years

One upcoming shift involves a different system from SPID, but points in the same direction. From 24 December 2027, the European eIDAS2 regulation (Regulation EU 2024/1183, article 5f) will require a range of regulated private sectors, including banks, insurance, telecommunications, energy, transport, healthcare and education, to accept the European Digital Identity Wallet, set to become Italy's IT-Wallet, whenever strong customer verification is needed. For now the obligation applies only to those specific sectors, not to private businesses in general, but it signals where digital identity rules are heading over time.

Where to start

If your business isn't a public service operator, you have no obligation today to add SPID login to your website. If you do have a concrete reason to want it anyway, the useful first step is working out whether that reason is really worth the per-user cost and the complexity of accreditation, or whether a client portal with its own credentials, which I wrote about in website with a client portal: when it's worth it, solves the same problem more simply. If you're not sure which case is yours, get in touch and we can talk it through.

Another digital obligation that follows the same logic, depending on what your website does rather than on your turnover, is website accessibility: I've written about it in website accessibility: when the law actually requires it.

Frequently asked questions

Is my business legally required to offer SPID login on its website?

In the vast majority of cases, no. Article 64 of Italy's Digital Administration Code requires access via SPID or CIE for public administrations and for public service operators, a category that article 2, paragraph 2 of the same Code extends to listed companies and publicly controlled companies when they provide services of public interest, such as energy, water or transport utilities (source: Normattiva, Digital Administration Code, Legislative Decree 82/2005, articles 2 and 64, checked on 27 September 2026). A shop, a professional practice, a hotel or an e-commerce business don't fall into this category: for them, adopting SPID stays a choice, never an obligation.

What does becoming a SPID 'Service Provider' actually involve?

It means getting accredited with Italy's Digital Agency (AgID) with a technical infrastructure that meets the system's specifications, then signing an agreement to join the SPID federation. It's a path built for structured companies, not a button you add to a website in an afternoon: it requires dedicated development, validation time from AgID, and a recurring cost for every user who authenticates or registers.

How much does it cost to offer SPID login to your customers?

AgID regulates the fees a private service provider pays to identity providers through a pay-per-use model, set by Determination no. 166/2019 and still in force. For level 1-2 credentials, the most common ones, authentication is free up to 1,000 unique users per year for each identity provider, then costs 0.40 euros plus VAT per additional user; registering a new user, on the other hand, always costs 3.50 euros plus VAT, with no free threshold (source: AgID, Annex 4 to Determination 166/2019, "SPID Authentication Service Fees", still linked as the current reference, checked on 27 September 2026). On top of that comes the cost of the technical integration itself, which varies by provider.

Is there an easier route than getting accredited with AgID directly?

Yes. A business that doesn't have the technical or organizational requirements to become an accredited Service Provider can rely on an aggregator already accredited by AgID, which acts as an intermediary toward the public infrastructure in exchange for its own fee. For a small or medium business still considering SPID login, this is usually the more realistic route compared with building the accreditation itself.

Are SPID and a digital signature the same thing?

No, and mixing them up is common. SPID proves who you are online to access a service; a digital signature signs a document with the same legal value as a handwritten one. Many digital signature providers use SPID only as a step to verify the identity of whoever is requesting the signature, not as a substitute for it. I wrote about this in full in [digital signature: what it really costs and when it's mandatory](/en/blog/how-much-does-a-digital-signature-cost/).

Is anything going to change in the coming years?

Yes, though it doesn't directly involve SPID. From 24 December 2027, the European eIDAS2 regulation (Regulation EU 2024/1183, article 5f) will require regulated private sectors, including banks, insurance, telecommunications, energy, transport, healthcare and education, to accept the European Digital Identity Wallet (in Italy, the IT-Wallet) whenever strong customer verification is needed. It's a distinct system from SPID, though a related one, and for now the obligation applies only to those specific sectors, not to private businesses in general.

More articles

Want to know if SPID login actually applies to you?

Tell me about your project