Summary
- Version 1.0 of the UK digital verification services trust framework entered transition on 2 September after the first conformity assessment body gained accreditation.
- Existing certified services have at least 15 months to move from version 0.4, while new services enter directly under the newer rules.
- The transition turns digital identity policy into certification, audit, operational controls, and supplier decisions across services including right-to-work and right-to-rent checks.
The UK’s updated digital identity regime has moved from policy design into operational transition, with certified verification providers now able to begin moving onto version 1.0 of the government’s trust framework while new entrants are assessed against the updated standards from the outset.
The Office for Digital Identities and Attributes said the transition began on 2 September after a conformity assessment body gained accreditation to certify services against version 1.0 of the UK digital verification services trust framework. Accreditation also covers updated supplementary codes for Disclosure and Barring Service checks, digital right-to-work checks, and digital right-to-rent checks.
Existing providers certified against version 0.4 do not have to migrate immediately. Each service will follow a timetable linked to its certification cycle and will have at least 15 months to complete the uplift, while providers can move earlier in some circumstances through an assessment focused on requirements that have changed.
The timetable gives the market breathing room without leaving version 0.4 in place indefinitely. At an existing service’s next evaluation activity, it can either move to version 1.0 or retain its older certification for another cycle; at the following evaluation, it must meet the new framework or lose certified status and be removed from the digital verification services register.
Certification becomes an operating requirement
The trust framework sets rules for organisations providing digital verification services that allow people to prove information about themselves without relying solely on physical documents. Uses include identity checks during recruitment, tenancy processes, and other regulated or commercial transactions where organisations need evidence that a person or attribute is genuine.
The legal context changed after relevant provisions of the Data (Use and Access) Act 2025 came into force, with the government subsequently renaming the framework to align it with the statutory system for registered providers. Version 1.0 therefore arrives inside a more formal regulatory structure than earlier iterations.
For suppliers, the transition becomes a series of technology and governance tasks. Providers have to identify which technical, security, and operational controls have changed, establish whether their existing systems meet them, schedule assessments with approved certification bodies, and make sure customers are not left relying on a service whose certified status later lapses.
Right-to-work and right-to-rent providers face an additional change because their supplementary codes have moved directly to version 1.1. The revisions align digital checks with wider changes to employment and tenancy requirements, so providers leaving the older 0.4 regime will move directly to the updated supplementary standards.
New entrants face a simpler timetable but a higher immediate threshold. Services seeking certification for the first time from 2 September are assessed against the rules now in force, removing the option of joining the register under version 0.4 and postponing the upgrade.
Identity adoption depends on trust between systems
The transition comes as digital identity moves beyond the financial services uses that established electronic verification as a commercial category. Techopia previously examined the expansion of digital identity into healthcare, public services, infrastructure, and industrial settings, where interoperability, liability, accessibility, and confidence in credentials issued elsewhere become operational concerns.
A certification framework cannot resolve those questions by itself, but it provides buyers with a common baseline against which providers can be assessed. The government is also introducing a CertifID trust mark for services certified and registered against version 1.0, creating a visible signal that a provider has passed the updated assessment.
The commercial value of the mark will depend partly on whether organisations recognise it and build certification status into procurement. Employers, landlords, screening providers, and software platforms can reduce some of their own verification work when they trust an external service, but dependence on that provider also turns a certification failure into a potential customer problem.
Interoperability adds another layer. Digital identity becomes more useful when verified attributes can be reused across services, yet reuse places greater weight on standards around consent, data minimisation, security, and assurance. A market in which every service accepts different credentials would recreate much of the administrative duplication digital verification is intended to remove.
The government has said that the programme does not make digital identities mandatory and is separate from the introduction of any compulsory national identity card. The framework regulates a market of private and public providers that people and organisations can choose to use, while GOV.UK One Login remains a separate government programme for access to public services.
That distinction will remain important as verification becomes embedded in more routine transactions. Digital checks can reduce repeated document handling and support remote processes, while responsibility becomes concentrated in the organisations issuing and validating electronic claims about people.
With version 1.0 now in transition, progress will be measured less by publication of frameworks and more by whether providers can move through certification without disrupting customers. The window is deliberately long, but organisations remaining on version 0.4 now have a defined route towards a standard they will eventually have to meet if they want to remain registered.












