All right. Good morning, everyone. Welcome to The Certification Advantage. We're going to talk about why compliance is your strongest market signal and a true advantage for you and your company. I will start with saying 90 minutes is a long time for one person to talk. I have a few folks up here with me, but I'd like for this to be interactive. If you have questions, disagree with me or just want to chat, please raise your hand or shout it out. But we'll need to make sure we have a microphone for you. And any of the folks online, if you have questions, please ask.
Andy is sitting to my right here, and we'll make sure we get to your questions. All right. Let me start with a little bit about us. My name is Renée Hunter. I'm treasurer of the board for Kantara Initiative. I'm also the CLO head of people and another title or two at a company called Proof, a U.S.-based company that specializes in digital identity and entire transformation of workflows. Kay Chopard is not here today.
Right now, she had a little bit of a delay in her flight. Kay is the executive director of Kantara Initiative. She has been with us, I think, about five years now. And then to my right here, Andy, do you want to go ahead? Good morning. How are you all doing?
Oh, wow. Oh, there we go. Excellent.
So, I'm Andy Hindle. I am here on this particular chair on this particular day wearing my UK advisory board for Kantara hat. I've been on the UK advisory board for about three years, and I was also on the Kantara board a couple of years ago for about a year. I have some history with Kantara before that, more on the standard side, particularly around the UMA specification. When I'm not doing this, most of my time is spent consulting independently in digital identity and privacy and a little bit of cybersecurity and some corporate governance.
Most people will more readily recognize me as the chair for the Identiverse conference. I'm also the chair for Authenticate, and I also cofounded and convened the Identity Salon, which is a smaller set of conversations around sort of what's happening in this five to seven year time frame for digital identity and access management.
So, that's me. I am not the person to deal with specific questions today. Rene knows that, and Finley knows that. I've just been super upfront about it. But more of the contextual stuff around why certification is important more broadly, those are kind of the things that I can help with. And I will be sitting here with the iPad dealing with any of the online questions for our wonderful online folks.
Hello, wonderful online folks. Finley.
Hello, I'm Finley Keane. I am client executive for Kantara Initiative UK.
So, I deal a lot with incoming clients looking to get their services certified in the UK DIATF trust framework to be DVSDF. So, a lot of everyone has come through there. I've spoken to a lot of them over the past year and a half, two years.
So, any questions for UK DIATF certification, I'll be able to answer quite well, hopefully. Excellent. I am also going to do a little bit of case speaking here. Just a little bit about the Kantara Initiative. We were founded in 2009, US-based, but we also now have a presence in the United Kingdom for the past several years. The goal of Kantara is to help defragment the really fragmented digital identity, but the world of digital identity. The goal has been to continue to come up with frameworks, which is why we expanded the UK.
We offer third-party conformity assessments against NIS SP 863, both revision three and revision four. And then additionally, we offer in the UK through Kantara LTD, we're the first UCAS accredited certification body. There are two ways you can work with Kantara. One is to go through the certification audit process, and the second way is to actually become a member and help us write criteria and help us influence the changes that we need to see in the digital identity marketplace.
So, that's just my, just want to make sure we're at least telling you who we are. All right.
So, the moment we're in and why we're here to talk about this, there are hundreds of vendors that claim that they are compliant with whatever standard they want to say they're compliant with. Digital identity right now continues to be fragmented. Regulated industries are demanding real evidence, both government, financial services, health care, the list goes on and on. The question is, are you compliant? And then if so, how do I know that? Marketing claims really aren't sufficient any longer. We're certainly seeing that over in the U.S., and we know that to be true in Europe.
The self-assertion market is breaking down. Again, if I were to say my company's IAL2 compliant, but I can't prove that through an independent, we call it an assessment in the U.S., but through an audit, it's basically me just saying I think I'm compliant. Trust me. And then certification is a market signal. It's not just a checkbox, and I think that was the biggest thing for my company and companies in the U.S. is it isn't just that you're going through an audit because you need to check some boxes.
If you work for a digital identity provider, you've gone through probably your own due diligence questionnaires from your customers. The SIG, SIG light, they're giant sets of questionnaires that just feel like checkboxes. This audit isn't just a checkbox. It's really important that we all think through what that process should look like in our company and why this is important. I do have three questions for this room. If a relying party asks you why should I trust your identity service, what's your answer? Okay. All right. No responses there.
And if you are actually a relying party, do you know what the certification means? Who audited the auditors? Those are important questions that anyone who's looking to purchase a solution or a government entity, even if they're not directly purchasing but is regulating, they should understand what that certification means. Who audited your auditors and ensure that there's consistency and conformity throughout.
And again, talking about policy and government, if you're in policy and government, what assurance levels do you actually require and how do you verify a vendor meets it? Three very important sets of questions for three different audiences all circling back to what does an audit mean, what does a certification mean, and how important it is. I'm going to add a fourth one. And I'm sorry, Renee, I'm doing the thing I said I was going to do, which is I'm going to jump in randomly when she least expects it.
So one of the things that comes up that we tend to forget about from within the industry is ultimately there's a large enterprise at the end of all of this that's buying this service. And I think your point about checkbox compliance is really important. We've seen that behavior historically and not just in the identity space, right? We see this behavior of I've got to be compliant. Have I had somebody check that or my services have to be compliant? Have I had somebody check that?
