DIATF / DVS certification: what it actually takes
The UK’s digital-identity rules moved from guidance to law. The framework once known as the DIATF is now the statutory DVS (Digital Verification Services) trust framework, given legal force by Part 2 of the Data (Use and Access) Act 2025 and run by OfDIA. Here’s what certification means, who needs it, and where Zanyara honestly stands.
The framework, briefly
OfDIA — the Office for Digital Identities and Attributes, part of the Department for Science, Innovation and Technology — owns the trust framework and maintains the public register of certified providers. The framework reached version 1.0 in 2026, superseding the earlier beta/gamma DIATF drafts. Its aim is a set of common rules for security, privacy, inclusion and interoperability so a relying party can trust a verification without re-checking the provider themselves.
What certification involves
- Independent assessment by an approved conformity-assessment body against the framework’s rules and any supplementary codes for your service type.
- An information-security management system and evidenced controls (security, fraud, data handling).
- Data-protection groundwork — DPIAs, retention and erasure, lawful-basis and consent records under UK GDPR.
- Inclusion & accessibility evidence — the framework explicitly cares that checks don’t exclude people.
- Registration by OfDIA on the register, plus a right to display the government-endorsed trust mark.
Who legally needs it
Providers offering Right to Work, Right to Rent or DBS digital identity checks must be certified and on the OfDIA register — it is a legal requirement, and the earlier beta certifications were time-limited on the way to the statutory framework. For general customer KYC and AML onboarding, certification is a powerful trust signal and increasingly an expectation, but whether it is mandatory depends on your regulator and the specific check.
Sources: GOV.UK / OfDIA — “Enabling digital identity” blog and the OfDIA 2026 annual report on the operation of Part 2 of the Data (Use and Access) Act 2025; the register of digital identity and attribute services. Educational overview; confirm current requirements with OfDIA.
Frequently asked questions
- Is the DIATF the same as the DVS trust framework?
- Effectively yes — it’s the same lineage. The UK Digital Identity and Attributes Trust Framework (DIATF) has become the statutory Digital Verification Services (DVS) trust framework, now on version 1.0, placed on a legal footing by Part 2 of the Data (Use and Access) Act 2025. OfDIA (the Office for Digital Identities and Attributes, within DSIT) owns and operates it.
- How does a provider get certified?
- A provider is independently certified against the trust framework by an approved conformity- assessment body, then registered by OfDIA on the public register of digital verification services. Certified providers can use the government-endorsed trust mark. Certification covers security, privacy, inclusion and interoperability — evidenced through an information-security management system, data-protection assessments, and framework-specific controls.
- Do I legally need a certified provider?
- For certain checks, yes. Right to Work, Right to Rent and DBS digital identity checks legally require a provider certified against the framework and listed on the OfDIA register. For general KYC/onboarding, certification is a strong trust signal but not always a legal requirement — it depends on your regulator and use case.