Customer Identity and Access Management (CIAM) has become critical as organizations expand digital engagement through mobile devices and social networks while also meeting privacy regulations such as GDPR. CIAM systems provision, authenticate, authorize, and store consumer identities at massive scale, often ingesting data from multiple unauthoritative sources and optionally strengthening it via identity-proofing integrations. Beyond login enablement, consumer identity data supports authorization, marketing analytics, and initiatives like anti-money laundering (AML). Core CIAM capabilities include registration (often with progressive profiling and fraud-resistant, higher-assurance onboarding), diverse authentication methods (MFA, biometrics, passwordless, social login, FIDO), SSO across brands and storefronts, consent management to satisfy GDPR/PIPEDA/CCPA, and continuous security monitoring enhanced by fraud and compromised-credential intelligence.
CIAM can be delivered through an “identity fabric” of modular microservices (e.g., registration, proofing, consent, SSO), typically cloud-based and reusable across consumer, B2B, and workforce scenarios, improving scalability, cost efficiency, and adaptability.
cidaas (launched 2018), the customer identity-as-a-service offering of Widas ID GmbH (founded 1997, Germany), is a globally distributed SaaS across multiple data centers in the EU, Asia, and North America with licensing based on feature packages and monthly active or registered users. It provides configurable registration workflows, migration APIs, and an identity integration layer. Its AutoIdent ID validator supports document scanning, selfie matching, and higher service levels addressing KYC/AML. cidaas supports device identity (including IoT via OAuth2 Device Flow), broad authentication and federation standards, risk and fraud detection (including bot detection and compromised credential checks), robust consent tooling with deletion webhooks, delegated and family access management, and integrations spanning payments, analytics, and Physical Access Control Systems (PACS), including offline operation. Strengths include identity proofing, low-latency performance with 99.99% uptime, payment integrations, and cyber-physical access scenarios; challenges include lack of FIDO and SOC 2 Type 2 certifications and a need for more packaged connectors.
See All Locations
See All Locations