Yes, I have. Okay, that's fine. Now what's happening is at the executive level and in boardrooms, directors and senior executives are really coming under pressure, strain, to make sure that the services they are providing when they say they comply and they're safe, that they genuinely are, right? It's a risk management process for them. And they are becoming much more aware now of what some of the downstream risks are of providing poor quality, potentially breachable, less reliable services to their customers. That's a really important point.
And so if you happen to be in a large enterprise, starting to have some of those conversations around, look, we're acquiring this service, we're providing this service to our customers. Do you at the senior executive level understand what that means and why it's important that we spend the extra time and do the diligence to get a vendor that's been through the certification process, right? Ultimately, that's what it's about, is making sure that you can rely on the information that's provided and that data is safe, right? Those two things are super critical.
Thank you, Andy. I couldn't agree more. It's very interesting in a world where you really don't know who you're dealing with, certainly online or in a digital environment. It's becoming very real in the boardroom. I can speak from experience. Our board wants to know that we're standing behind what we're doing, and they want more than just management saying we're doing, we're checking the boxes.
So, all right. What certification actually is and what it isn't. Through these slides, we're going to just talk about what the certification process looks like through Kentara and what it actually isn't at the same time.
Again, we started talking about two very different claims here. You can trust us. We're compliant. We meet the standards. We're high confidence. There's no real external verification, or if there is external verification, it's an auditor who hasn't themselves been audited and isn't held to a specific standard. Maybe they're not actually even publishing very transparently the assessment criteria.
So, when you say trust me, what am I trusting you? What controls are you complying with? It's not auditable by relying parties most of the time. And then over here on the Kentara Trustmark side, it's assessed by an accredited assessor.
So, your auditor, and I realize I'm going to probably use assessor a lot. So, your auditor is actually audited against an independent standard. We've got published service assessment criteria.
Again, Kentara's ISO, we'll go into this a little more, but there's ISO accreditation, which is something to stand behind so you can trust the actual organization that's providing the assessment criteria and that full audit. There's a full audit trail. There's an auditor report. And then there's ongoing surveillance audits that ensures that on an ongoing basis, you maintain that compliance. It's not just a one and done. And your license to the Trustmark to show that you have gone through this process is revocable if you don't continue to meet those standards.
So, there's the self-assertion versus the third-party certification. They are markedly different. All right.
Andy, you want to tell us a little bit about the ISO 17065? Yes, at a super high level.
So, again, going back to this whole point about it's not just a checkbox, right? If you as a large enterprise are relying on a service that you're acquiring in whatever way, you're relying on that service to do a job properly.
So, you want it to be certified. You also want to know that when it has been audited, that that audit process is being done well, right? It's the who guards the guardians question, basically, is what 17065 helps to answer. And likewise, if you're a vendor of products in this space, you want to know that your product is being assessed properly and fairly.
And so, 17065, which Kantara assessors are now assessed against, certified against, essentially is that reassurance for you, right? You know that when somebody comes in and audits the product, when somebody says that they have a Kantara audited certified product, that that process has been done the right way. It's reputable. It's safe. You can lean on it and rely on it.
Thank you, Andy. And on one point there, in the U.S., there are this is really one of the only certifications that you can get that actually tests against control criteria. The interesting part is, and, you know, when you hear other vendors or vendors saying, oh, we're compliant, but you know the third-party auditor and you know the process.
So, like, I've been part of processes, specifically in the remote online notarization context, and I know this is being recorded, so I'll be careful here, where you know the vendors actually aren't maybe meeting the criteria, you feel very strongly, but they get to pick any and every auditor they could possibly want to go through this process. This really does help level out the playing field, and it is very notable that member that your membership in Kantara doesn't matter. It's not pay-to-play here.
Even on a board level, you can be on the Kantara board and not pay a single cent in sponsorship or as a member. They are divorced from each other. A lot of organizations still require board membership or Thai board membership for like a pay-to-play type thing.
So, I am very proud of the organization for not maintaining that type of requirement or allowing that. All right, so our certification programs, I kind of went through these quickly, but we've got the NIST SP-863 Identity Assurance Framework.
Again, we're testing against both REV-3 and REV-4. Right now for REV-4, we've got the IAL-2 assessment criteria that were released at the end of March, and our first company is going through that REV-4. What's unique about this NIST 863 Revision 4 that was published last August in the U.S. is it really componentizes identity for the first time, which is actually very helpful since that is the nature of how when you look at the actual identity marketplace.
We're in the process of publishing the AAL, the authenticator assurance level criteria, and this for Revision 4, we will actually have the federated assurance level audit or assessment that you can get completed previously for REV-3 that was not available. Kay's not here, but I believe it's due out this summer, those assessment criteria. Do you want to speak a little bit about DIATF? Are you looking at me? Or Finley? I'll do a bit and then Finley do a bit? Perfect.
No, actually, let's change that around. I'm going to let Finley go.
Okay, yeah, for the DIATF, there's five main roles you can come in as. Identity service provider, asset service provider, holder, that would be for your wallet, so your reusable identity, and CSP. So there's a lot of other things you need to read up on and make sure you know what you're applying for is the really important bit. We often get questions coming in not knowing what, and not really understand how they apply, what they're going to say they're going for.
And it's very difficult to find any sort of information about that outside of the provided government documentation for your own interpretation of it. And I'm there to help if you need it.
And yeah, it's well established now, the process for doing it. And yeah, any questions? Excellent.
