Skip to main content
Promotional banner ad for the Penetration Testing Report Kit
ISO/IEC 17065 Certification for Your Digital Identity ServiceGovernance & Compliance
4 min readFor CISOs & Security Leaders

ISO/IEC 17065 Certification for Your Digital Identity Service

If you're running a digital identity verification service in the UK, you need to understand a critical development. Kantara Initiative is now the first Conformity Assessment Body (CAB) accredited under ISO/IEC 17065:2012 to certify against the UK Digital Identity and Attributes Trust Framework (DIATF). With the Data (Use and Access) Act 2025, certification from an accredited CAB is mandatory to appear on the statutory register.

In simple terms, if you want your service on the government's register, you need certification. Right now, Kantara Initiative is the only accredited body that can provide it.

The Problem: Your Service Needs Government Recognition

The UK government is creating a statutory register of approved digital verification services. Without a spot on that register, you're outside the framework that government departments and regulated industries will use to evaluate identity providers.

This isn't just about compliance. Organizations will choose identity verification partners based on register status. If you're not listed, you're not considered.

What You Need Before Starting

Organizational prerequisites:

  • A digital identity verification service in the UK
  • Documentation of your current identity verification processes
  • Technical specifications for your verification methods
  • Security policies and incident response procedures
  • Privacy impact assessments for data handling

Technical foundation:

  • Identity proofing workflow (document verification, biometric matching, or liveness detection)
  • Attribute verification capabilities (if applicable)
  • Audit logging infrastructure
  • Session management and authentication systems
  • Integration points with relying parties

Team resources:

  • A project lead familiar with your technical stack and compliance needs
  • Engineering teams to modify verification workflows
  • Legal or compliance staff knowledgeable about data protection regulations
  • Budget for certification fees and potential remediation work

Review the DIATF documentation published by the Office for Digital Identities & Attributes before contacting a CAB. Determine which certification level you're targeting (Medium or High confidence) and which components of your service are within scope.

Step-by-Step Implementation

1. Map your service to DIATF requirements

Identify which DIATF rules apply to your verification methods. For identity documents, demonstrate compliance with document authentication requirements. For biometric matching, align your processes with biometric verification rules.

Document each verification step and note the corresponding DIATF requirement. This mapping becomes your certification roadmap.

2. Conduct an internal gap analysis

Compare your current implementation against DIATF requirements. Common gaps include:

  • Insufficient audit trail granularity for verification decisions
  • Lack of documented fraud detection thresholds
  • Missing security controls for biometric template storage
  • Inadequate session timeout configurations
  • Incomplete incident response procedures specific to identity verification failures

Estimate the engineering effort required to close each gap. Prioritize gaps affecting core verification logic over documentation improvements.

3. Remediate technical gaps

Focus on verification logic first. If DIATF requires liveness detection for Medium confidence and you're using passive checks, upgrade your biometric stack before proceeding.

Next, address audit logging. Capture:

  • Each verification attempt (successful and failed)
  • Specific checks performed (document authentication, biometric match score, attribute verification)
  • Decision points where automated systems or human reviewers made determinations
  • Timestamps with sufficient precision for forensic analysis

Configure your logging to retain records according to DIATF retention requirements.

4. Prepare documentation for assessment

Create a certification package that includes:

  • System architecture diagrams showing data flows
  • Process documentation for each verification method
  • Security policies covering key management, access control, and incident response
  • Privacy policies and data handling procedures
  • Test results demonstrating verification accuracy
  • Training materials for staff involved in verification decisions

The CAB will review this documentation before conducting on-site assessments. Incomplete documentation delays the process.

5. Engage with Kantara Initiative

Contact Kantara to initiate the certification process. They'll assign assessors to review your documentation, conduct technical interviews, and perform on-site assessments of your verification systems.

Be prepared to demonstrate your verification workflow in real-time. Assessors may ask you to process test identities and explain decision logic at each step.

6. Address assessment findings

Assessors will identify non-conformities (requirements you don't meet) and observations (areas for improvement). Non-conformities must be resolved before certification. You'll need to:

  • Implement corrective actions
  • Provide evidence that corrections address the root cause
  • Demonstrate that corrections don't introduce new issues

This phase often takes longer than expected. Budget time for multiple remediation cycles.

Validation: How to Verify It Works

Once you receive certification from Kantara, you'll be invited to join the statutory register maintained by OfDIA. Verify your listing appears correctly and includes accurate information about your service capabilities.

Test your certification status with potential customers. Government departments and regulated entities should be able to verify your register status independently.

Monitor your audit logs to confirm you're capturing the data required for ongoing compliance. Run sample queries that would support incident investigations or compliance audits.

Maintenance and Ongoing Tasks

Certification isn't permanent. You'll need to maintain compliance through:

Continuous monitoring:

  • Track verification success rates and failure patterns
  • Monitor fraud detection metrics
  • Review incident logs for security events
  • Audit access to sensitive verification systems

Regular reporting:

  • Submit required reports to OfDIA as specified in the Data (Use and Access) Act 2025
  • Maintain documentation of system changes
  • Update risk assessments when you modify verification methods

Recertification preparation:

  • Track changes to DIATF requirements
  • Document system modifications that affect certified components
  • Schedule internal audits before recertification windows
  • Budget for recertification assessments

Incident response:

  • Report security incidents according to OfDIA requirements
  • Investigate verification failures that could indicate fraud
  • Update procedures based on incident findings

If you modify your verification workflow, assess whether changes affect your certification scope. Material changes may require reassessment before you deploy them to production.

The UK's statutory register creates a clear dividing line in the digital identity market. Organizations on the register have demonstrated compliance with government-backed standards. Organizations outside it are operating without that validation. Your implementation timeline determines which side of that line you're on.

a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.

You Might Also Like