The UK DVS trust framework 1.0 reached its earliest start date on 1 September 2026. What certification, the CertifID mark and MLR reliance now mean for firms.
Table of contents
The UK DVS trust framework 1.0 reached its earliest possible start date on 1 September 2026, though nothing can be certified against 1.0 until an assessment body is accredited. Only then can the first licences to use the UK CertifID mark follow. Commencement is tied to accreditation, not to the calendar.
- The DVS trust framework 1.0 was published on 9 June 2026 under section 28 of the Data (Use and Access) Act 2025.
- It takes effect when the first conformity assessment body is accredited to certify against it, which the document says will be no earlier than 1 September 2026.
- Services certified against the gamma (0.4) version get at least 15 months to uplift, and gamma certificates expire once 27 months have elapsed from the in-force date.
- HM Treasury approved guidance published on 26 February 2026 says certified services can satisfy regulation 28 for individuals, and can also verify company directors.
- That same guidance says non-certified services cannot reliably be deemed suitable for identity verification under the Money Laundering Regulations.
What has actually changed on 1 September 2026?
The date marks the earliest point at which version 1.0 of the DVS trust framework, the UK rulebook for digital identity providers, can bind anyone. It was published on 9 June 2026, after a pre-release on 3 March 2026. Its commencement clause is conditional rather than fixed to a calendar day.
The wording matters. Paragraph 0.a states that the DVS trust framework comes into force under section 28 of the Data (Use and Access) Act 2025 on the date the first conformity assessment body is accredited to certify against it, "which will be no earlier than 1 September 2026".
Three government documents describe that trigger three different ways. The framework points to the first body, in the singular. The June explainer says 1 September or the date at least one body is accredited under the 1.0 scheme, whichever is later. The annual report says version 1.0 will come into effect on 1 September "subject to successful accreditation of conformity assessment bodies", in the plural. Accreditation comes from the United Kingdom Accreditation Service, and the first body accredited under the predecessor framework was the Kantara Initiative, in November 2025. Accreditation against the 1.0 scheme is a separate step, and no confirmation of it had been published at the time of writing.
| Milestone | Date | Instrument |
|---|---|---|
| Non-statutory gamma (0.4) published | 26 June 2025 | Predecessor framework |
| Part 2 provisions commenced | 1 December 2025 | S.I. 2025/1213, reg. 2 |
| Statutory gamma (0.4) published | 1 December 2025 | Section 28 |
| HM Treasury MLR guidance | 26 February 2026 | Approved guidance |
| UK CertifID mark designated | March 2026 | Section 50 |
| 1.0 published | 9 June 2026 | Section 28 |
| Earliest 1.0 commencement | 1 September 2026 | Conditional on accreditation |
How does certification under the DVS trust framework work?
Certification runs through independent assessors rather than government. A provider engages a conformity assessment body, accredited by the United Kingdom Accreditation Service and approved by the Office for Digital Identities and Attributes (OfDIA), now in DCMS after moving from DSIT. It audits the service and issues a certificate. The provider then applies under section 33 to join the register.
The register is the legal hinge. Section 32 requires the Secretary of State to establish and maintain a register of persons providing digital verification services. Subsection (3) adds a publication duty: "The Secretary of State must make the DVS register publicly available."
Section 50 restricts the designated mark to registered providers. The framework adds a licensing layer on top: the UK CertifID mark is a registered trade mark, OfDIA licenses its use, and authorisation requires both a valid certificate against the 1.0 publication and a register listing. Each licensed service gets its own trust mark identifier, which is what a buyer can actually check.
The DVS trust framework sets rules across organisational governance, information security, privacy and data protection, technical specification and user experience, and certifies roles rather than whole companies: identity services, attribute services, orchestration, holder services such as wallets, and components.
Existing certificates do not evaporate. Every service certified against the gamma version of the DVS trust framework has a bespoke transition based on its own audit cycle, and government has committed that every service gets at least 15 months to uplift. A service may stay on gamma at its next evaluation, but at the evaluation after that it must move to 1.0 or lose certified status. A lighter delta assessment, covering only changed rules, is available to services that completed a full gamma audit in the past year and sit on a three-year cycle.