Thanks, Finley. And I'll just overlay on top of that the point that's on the slide, but it's worth saying out loud, right, which is today, Kantara is the only UCAS accredited assurance assessment board in the UK. So if you want to be on the statutory registry of service providers in the UK, that is the option, right, is to go through Kantara. Without being self-serving about it, I think Kantara is quite proud of having achieved that.
And again, back to the 17065 accreditation, right, that gives you the assurance that it's being done really well. Excellent. All right. The last one here on the slide is the OpenID Foundation conformance program. This is new and very exciting. It shows kind of the progression here that Kantara has gone through, which is US-based, specifically the NIST 863, which is government-based identity and identity framework. And then we've got the UK and then more global and not tied to a government necessarily is the OpenID Foundation program. That is actually in the works.
We just announced the partnership. Very exciting. It also shows the how adaptable Kantara can be. We've got auditors who are excited and interested, will come up with the conformance criteria, and then now you'll have the standard and then you'll also have an audit to go along with it. I think a lot of the standards have benchmarks and you can go through a process that isn't necessarily a formal audit.
We've had other groups that are also interested and even some states in the United States where they're doing state endorsed digital identity that are looking for auditors and someone who is like a neutral third party that they know they can trust. So it's very exciting for Kantara.
Yes, finally, someone from the audience. So I've been leading the program for the OpenID Foundation and working with some of these guys on building out that conformance program. It's about ensuring that the independent testing service providers are able to deliver a diligent service and it can be relied upon. So Kantara would be checking the test providers who then are approved for independent testing of OpenID Foundation specs. It's going to be across the full range of OpenID Foundation test plans that we have available.
So that would include wallet domains and OpenID Connect-based stuff and shared signals and all the rest of it. So there you go. Thank you. Thank you for that participation from the audience. Very helpful. All right.
So again, let's talk here a little bit more about TrustMarks, what it tells a relying party. Again, that it was audited by a Kantara accredited auditor. The audit was qualified and independently verified. The great part about the OpenID Foundation process is, as you see, it's just all about ensuring your auditors are auditing to the same standard and ensuring that everyone is getting the same high level of service that's objective as possible and neutral.
Again, assessment was against published auditable criteria, that there's annual ongoing conformance reviews. So in the United States, the process is you do your initial first, it's a tri-annual, your initial first audit. It's a big one. And then every year, or year two and three, takes a piece, basically splits it up, and you do a piece of 50% in year two and 50% in year three, so that you're continuing to ensure that you're compliant. And then once you're done with year three, you hit year four, you start over again with a three-year tri-annual.
Again, the TrustMark covers a specific defined set of services, and it's very clear, all of the information can be found publicly. Those who are actually earned the TrustMark and gone through the process are available through a webpage that is accessible without a paywall, so those who need to rely on it can find it easily.
And again, I have to say the license is revoked if you are not in conformance even throughout that three-year period. It doesn't tell you everything you need about the vendor.
So again, if you're looking into what it means, you want to make sure you understand what that doesn't mean when you see the TrustMark. It doesn't mean that the vendor won't have incidents or issues come up throughout their lifecycle with you if you're purchasing services from them. It doesn't mean that any of their other products or services are certified or fall under that TrustMark. And then I guess these last two will tie together. It means that it applies to a specific potential regulatory regime, and it doesn't mean that those vendors are immune from fraud, breach, or failure.
I think I like this line at the bottom here best. Certification is a signal. It's a strong one. It's not a substitute for any of your vendor due diligence. You still need to know what your vendors are doing.
Yeah, and I do want to pick up on the transfer to different regulatory regimes. So one of the things we're starting to see now, and it tends to happen more with organizations that vendors that already operate, say, in North America, and then they're coming across into Europe or into the UK. And it always surprises me, and it probably shouldn't, but we get into these conversations folks like, oh, we've already got the certification in the US. That's fine, right? And these are vendors in the space. These are not even enterprises buying the services, right?
They're vendors in the space, and they haven't quite realized that they need to get certified correctly for the regulatory regime that they're going to be selling that product or service in. So it's really important to remember that, that those assurance processes are specific to a particular regulatory. That's really hard to say. Regulatory regime. Wow.
So yeah, just wanted to stress that. Thank you. All right. All right. So what does it look like from the inside? I'm going to talk about what it looks like for proof at a high level.
Proof, we're formally notarized. We're remote. We started as a remote online notarization vendor in the United States.
I've been, it's been my pleasure to help pass laws in over 47, well now 47 states for remote online notarization, which a component of that is you need to identify the individual remotely in a reliable way. We also now are actually more mainstream digital identity and that entire lifecycle of a consumer.
However, no one told us we needed to be IAL2 certified. We were a company that was looking for something to measure ourselves against. I still sometimes get looks from a few folks within the organization when I say, well, we still, like, it's not because we have a government contract that it was required. We were looking for a standard so that when we went to large enterprises, large international banks, we're in all different industries, financial services, insurance. We've got some very, very, very big name customers and we thought this was the best route to go.
Even though people were kind of giving us some side eye, a lot of vendors are doing it because they have a government contract and specifically in the United States where it references that you need to comply with 863 A or B, possibly C, but mostly A and B. So we took it upon ourselves to go through this process as a little old startup many years ago and we did it so that we could answer the question when people ask, are you compliant? We can say we are. We've gone through this third party assessment. It's from a very neutral body.
