Skip to main content
Promotional banner for the pentest readiness checklist
Australia's VC Consultation Reveals the Cost of FragmentationOAuth & OIDC
4 min readFor IAM Architects

Australia's VC Consultation Reveals the Cost of Fragmentation

The Australian Department of Finance's consultation on verifiable credentials policy closed with a clear warning from the OpenID Foundation's Australian Digital Trust Community Group: prioritize interoperability now, or prepare to manage disconnected silos later. The response, published by the ADT CG, synthesizes years of global experience building identity ecosystems into a practical roadmap for national digital identity systems.

The Consultation's Focus

Australia's Department of Finance asked the Commonwealth community to weigh in on verifiable credentials policy and regulatory settings. The consultation covered economic impact, use cases, investment requirements, and the design of a proposed Commonwealth VC Trust Framework. The scope extended to international interoperability, multi-standards environments, and risk mitigation as adoption scales.

The ADT CG's response centered on one strategic principle: interoperability must be the foundation, not an afterthought. This isn't a philosophical position. It's a technical requirement that determines whether credentials and digital wallets work across services, sectors, and borders.

Key Findings

Open standards reduce fragmentation risk. The response highlighted OpenID Foundation standards already deployed at scale: OpenID for Verifiable Presentation, OpenID for Verifiable Credential Issuance, OpenID Connect, FAPI 2.0, OpenID Federation, and Shared Signals. These specifications give implementers a tested foundation. When you build on standards proven across billions of authentication flows, you're not debugging interoperability from scratch.

Conformance testing provides assurance without new infrastructure. The ADT CG pointed to the Foundation's freely available, open-source conformance tests. These tools let implementers demonstrate that their deployments meet security, privacy, and interoperability requirements built into the specifications. The Foundation's accreditation program, launching later this year, offers ecosystem-level assurance. You don't need to build certification infrastructure when tested tooling already exists.

Governance choices made now determine ecosystem structure for years. John Scullen, co-chair of the ADT CG, framed the stakes clearly: "The choices made now will determine whether Australia develops a single interoperable credential ecosystem or a collection of disconnected silos." This isn't about technical elegance. It's about whether your investment in verifiable credentials delivers portability or vendor lock-in.

Multi-standards environments need active management. The consultation asked how to handle multiple standards coexisting in the same ecosystem. The ADT CG's answer: establish clear conformance requirements and testing protocols. Without them, you get semantic drift where implementations claim compatibility but fail in production.

Implications for Your Team

If you're designing or implementing identity systems in government or enterprise environments, Australia's consultation exposes three planning gaps you need to address:

Your interoperability requirements are probably too vague. "Support industry standards" doesn't cut it. You need to specify which versions of which specifications, what conformance level is required, and how you'll verify compliance. The Australian Government's consultation revealed this gap at national scale. Your organization likely has the same problem in its identity roadmap.

You're underestimating the cost of proprietary extensions. Every custom modification to a standard protocol creates a maintenance burden and an interoperability boundary. When vendors add proprietary features to OpenID Connect or FAPI 2.0, they're betting you'll never need to integrate with partners who didn't make the same choices. That bet fails more often than it pays off.

Your testing strategy assumes perfect implementations. Conformance testing isn't about catching obvious bugs. It's about verifying that edge cases, error handling, and security properties work as specified. The ADT CG's emphasis on freely available conformance tools reflects a lesson learned across dozens of deployments: manual testing misses the interactions that break in production.

Action Items by Priority

1. Audit your current standards baseline. List every identity protocol in production. For each one, document the specification version, any proprietary extensions, and whether you've run conformance tests. If you're running OAuth 2.0 without PKCE or OpenID Connect with custom claim formats, you're creating interoperability debt.

2. Establish conformance requirements for new integrations. Before you approve a vendor integration or deploy a new credential issuer, define what passing conformance means. The OpenID Foundation publishes test suites for its specifications. Make "passes OIDF conformance tests" a contract requirement, not a nice-to-have.

3. Map your cross-border identity requirements. If your organization operates internationally or partners with entities in other jurisdictions, document where credentials need to work across borders. Australia's focus on international interoperability reflects a reality you can't ignore: identity systems that work only within organizational boundaries have limited strategic value.

4. Review your trust framework for interoperability language. Your governance documents should specify how you'll handle multi-standards environments, what happens when specifications conflict, and who decides when to adopt new versions. If your trust framework treats standards as implementation details, you're missing the governance layer that prevents fragmentation.

5. Calculate the cost of non-interoperability. When you evaluate proprietary identity solutions, model the integration cost if you need to federate with partners who chose different vendors. Include developer time, ongoing maintenance, and the opportunity cost of features you can't build because you're managing custom integrations.

OpenID Foundation OAuth 2.0 PKCE

Promotional banner highlighting failures found in PCI audits and how to spot the gaps

You Might Also Like