There are two ways a state can make a digital identity trustworthy. It can center trust on certifying market providers against a published standard. Or it can center trust on a credential the state issues itself, and specify the architecture.
The United Kingdom (UK) and the European Union (EU) each picked one. For most of the last decade the difference looked like a matter of administrative preference. It was hard to judge, because neither model had delivered. Both models now have a delivery record, and in the space of ten months the UK managed to try both.
This post outlines what each has produced by mid-2026, which model the evidence suggests is slower, and what relying parties in both markets should do differently. The answer is not the one most buyers expect.
Two ways to manufacture trust
The UK model treats trust as something you certify. Part 2 of the Data (Use and Access) Act 2025 put the digital verification services trust framework and its register on a statutory footing, commencing on 1 December 2025. The state publishes rules, a conformity assessment body accredited by UKAS audits against them, and providers that pass appear on a public register. The state writes the rules and keeps the register. It does not issue the credential.
The EU model treats trust as something you issue. Under the amended eIDAS framework, every Member State must make a European Digital Identity Wallet available to citizens by the end of December 2026, with the architecture, security requirements, and certification specified centrally.
The interesting question is no longer which approach is more elegant. It is which one actually delivers. On that point, the conventional wisdom has been wrong.
The certification model is reaching the point of sale
The intuitive view is that the UK approach is the slow one: years of alpha, beta and gamma versions, accreditation bodies, conformity assessment, a trust mark. It was certainly slow to start. David Crack, chair of the Association of Digital Verification Professionals, told the Home Affairs Committee in Mandatory to manageable: the government’s plans for digital ID that the framework began in 2008, making the sector “the product of a long-standing cross-party consensus over 17 years.”
But it has compounded. As of 21 August 2026 the register listed 46 providers offering 63 certified services. Version 1.0 of the framework was published on 9 June 2026 and takes effect on 1 September.
More importantly, the framework is about to reach a point that assurance schemes rarely do: an ordinary transaction with legal consequences. On 30 June 2026 the Home Office laid a draft order amending the mandatory licensing conditions under the Licensing Act 2003. It removes the requirement that proof of age carry a physical security feature, such as a hologram. Instead, it permits a licensee to accept digital proof, provided that specific conditions are met. As of 1 September the order was still a draft, awaiting approval by both Houses.
Those conditions are the point, and OfDIA set them out when the order was laid. The provider must be registered, must deliver identification at “at least a medium level of confidence, as defined in the relevant versions of the UK DVS trust framework,” and the check must happen “through secure technological means, rather than someone simply looking at a digital proof of age on a screen.”
Once the order is made, an assurance level stops being an abstraction. It becomes the thing standing between a licensee and a license review.
What the order did not require is as telling as what it did. OfDIA set this out in guidance on 19 August 2026: “The new regulations do not introduce any new certification requirements for DVS providers and do not introduce any additional approval process.” A mass-market transaction with criminal liability attached is being fitted to the assurance framework without building anything new for it. The plumbing is already there.
The same country tried issuance, and stopped
The UK also tried the other model.
In September 2025, the government announced a state-issued digital ID. By the March 2026 consultation, the scheme had already softened: “There will be no legal obligation for people to have or present the digital ID.”
Even more striking, the consultation did not propose an alternative to the certification model. It proposed building inside it. The government intended the digital ID system “to operate within this ecosystem, adopting these standards and safeguards.” It expected the GOV.UK Wallet “to be certified as a DVS.” It stated that “only DVS providers that are certified under a current version of the trust framework and present on the government register will be able to programmatically verify a digital ID presented from the GOV.UK Wallet.”
The state’s own wallet was to be certified under the framework built for private providers.
It did not survive. On 21 July 2026 the programme was cancelled. The public record is thin: the cancellation appears as a line of funding in a Treasury announcement about a VAT cut on household electricity, costed at £1.8 billion over three years. There is no dedicated statement, because Parliament rose on 16 July.
The certification track carried on. Its statutory basis, its register and its September framework date all sit on separate legislation with a separate budget line.
It also outlived the department that owned it. DSIT was abolished on 21 July 2026 and digital identity policy moved to the Department for Digital, Culture, Media and Sport. OfDIA published operational guidance on 19 August and updated the register on 21 August. An assurance regime that keeps working through the abolition of its parent ministry is telling you something about where the durability sits.
The EU is committed to issuance, and still assembling the assurance behind it
The EU cannot make the same choice, because its model is in a regulation with a date attached.
Two pieces of evidence bear on readiness, both from EU institutions. ENISA’s candidate cybersecurity certification scheme for the wallet was still in public review between 4 and 30 April 2026. Member States owe certified wallets by the end of the year. The Regulation fills the gap with national certification schemes, which cover the requirements that European schemes "do not, or only partially, cover". So certification does not depend on the ENISA scheme alone. But a common scheme that was still a draft candidate in the spring shows how much of the shared assurance layer remained unfinished late in the delivery cycle.
The second is the Commission’s own report on the interoperability testing event it ran in December 2025. Of the 11 Member States that brought wallet applications, roughly half used the Reference Implementation, which the report notes means “fewer than one quarter of Member States participated with EUDI Wallet enabled applications.” Its conclusion is direct: “While this suggests that only a limited number of Member States are likely to meet the November 2026 EUDIW deadline, it also demonstrates that the Reference Implementation is effectively supporting early testing, experimentation, and learning, particularly for less mature implementations.”
The same report identifies where the gap sits: “trust infrastructure onboarding remains a weak point,” with “limited use of the trust lists available and incomplete onboarding to the EUDI trust framework.”
That is the mirror image of a register with 46 providers on it. The Commission is careful to limit its own conclusion to countries that attended, and so should anyone quoting it.
What relying parties should take from this
An organization accepting digital identity in both markets cannot run one acceptance strategy.
In the UK you evaluate a certificate held by a provider. The questions are which framework version, which assurance level, which service role, and whether the register entry still stands. In the EU you evaluate a wallet implementation and the Member State behind it, and on the Commission’s own evidence you should expect that assessment to differ sharply between Member States well into 2027.
Two further points follow for identity verification buyers. First, wallet availability is not wallet ubiquity, and IDV demand does not disappear when a wallet arrives, a point I have argued separately. Plan parallel wallet and non-wallet paths. Second, treat certification status as a live attribute rather than a procurement checkbox. Framework versions change, registers move, and in the UK the machinery of government moved in July.
Conclusion
Three things are worth carrying away. Certification models can be slow to establish, but they compound once the infrastructure is in place. The UK experience shows that. The EU experience shows something different: making wallets available does not remove the work of assurance, interoperability and trust-infrastructure onboarding, and the Commission's own testing report documents that work. And the two are not alternatives: the UK scheme was designed to run inside the certification framework, not replace it.
The due-diligence exercise is genuinely different in each market. That distinction belongs in your requirements now, not after December. KuppingerCole’s Identity Verification research and advisory team can help you determine the scope.