It became a market differentiator for us because our competitors weren't actually leading with the fact that they had the certification if they were selling to private business. They were only leading with that when they were doing an RFP with the government. So we've really, it's very interesting now to see when we go head to head with competitors that they're now referencing their certifications.
A SOC 2, type 2 isn't enough. They, for some reason, we're just leaving it out. So it was a lot. We were a startup. I guess we still are, but we're a very sophisticated startup. It was a lot. We had to get rigorous. We needed to make sure everybody understood within the company from engineers to the product folks. It wasn't just a check the box that we were all doing. We needed to have the policies, the procedures in place, and doing that all in a timely manner.
I mean, it was, it was a lot of work, but it's definitely been worth it and it's paid off hundreds, hundredfold, 100x for us. So again, the assessment process forces you to document things. There are things you're probably already doing, hopefully. It forces you to defend your controls and it really like puts that rigor in place that many companies really, they're doing, but they're not formally documenting it in the way that would help them pass this audit. So that's just a little bit about what it looks like for my company in the US, a smaller, a smaller company that was US based.
I don't know, Finley, I don't want to put you on the spot, but do you have any thoughts on what this might look like in the UK or? Yeah, there are less from a government side, but there are a lot of clients or incoming people that we have that say they've had a contract or something that relies on them getting the certification either directly or their supply chain as well. Okay. So there's a lot of that coming in that I hear.
I will say this, it doesn't mean you're still not going to get asked due diligence questions that are 26 Excel sheet tabs long, but it does mean though you have more credibility, especially when you get to the executive level meetings, we've definitely seen a difference. It's not, as we said in the last slides, people still need to check out their vendors and enterprises still are. So a little bit more about the process. There's the internal readiness process. This is all outlined on the Kentara website for both the UK and the US. It's very straightforward.
It's still a lot of work, but pretty straightforward. You're going to go through a gap analysis, make sure you have your documented procedures and policies. You're definitely going to want to do a little control testing and gather your evidence. And then the last piece here in this first box is define the scope. Are you going for one of the, I think it was five, D-I-A-T-F audit assessments, or are you going through I-A-L-2-A or I-A-L-A-A-L or F-A-L in the United States? You can do all three. I'm assuming in the UK you could do five at once if you wanted. Okay. That sounds like a lot.
All three at once in the United States is a lot. All right. Then you go to the assessment. You're going to pick one of the accredited Kentara assessors.
Again, don't get to just pick any assessor you want. They're going to do an audit readiness assessment. I believe this is the same in the UK when I looked at it. Once they do the readiness, they're going to go ahead and go into that full audit stage. They'll produce a report. They'll have any remediation or nonconformance requirements that are passed to you. Then over in the US, and I believe this is similar over in the UK, there's going to be a quality review. It's not just that the auditor says you're ready to go and here's your audit report. There's an independent board.
That in the United States is actually the audit review board actually is not controlled at all by the board of Kentara. We have no say over what they're doing.
Again, a wonderful feature if you want an independent audit. Then once you pass through the assessment review board, as long as you pass, you'll get issued that trust mark. It's issued for three years with again, the ongoing every year a portion of the assessment is completed. They call them surveillance audits.
In the UK, do you guys do it every three years like that too? Again, the trick is the actual audit review board, even if your auditor says it looks great and submits the audit report, they could come back to you and say, no, this doesn't meet the standard. You've got to go update or make corrections or change your controls. That can happen once or twice. It could happen not at all. Depends on how much the auditor ensured that you actually met the objective conformance criteria. If he's your buddy and he just wants you to pass, it's not going to help you at the end of the day.
You could go through the process dozens of times, which I don't believe anybody has, but just wanted to reiterate that. All right. What changed after certification?
Again, I told you it was actually a benefit for us. We put it on all of our materials. The people that we're selling to are the people that a lot of folks maybe in the audience are selling to, chief information officers, chief security officers, chief information security officers, sometimes now CFOs, chief people officers who are looking for identity solutions. It has helped because, again, we can point to a website with the conformance criteria. Kentara does a wonderful job of that. Our internal operations, it's just part of our daily life now. We know that this is what we're doing.
We need to make sure that we're making sure our policies and procedures are updated on an ongoing basis. It's just part of everyone's job. What didn't change is as the product changes and as the environment changes, continuing to change our products, we just need to make sure we keep our controls in check and that we're updating our auditors should controls change. If a client were to ask, are we certified? Or my new favorite question, do you have any certifications other than a SOC 2?
Yes, we do. We have several. This is but one in our belt. All right. This is kind of breaking down here. I'll run through these really quick. The pieces of what the audit looks like for you all if you go through this process.
Again, define your scope before you engage an auditor. Know what you want to be tested against. Do your gap analysis and then make sure you pick that auditor who will push back and challenge you. Then surveillance audits are real. Put them in your calendars. Make sure that it's not just a one-time event. Make it part of your company's culture. It's critical. It makes the ongoing audits, I don't want to say easy, but it just makes it part of your everyday life.
And then make sure you actually tell people you have it, not just people who work in the government who are looking to procure a service. It is a competitive advantage. And I'm just going to pick up on that last point and echo something that was on one of the slides earlier on. It's not that long ago that this was really in most cases just about a competitive advantage in the sense that it was something you could say you had and that's great as a vendor in the space.