Gamma remains available for new certification in two narrow cases: where an application was made before the in-force date but the certificate is issued after it, and where a provider holding an unexpired gamma certificate applies within 15 months of that date. Gamma certificates then expire and should be ignored for the purposes of certification and Part 2 if 27 months elapse, the service uplifts to 1.0, or the certification lapses on its own terms.
What does this change for your Money Laundering Regulations obligations?
Reliance is settled by HM Treasury guidance published on 26 February 2026, which states on its face that it is approved guidance for the purposes of compliance with the Money Laundering Regulations. It is a different document from the OfDIA explainer that followed in August, and it names the UK digital identity and attributes trust framework, which the 1.0 text confirms is the same document under its earlier title.
It says services certified against the trust framework and on the DVS register are a reliable and independent source of information. Specifically, for individuals, firms can fulfil their obligations under regulation 28 by verifying a customer's identity using a certified and registered service. Firms may also use one to meet obligations regarding the verification of company directors, which matters for anyone running business onboarding. It warns, though, that firms should not assume digital identities fulfil every aspect of due diligence, naming the purpose and intended nature of the business relationship.
The guidance is equally clear about the other direction. Services "cannot reliably be deemed suitable for identity verification in compliance with the MLRs" if they are not certified and therefore not on the register. Within the MLR perimeter, registration is closer to a gate than a badge.
Four limits belong in your policy. First, the firm's own risk assessment survives: businesses must assess each customer's risk and select the level of assurance commensurate with it. Second, that assurance has a fixed vocabulary, because certified services must express the identity outcome as a Good Practice Guide 45 level of confidence, being low, medium, high or very high. OfDIA warns this may affect many services that regulated businesses already use. Third, the August explainer puts attributes outside the perimeter: they are not part of the identity check and are not covered, and there is no obligation to source politically exposed person or sanctions screening from a certified service, though it is strongly recommended. Fourth, liability does not move, since regulated firms remain ultimately liable for failures to apply due diligence properly.
Everything downstream is untouched. Ongoing monitoring, enhanced due diligence and suspicious activity reporting run as before, and firms must ensure a service meets the record-retention requirements in regulation 40. Sector guidance sits on top.
| Sector | Guidance body |
|---|---|
| Financial services | JMLSG |
| Accountancy | CCAB |
| Legal | LSAG |
| Casinos and gambling operators | Gambling Commission |
| High value dealers, MSBs, TCSPs, estate and letting agents | HMRC |
Beyond the MLRs, supplementary codes under section 29 cover digital right to work, right to rent and Disclosure and Barring Service checks, and separate work will extend certified checks to alcohol age verification in England and Wales once Parliament approves it.
What is still uncertain about the DVS trust framework?
Commencement itself is the largest open question. A DVS trust framework whose start date depends on an accreditation event is harder to plan around than one fixed in a statutory instrument. Firms writing policy against "1 September" may be relying on a date that has not yet done any legal work, and the three official formulations do not help.
The second uncertainty is scope. The DVS trust framework states plainly that it does not design a centralised or mandatory national identity system, and does not supersede other duties including data protection law. Outside the MLRs and the supplementary codes, firms may verify identity by other means. Inside them the position is stricter, so the general voluntariness of certification should not be read across to money laundering compliance.
Third, reliance is not transfer. A certified check improves the evidence behind a decision, but the regulated firm keeps the obligation and the liability, and supervisors will still ask why a given level of confidence matched a given risk. A certificate does not answer that question.
Fourth, the register becomes ambiguous to read. Only 1.0-certified services can be licensed to display the mark, but display is optional, so an absent mark could mean a gamma certificate, no certificate, or a 1.0 certificate the provider has chosen not to advertise. Buyers who treat the mark as a pass or fail signal will misread it, and the per-service trust mark identifier is the only reliable check.
Finally, the supply base is thin and can attrit: five providers were removed on 1 April 2026 when older beta certificates expired. The first annual report recorded 46 providers offering 64 certified services, and OfDIA has said it will encourage a greater range of accredited assessment bodies into 2027.
