KuppingerCole’s Buyer’s Compass for decentralized identity solutions is a structured starting point for vendor selection. It guides organizations to first identify primary use cases, then evaluate vendors against functional and non-functional selection criteria, request and rate vendor information, ask targeted follow-up questions, and narrow to a shortlist for deeper RFIs and proofs of concept—while ensuring technical and organizational prerequisites are in place. The approach emphasizes aligning product capabilities with the most relevant use cases, rather than treating selection as a generic feature comparison.
Decentralized identity is positioned as an IAM sub-category shaped by blockchain development and rising public demand for control over personally identifiable information (PII). Traditional account-per-institution models create data “honeypots” for organizations and encourage insecure password reuse by users; the growth of uniquely identified IoT devices worsens siloed identity challenges. Decentralized identity aims to return control of identity attributes to individuals, improve user experience, support digital document integrity, and increase resiliency. The ecosystem model commonly involves Issuers, Holders, and Verifiers: issuers provide credentials, holders store them in digital wallets, and verifiers validate claims cryptographically using an immutable ledger and revocation records.
Top use cases include identity management, new customer onboarding, reusable KYC, strong customer authentication, and proof of age with selective disclosure. Selection criteria span functional capabilities (e.g., verifiable claims, zero-knowledge proofs, wallet security, interoperability, PII storage location, smart contracts, APIs/SDKs, recovery) and non-functional vendor factors (e.g., deployment models, maturity, documentation, standards participation, partner ecosystem, roadmap, pricing, privacy focus). The document also highlights prerequisites—such as hardware capacity, multispeed IAM integration, iterative cybersecurity, metrics, governance, incident response, and business case discipline—to avoid adopting blockchain where it doesn’t fit organizational goals or maturity.
See All Locations
See All Locations