Now what's happening is, and it's back to this, you know, executives understand this much better now in enterprises that are acquiring these services. It's a requirement, right? If you don't have a trust mark, if you don't have conformity assessment in the right market where you're selling the product, you're never going to get past the RFP stage. That's a change in the market. It's an active change in the market. You don't see it everywhere, but it's absolutely happening.
And so this is now just becoming a requirement in exactly the same way that, you know, compliance is becoming a requirement. All right. This next part is supposed to be a little interactive. So what's blocking you? What's blocking you from pursuing certification or requiring it from your vendors? Anyone? All right.
Well, you get a gold star. All right. So is it cost? Is it the timeline? Uncertainty about the certification? Not knowing where to start? Those are all of the common questions. If you have friends who are saying any of these things that aren't in this room, you obviously know they can come find us. We can talk through any of this. What would make certification more legible to your board, your procurement team, or your regulators? What's the gap between what the certification provides and what your decision makers need to see? So I have a question. Yes.
For the room, you know, Renee spent a little while explaining what this stuff is and how it works and why it's important. How, you know, is this a conversation that you think you're going to have to go and have internally?
And if so, where are you going to go and get those materials to help you have that conversation? Because bear in mind, we're talking to an audience of, you know, relatively well-read, you know, identity folks who kind of understand this. Now you're going to go into a senior executive or a board member and say, we've got to do this certification thing. Or we need to acquire a product that has this trust mark. How do you think about explaining that in a sentence as opposed to a 20-minute deck? Yes. Go ahead. Please state your name for the audience online.
Sorry, I don't have an answer to that, but I do have a question. Excellent. Go. So I'm Graham, by the way, from the UK, from the Office for Digital Identity and Attributes. Welcome. We run one of those systems. You said earlier on that actually one of the assumptions that people make is that if you're certified in one country and maybe that certification is to, you know, ISO 17065, then your certification could automatically be accepted in another country. And sort of people think that that's, you know, it's not the case, but people think that might be the case.
And people might think that's the advantage of certification. Like, if that's not the case now, do you think it could ever be?
Oh, that's a fascinating question. So hopefully everyone heard that. But the kind of summary of the question essentially is where today certifications don't easily translate from one regulatory environment to another, is that something that might change over time?
Look, if I had a crystal ball, then this would be an easier one to answer. So I hope so. I think it would be a lot simpler if we could get to that point.
However, certainly in the case of regulatory regimes that are government driven versus industry sector driven, right? I think, and history probably supports this view in other sectors, that getting deep alignment internationally, at minimum, takes significant time. So at least we're getting to a point where there's a lot of similarity between things. That helps if you're a vendor going through this in different places. There's a lot of crossover in terms of the work that you need to do. You still need to do the work, but the fundamentals are very similar.
It would be lovely to think that at some point we could just have a single global certification, but I'm an optimist. So it's kind of a non-answer answer, Graham, but I hope it at least gives you some sense of direction. All right. Excellent. All right. So where is this going?
Oh, that was a great segue too. Thank you. All right.
Kentaro, I'm going to ask you a question. Thank you. All right. Kentaro and Wallace, where the real work is. So in the United States, we do have the Privacy Enhancing Mobile Credentials Work Group, or PEMC Work Group. Kay is actually speaking tomorrow on a panel with a representative from AMVA, the American Automotive, or I'm going to mess it up, American Automotive Vehicle. Okay. Yes. I normally could do this, but I can't on the spot. So anyways, Kay is speaking tomorrow because this is a real issue in the U.S.,
and obviously it is something, there's a pending deadline or pending deadlines in the U.K. here. This is how you can actually get involved. Even if you aren't based in the U.S., you can actually join this work group. You don't need to be a member. You can have an individual membership. We do offer those. But this is helping to address the gap in the standards between the ISO, the MDL spec here in the United States. And honestly, I think it would be great if we could somehow, this goes to your question of how do we get more international standards to map in one area.
We need participation though from others outside of just the MDL space. All right. And then the DIATF Holder Services, do you want to tell us a little bit about Holder Service Provide, like what you guys are actually looking at in that audit process? Yes. So for the audit is looking for just that they have that reusable identity, that it's storing it and they can bring it back up. And there are a few, quite a number. I think I last checked, maybe there were eight already on, probably more. And one ID was the first one, I think back in August or September last year.
And of course, as only accredited cab in the U.K., it's only through Compower that you can get your Holder Service Provider or your wallet certified against that scheme. And completely off topic, American Association of Motor Vehicle Administrators.
Thank you, Google, for answering that question in the background. Wonderful. All right. So what is Cantera building towards?
Again, the reset milestones, we are the only UCAS accredited cab for U.K. Again, very exciting. We did publish the criteria and finalize the criteria for the 863A that was finally published in March, working through the AAL criteria right now, should be published in the next month or so, and then on to the FAL criteria. We talked about the OpenID Foundation. And thank you, correct?
Thank you, Mark, for jumping in there. Cantera, again, is the only certified body in the U.K. We're interested in continuing to find new frameworks where we can help implement standardization. So if you ever, like, it's a great question, how can we make this more standard across nations and globally? I can't say it's going to happen overnight. I think the EU is the closest to be able to do it. And even in the U.S., the states are fragmented at times. Three calls for action for everyone. If your identity providers are not yet certified, you should start holding them accountable to be certified.
If you are an identity provider, get certified. Relying parties should be asking these questions. I actually had someone who couldn't attend ours for the competing AI conversation take pictures of some of the questions, because they were good questions, and she works for a consortium of relying parties.