How does the UK approach compare with the EU wallet?
The two regimes solve the same problem from opposite ends. The UK certifies commercial providers and publishes a register, leaving the market to supply the credential. The EU requires member states to issue a wallet to citizens under Regulation (EU) 2024/1183, with the state as issuer.
| Dimension | UK digital verification services | EU digital identity wallet |
|---|---|---|
| Legal basis | Data (Use and Access) Act 2025, Part 2 | Regulation (EU) 2024/1183 |
| Who supplies the credential | Certified private providers | Member states |
| Assurance vocabulary | GPG 45 levels of confidence | eIDAS levels of assurance: low, substantial, high |
| Public mark | UK CertifID, licensed and optional | EU trust marks |
| AML reliance | Approved guidance ties it to regulation 28 | Handled through national AML rules |
A single verification event will not travel between them. Firms serving both markets should expect two acceptance paths, a pattern familiar to anyone who followed the EU age verification trusted list or the EUDI wallet biometric portrait decision.
The Digital Identity Sectoral Analysis Report 2026, published on 8 July 2026, counted 275 firms generating an estimated 2.027 billion pounds of annual revenue and employing 9,624 full-time equivalents, with 77 per cent of UK consumers having used a digital identity service.
How should compliance teams respond?
Check the register rather than the marketing. Confirm which providers are registered, which DVS trust framework version each certificate names, and when each expires, because that date sets the uplift clock. Ask each provider when it intends to certify against 1.0 and whether it qualifies for the delta route.
Then separate identification from everything attached to it. Record which parts of customer due diligence a certified check evidences under regulation 28, and mark screening, monitoring and enhanced due diligence as out of scope. Capture the GPG 45 level of confidence selected for each customer segment and the risk rationale behind it, because that is the artefact a supervisor will test. Note that this is a UK measure and does not map cleanly onto the assurance levels used in identity proofing elsewhere. Then review retention: certification raises the standard of the check but does not reduce the volume of identity documents your systems hold, and holding less remains the cheapest way to shrink breach exposure.
That last point is where Zyphe fits, with one thing said plainly. Zyphe is not on the DVS register, so for MLR identity verification in the UK you will need a certified provider for that step. The architecture question is separate and still worth asking. Zyphe performs NFC chip reads to ICAO 9303 and eIDAS standards with two-step liveness and no image upload, splits personal data so no single node holds a complete record, and issues a reusable credential the customer controls. To see how that changes what your systems retain after a verification, book a demo or read how it works.
The bottom line
Version 1.0 arrives with a public register, a licensed mark and, more importantly, approved guidance that tells supervisors what a certified check is worth. For teams running KYC in the UK, the near-term work is unglamorous: diarise the uplift dates, and stop treating a certificate as evidence of anything beyond the identity check itself. The reliance is real but bounded, the transition runs for over two years, and the obligation never leaves the regulated firm. Teams that write those boundaries into policy now will find the next supervisory conversation much shorter than those that read the headline and assumed the whole file was covered.
Cited sources
- Data (Use and Access) Act 2025, Part 2: digital verification services
- Data (Use and Access) Act 2025, section 28: DVS trust framework
- Data (Use and Access) Act 2025, section 32: DVS register
- Data (Use and Access) Act 2025, section 50: trust mark for use by registered persons
- UK digital verification services trust framework (1.0), full text
- HM Treasury: using digital identities with the Money Laundering Regulations, approved guidance
- OfDIA: uplift to 1.0 trust framework, pathways and timelines
- OfDIA: how digital verification services help meet Money Laundering Regulations obligations
- OfDIA: building trust through independent, accredited conformity assessment
- OfDIA 2026 annual report on the operation of Part 2 of the Data (Use and Access) Act 2025
- Regulation (EU) 2024/1183 establishing the European Digital Identity Framework
- Digital Identity Sectoral Analysis Report 2026
- Good Practice Guide 45: how to prove and verify someone's identity
- Digital verification services register
Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.