If you're running a digital identity verification service in the UK, you need to understand a critical development. Kantara Initiative is now the first Conformity Assessment Body (CAB) accredited under ISO/IEC 17065:2012 to certify against the UK Digital Identity and Attributes Trust Framework (DIATF). With the Data (Use and Access) Act 2025, certification from an accredited CAB is mandatory to appear on the statutory register.
In simple terms, if you want your service on the government's register, you need certification. Right now, Kantara Initiative is the only accredited body that can provide it.
The Problem: Your Service Needs Government Recognition
The UK government is creating a statutory register of approved digital verification services. Without a spot on that register, you're outside the framework that government departments and regulated industries will use to evaluate identity providers.
This isn't just about compliance. Organizations will choose identity verification partners based on register status. If you're not listed, you're not considered.
What You Need Before Starting
Organizational prerequisites:
- A digital identity verification service in the UK
- Documentation of your current identity verification processes
- Technical specifications for your verification methods
- Security policies and incident response procedures
- Privacy impact assessments for data handling
Technical foundation:
- Identity proofing workflow (document verification, biometric matching, or liveness detection)
- Attribute verification capabilities (if applicable)
- Audit logging infrastructure
- Session management and authentication systems
- Integration points with relying parties
Team resources:
- A project lead familiar with your technical stack and compliance needs
- Engineering teams to modify verification workflows
- Legal or compliance staff knowledgeable about data protection regulations
- Budget for certification fees and potential remediation work
Review the DIATF documentation published by the Office for Digital Identities & Attributes before contacting a CAB. Determine which certification level you're targeting (Medium or High confidence) and which components of your service are within scope.
Step-by-Step Implementation
1. Map your service to DIATF requirements
Identify which DIATF rules apply to your verification methods. For identity documents, demonstrate compliance with document authentication requirements. For biometric matching, align your processes with biometric verification rules.
Document each verification step and note the corresponding DIATF requirement. This mapping becomes your certification roadmap.
2. Conduct an internal gap analysis
Compare your current implementation against DIATF requirements. Common gaps include:
- Insufficient audit trail granularity for verification decisions
- Lack of documented fraud detection thresholds
- Missing security controls for biometric template storage
- Inadequate session timeout configurations
- Incomplete incident response procedures specific to identity verification failures
Estimate the engineering effort required to close each gap. Prioritize gaps affecting core verification logic over documentation improvements.
3. Remediate technical gaps
Focus on verification logic first. If DIATF requires liveness detection for Medium confidence and you're using passive checks, upgrade your biometric stack before proceeding.
Next, address audit logging. Capture:
- Each verification attempt (successful and failed)
- Specific checks performed (document authentication, biometric match score, attribute verification)
- Decision points where automated systems or human reviewers made determinations
- Timestamps with sufficient precision for forensic analysis
Configure your logging to retain records according to DIATF retention requirements.
4. Prepare documentation for assessment
Create a certification package that includes:
- System architecture diagrams showing data flows
- Process documentation for each verification method
- Security policies covering key management, access control, and incident response
- Privacy policies and data handling procedures
- Test results demonstrating verification accuracy
- Training materials for staff involved in verification decisions
The CAB will review this documentation before conducting on-site assessments. Incomplete documentation delays the process.
5. Engage with Kantara Initiative
Contact Kantara to initiate the certification process. They'll assign assessors to review your documentation, conduct technical interviews, and perform on-site assessments of your verification systems.
Be prepared to demonstrate your verification workflow in real-time. Assessors may ask you to process test identities and explain decision logic at each step.
6. Address assessment findings
Assessors will identify non-conformities (requirements you don't meet) and observations (areas for improvement). Non-conformities must be resolved before certification. You'll need to:
- Implement corrective actions
- Provide evidence that corrections address the root cause
- Demonstrate that corrections don't introduce new issues
This phase often takes longer than expected. Budget time for multiple remediation cycles.
Validation: How to Verify It Works
Once you receive certification from Kantara, you'll be invited to join the statutory register maintained by OfDIA. Verify your listing appears correctly and includes accurate information about your service capabilities.
Test your certification status with potential customers. Government departments and regulated entities should be able to verify your register status independently.
Monitor your audit logs to confirm you're capturing the data required for ongoing compliance. Run sample queries that would support incident investigations or compliance audits.
Maintenance and Ongoing Tasks
Certification isn't permanent. You'll need to maintain compliance through:
Continuous monitoring:
- Track verification success rates and failure patterns
- Monitor fraud detection metrics
- Review incident logs for security events
- Audit access to sensitive verification systems
Regular reporting:
- Submit required reports to OfDIA as specified in the Data (Use and Access) Act 2025
- Maintain documentation of system changes
- Update risk assessments when you modify verification methods
Recertification preparation:
- Track changes to DIATF requirements
- Document system modifications that affect certified components
- Schedule internal audits before recertification windows
- Budget for recertification assessments
Incident response:
- Report security incidents according to OfDIA requirements
- Investigate verification failures that could indicate fraud
- Update procedures based on incident findings
If you modify your verification workflow, assess whether changes affect your certification scope. Material changes may require reassessment before you deploy them to production.
The UK's statutory register creates a clear dividing line in the digital identity market. Organizations on the register have demonstrated compliance with government-backed standards. Organizations outside it are operating without that validation. Your implementation timeline determines which side of that line you're on.