And then, again, if you're in the government or policy, make sure that you're tying back to these frameworks. In the U.S., we are actually doing a lot of quite a bit of policy work where the government isn't tying back to the framework, unlike in the U.K., where we're trying to encourage them to tie back to this neutral framework, not just you need to be IAL2 self-certified.
That is a thing of the past, but it was very popular when in regulations or even laws, when they would mention that you needed to be NIST 863, there was no actual conformance criteria, and they didn't point to a specific trust mark. But that is changing now in the U.S.
Yeah, and I think sorry, Renee, I'm digging again, jumping in. One of the things that maybe isn't obvious unless you think about it, in those use cases where you need to know that you are dealing with a real human being and that there are certain attributes about that individual that you need to know to a reasonable level of assurance, that requirement, when you have it, and it's important to note that there are plenty of use cases online where you don't need to do those things, right?
But when you do, it is increasingly important in a world where we are seeing orders of magnitude more non-human users or either deliberately aggressively, right, so as a threat vector, or just legitimately, right, agents acting on behalf of humans quite correctly, it is super important that when you need to know that you have got a real human on the other end of the line, as it were, that you have trust in that statement. That ultimately is why this is so important right now. It's why there's so much work going on here.
It's why enterprises are starting to insist on it, and it's why policy frameworks are including it exactly to Renee's point. It's why vendors need to make sure that they're stepping up as well. Thank you for that in closing, because our last slide here is how you get in touch. Yes. I get so excited. Hold on. The previous slide, the first point, speak about gap analysis. For my company, that will be a big provider in Italy, it's a big issue to understand the gap between our current work and what we need for the certification with the ADAS compliance certification.
And we are new on something like certification, and our goal is to certify it, but it's not clear to us what a company could give us to understand what we need to certify it. The gap analysis is this. My company needs to understand how much work we have to do to have the compliance and the certification. Yeah.
No, I understand. So I'm going to give a really high level brief answer now, and then I'll suggest that we maybe have a separate conversation afterwards, and we can put you in touch with people who really have the detail. At a super high level, and Rene mentioned it earlier, on the Kantara website, you're going to find walkthroughs. So Rene had some slides earlier on that, again, at a really high level said, okay, here are the steps you're going to go through. On the Kantara website, you'll find each of those steps broken down to a great level of detail.
That will then help you understand what are the steps I need to go through, and you can do a gap analysis internally to say, okay, which of these things am I already across? Which of these things am I going to need to do extra work on? So that's the very brief answer, which applies generally across all the certifications, and then I think there's probably going to be some specific questions which we can pick up afterwards, and it may be that we need to pass some of those on to others.
Obviously, Kay's not here, and she's probably best placed to answer some of that, but we've got some other folks around who can help. Does that help?
Yes, but in general, gap analysis give us the answer. What are the work that we have to do to achieve the certification?
Right, yeah, and so that's the detail. Again, you'll find those steps listed out on the Kantara site, and we can walk through some of that.
Okay, John. We're all getting our steps in. It's great. There's a huge room, isn't it? So I'm John. I'm the Chief Executive for the Office of Digital Identities and Attributes, which is the UK entity that owns the DIATF Trust Framework that was mentioned in your presentation.
I think to your point about gap analysis, and it's also to the point that Rene and Andy were mentioning, it's really important that, and certainly from the UK government kind of structuring some of this stuff, that you've got independence of the person giving you advice about what you should be doing from the person that's then assessing you. It's a kind of core tenet of the 17065 standard that Andy was mentioning.
A lot of this ecosystem relies on people being highly skilled and not being biased when they're making decisions, and the independence of the board making decisions on certification for Kantara, the independence of the person giving you advice, it's really important you separate all that out, because it would jeopardize the quality of all that stuff. So I think I just want to let you know that that is a thing you'll need to do.
It's quite hard to find quality consultants that can do that for you, is the challenge that we haven't managed to crack, I don't think, but I suspect that's probably true in lots of other ecosystems as well. I had a follow-up question as well, which was about the range of stuff that Kantara is now starting to do, and the different types of certification that you're offering in different contexts. So the UK system is very explicitly about a 17065-based product conformity process.
I'm fairly sure that, Mark, your process on testing is not 17065, it's other stuff because it's technical conformance. How are you seeing the market react to the need for different kinds of certification, pushing in different directions and requiring very different types of assessment, and how complex that is for organizations to navigate when they have to get certified?
Yeah, that was kind of two questions in one, John, which was sneaky. So I think, contextually, one of the things that has happened is what we used to think of in the industry as technical requirements, essentially, right? Does my product technically do this thing? Does it meet the specification? Will it interoperate correctly with another product that also technically does these things correctly? Sorry. We used to think of that as a technical set of requirements, right?
And so an enterprise or a line party would come along, they'd buy a product, they'd say, okay, does it interoperate with this other product? Yes, no, fine. As the data that we're dealing with becomes more small S sensitive, and I say that because I'm not, I don't mean to call out GDPR in this context, right? But just data that you need to handle more carefully, it's more about people. And as enterprises, line parties start to understand that identity is, and it's a thing that we all know in the industry, right? We've been saying it for 10 years.
It's a fundamental underpinning of the business, right? It's not just technical infrastructure anymore. It's actually what enables business to happen. And coming back to the agentic point, increasingly, it's the case that it's what helps business happen safely. Then we're starting to see the market at large. So not just vendors, but they're being pushed by their enterprise customers, come and say, okay, this used to be a technical requirement. Now it's a business imperative, right?
Now we need to have faith that we can trust these products and services that we're acquiring and installing and running our customer data through. I think, and now I'm going out on a limb a little bit, but I think that then what's happening is that organizations are saying, well, okay, what exists already in the identity space? And there are some answers to that, right? We've been doing certification in the US. We've obviously been doing it in the UK against these various trust frameworks and so on and so forth for a while. The knowledge of how to do that is relatively mature.
It's well-established. We know how to industry. We know how to do good audits. We know how to make sure that they are trustworthy and reliable and impartial and all of those things. Okay. Now the technical certifications are becoming a business requirement. We want to see the same principles applied to those. And so that's why I think we're starting to see that requirement come out of the market. And Kantara is in a good place to respond to that need because we've got some well-established processes that we can extend. And somewhat, I'll pick you up in a second, Mark.
Somewhat to Graham's point earlier, whilst these things are clearly different things, there are some fundamentals that are true full stop about how you do a conformity assessment, how you do an audit, right? And so you can apply those same sets of skills and capabilities and governance processes, right?
I mean, you pointed out that the separation and Renee made the point earlier of, you know, the assessment and then the review board and those things are separate and that all of that can be applied similarly to these, you know, new, slightly more technical areas. Mark? Yeah.
So, Mark in OpenID Foundation, sorry, I didn't name myself earlier. Actually, the way the IDF is looking at it is that the technical testing needs to be done in a controlled fashion. And so we are anchoring our conformance program for independent parties in the appropriate ISO specs to make sure that they are running the processes of the technical testing correctly. So we're layering it to say, well, these guys need to run a robust process when they're, you know, when they're executing the technical tools to do the technical testing.
We're actually saying the auditor at the top must be 17065, the testing body in the middle must be, or should be doing things aligned to, I think is the language you're using, 17025, because we don't want to be exclusively, you know, sorry, excluding organizations because they don't have the ISO thing. The important thing is that they run the processes correctly.
Thank you, Mark. John, did that answer the question? You got halfway there. The other half of the question, I did ask two questions, you're right, was how confusing is this for vendors? So one of the bits of feedback that we get quite a lot from stakeholders in the UK market is that, you know, there's a, I think it's 135 pages of requirements that the UK government has published on the trust framework. NIST is equally as large, the EU's ARF is massive, and there's been, I think, 18 versions of that now. How do they possibly keep up with all these changing requirements across multiple markets?
And then we're also layering in new kind of layers of the certification stack underneath it for accredited testing, as well as accredited conformity assessment and those kinds of things as well. And just how complicated is that for people to actually navigate? And do you have a sense of what would help, aside from kind of just making one mega standard across the whole planet, because that feels unachievable in the short term, what would help to kind of simplify that environment for vendors from the perspective of someone's interacting with them all the time? Yeah. Okay.
So I, thank you. So I think, yes, there's a lot of complexity for vendors. Vendors as a general statement, as a general group, are not unused to having to deal with this, right? And that's been the case for a very long time.
I mean, you think about some of the compliance you have to do, say, if you're a vendor in the U.S. to get onto the, what's it called? The U.S. government cloud thing.
Yeah, that, it'll come to you in a minute, and you can jump in and remind me what it's called. So, and again, there's a whole set of requirements there, and they're very complicated. And as a vendor, you go through a process of, okay, at what point are we ready to engage with that process, right? So it does take a certain amount of maturity as a vendor to approach this and to get through it well.
I think, but vendors are used to doing it, right? So it's perfectly possible. It's fine. I think what would help is the more, the more standardization, the more alignment we can get across the different regimes, the easier it is, particularly if those things are clearly labeled and called out. And so the parallel I'll draw here is with GDPR and other equivalent privacy, privacy, pick your pronunciation of choice, privacy regulation. So obviously in Europe, GDPR was published. It wasn't much after that that in Brazil, they published the Brazilian equivalent, LGDRAT, forgotten it.
But anyway, there's a Brazilian equivalent. And there were bodies such as the IAPP, the Institute of Privacy Professionals, who published work that essentially compared the two sets of regulation and said, okay, these things are essentially the same. So if you're thinking about doing a privacy impact assessment, once you've done it over here for these things, that absolutely translates one to one, right? Or as near as makes no difference. These four clauses are fundamentally different, and you're going to need to think about how you handle those, right?
So I think, yeah, it's going to be a while before we get to full alignment for everything. We may never get there. But the closer we can align these things, the easier it's going to be for vendors, the easier it's going to be for the marketplace to understand. And actually, the safer those services are going to be for the people who are using them, right? Because there's less risk of gaps occurring where bad things can happen. Mark. So when I was researching building the conformity program for OpenID Foundation, I spoke to other non-profits that were doing something similar.
And there were two examples where it really drove us towards building something. Essentially, two other non-profits with conformity assessment programs had had bad actors get into the ecosystem as authorized entities. And it was only because they had rules that they were able to eject them. So to quote my friend Andy from yesterday, this is why we can't have nice things. Or do it for cheap, actually, is really the point, right? Yeah. Thank you. Anyone else have a...
Yeah, go ahead. We're going to run a microphone to you at speed and in danger. Careful there, Mark. Thank you. I'm Luke from the Big Tech Bank in Switzerland, so on the customer side. My question is regarding the large vendors. We always see SOC2 and so on. Why don't we see more trust, Mark, and more sectors that are covered by the initiative? So we can... Does it mean they are not completely certified? Does it mean it's too complex for them, like the one like Microsoft, AWS, and so on? Yeah. So I think, and Rene, you might want to add something to this.
I think some of it is that it is still a, relatively speaking, nascent market, right? So yeah, we've been doing, at least as Kantara, these kinds of assessments in the US for a while because there's been a requirement in the US for that to happen. But most of those requirements have been for government services rather than for commercial services. That landscape has changed, as a result of which you're starting to see more vendors go through this in the US. Similar story in the UK, where until relatively recently, there wasn't a legislative framework that really covered this.
There wasn't a trust framework that really covered this. I'm skipping over loosely some of the earlier work. But essentially, that's a reasonable description. That situation has changed, as a result of which you're starting to see the market pick up. The same thing is happening elsewhere. I'm less familiar with the details of the European, sorry, politically European market. But it's a similar situation, right? So you're starting to see these vendors now apply the trust market. So I think the answer is it's a timing question, right?
It's starting, and you're going to start to see these things arise. As a relying party, as an enterprise, asking that question of your vendors is a super helpful thing to do, right? Because they will react to that. And the more that we get people saying, look, we need certified services, right? It helps us as an organization be safe and know that we're safe. Once vendors start to hear that message more, not just from folks within the industry like me with my independent hat on, but from large enterprise, it will drive that process as well. Renee?
While you stole my thunder, you need to start asking your vendors for it. And Kentara, also, again, this goes back to my trope about how my company was asked, why are you doing this?
I mean, four or five years ago, it was crazy that we would be going down this road towards a government standard that most of the time the government wasn't enforcing, even though it is actually funded by the U.S. government.
So for us, it was a competitive advantage. We find more and more now because we know who we're talking to. We know the large banks are looking for credible vendors. And in fact, most of our competitors can't have these marks, but are they actually offering the service that has the mark? It depends, and vendors should be able to explain the difference. I think this also goes to what it means to actually establish an identity and what you can rely on, not just the standards around communication and how systems communicate across the wire, but really, can you all trust what this identity means?
Because if it met the specific conformance criteria, then you should know that's how that person was identified. So we're talking about the who, not necessarily how you transfer the information across systems. So it is.
It's also, Kantara, joining more groups like this and, you know, Mortgage Bankers Association in the United States and other financial services industries and communicating out that there is a standard, there is a neutral third party. Again, we're not going to, it's not doing all the work for you, but it's more than a SAC-2 and not as specific as like a web trust for CA or RA audit or, so anyway. And so to add more color to what both of you just said as well, in the UK example, Andy's exactly right.
So up until December of last year, the UK didn't have the ability to point its structures at a legally assured thing that would then give confidence to relying parties that they weren't going to fall afoul of the requirements. So we've now got the ability under our disclosure and barring service process, for example, which is a criminal records check in the UK. It's now a legal requirement that in order to do those checks, if you're doing it through a private sector provider, they have to be on our statutory register.
Later this year, we're going to be changing the law on alcohol purchases to say that people's wallets have to be on those systems as well. I think where some of the disconnect and some of this space does come from though, is that when we talk about identity products, we're not talking about the same things a lot of the time, right? There's the kind of consumer facing end of this market, which is largely what our domestic trust framework is kind of angled towards. It's not really going for your kind of, as your kind of style, active directory style products in that way.
I don't know if NIST is in the same direction, but we're much more focused on kind of consumer usage of digital identity products rather than kind of business to business or kind of employee engagement activities, which may also explain why it's not popping up in some of the spaces in the industry that you might expect. Yeah, that's a fair point, John. Thank you.
And I, you know, to add to that and to come back a little bit to this, it's an evolution, right? And it's happening relatively quickly. One of the requirements we're starting to see, and I've seen it, this may be observer bias on my part, right? But I've seen it more in the U.S. than elsewhere. I know it's happening elsewhere. Our business requirements around workforce assurance, right?
So, if you're doing remote hiring, for example, making sure that the person you're hiring is actually a real person, it turns out to be a major issue. I don't believe, although somebody feel free to correct me if I say something that's completely wrong at this point, I don't believe that there's an awful lot of legislation anywhere around that. It's more of a business requirement, a sensitivity to risk. But my expectation is, and I have no, you know, secret knowledge here, I'm guessing, but I suspect that we're going to start to see some hard requirements coming up around those things.
That, again, is going to start to drive the market. And you already see some early stages of that.
You know, several countries have got rules around right to work that, you know, where you need to verify those things. Remote hiring is a particular risk. And my suspicion is we're going to start to see some activity around that.
Mark, did you have something? Okay. Excellent. Anyone have any other questions? No more questions, Renee. All right. Excellent. Thank you all for participating. All of the information here on this slide will also be available online for you. I think it's within four weeks, this presentation, the entire thing will be available. You can find the information at the KentaraInitiative.org. Kay Chopard will be here later this afternoon. She's presenting tomorrow. Somebody from the American Association of Motor Vehicle Administrators.
Thank you, Andy. Yes.
Well, she'll be here tomorrow and Thursday. If you've got any questions or don't like the answers we provided, maybe she'll provide you a different one or a better answer. But thank you all, and I do appreciate the participation. Yeah. Thank you. All right.
Oh, and thank you, Andy and Finley.