Signicat has been certified against the UK Digital Identity and Attributes Trust Framework (DIATF) for the NFC-based identity document verification components and orchestration services behind its ReadID product. The certificate runs from 29 June 2026 to 29 June 2029, and it clears the way for certified UK providers to build chip-reading identity checks into Right to Work, Right to Rent and Disclosure and Barring Service (DBS) processes.
The certification followed an independent audit by the Kantara Initiative, one of the conformity assessment bodies that carry out DIATF audits. The Office for Digital Identities and Attributes (OfDIA) oversees the framework itself rather than performing the audits. What Signicat has certified is a component rather than a finished consumer service: the Norwegian identity firm is offering its technology and orchestration to third party services that are themselves certified for those use cases.
What the chip is actually doing
ReadID reads the contactless chip embedded in e-passports, biometric residence permits and national ID cards. That chip is a proximity card under ISO/IEC 14443, operating at 13.56 MHz in the HF band, and it is the same air interface an NFC-capable smartphone uses when it acts as a reader. No dedicated hardware is needed at the point of check, which is what made phone-based chip reading practical for remote onboarding.
The data on the chip is structured per ICAO Doc 9303, which organises it into logical data groups. DG1 holds the machine readable zone data (name, document number, nationality, dates), DG2 holds the facial image, and further groups hold optional biometrics and issuer information. Hashes of those groups sit in the Document Security Object, signed by the issuing country’s document signer certificate, which chains back to that country’s certification authority. A verifier can therefore establish two things: that the data has not been altered since issue, and that it came from the state it claims to.
Getting at that data is deliberately awkward for anyone who does not have the document in hand. Access is gated by Basic Access Control or, on newer documents, the stronger PACE protocol, with session keys derived from the printed machine readable zone. Reading the chip therefore requires optical access to the document as well as radio access to it. Chip authenticity is a separate question, answered by Active Authentication or Chip Authentication, in which the chip proves it holds a private key that cannot be extracted. That is what distinguishes a genuine chip from a cloned copy of its contents written to a blank.
Why chip beats page
Conventional identity checks read the printed page, by eye or by OCR of a photograph, then judge whether the security printing looks right. Both are attackable at the point of capture. A printed page can be altered, a photograph of one can be edited, and an injected camera stream can present a document that never physically existed. Cryptographic verification of the chip is indifferent to how convincing a forgery looks, because any change to a data group breaks the signature covering it.
Signicat says the certified technology pairs the document check with facial verification, matching a live capture against the image held on the chip to confirm that the person presenting the document is its legitimate holder and is present at the time of the check.
The UK backdrop
Signicat positions the timing as significant. Its announcement points to government statements ending the Digital Identity scheme, which in the company’s reading leaves the trust framework, under OfDIA’s guidance, as the main route to wider digital ID adoption in the UK. Certification against the DIATF becomes correspondingly more important for suppliers serving regulated checks.
“Organisations and individuals spend an exorbitant amount of time and money trying to keep up with fragmented identity regulations across Europe and the UK,” said Ray Ryan, UK country manager at Signicat. “The DIATF certification alongside our other certifications ensures regulated sectors have a unified, independently certified secure method to onboard staff and customers instantly, without leaving the door open to sophisticated fraud.”
This is a compliance milestone rather than a new deployment. ReadID is an established commercial product, and Signicat says the technology and orchestration covered by the certification is already handling millions of transactions per month for public and private institutions. What changes is the component’s standing in the UK: providers assembling a certified Right to Work, Right to Rent or DBS service can now fold in an audited NFC document verification layer without proving it out themselves.
Read more at https://www.signicat.com/press-releases/signicat-secures-key-uk-digital-identity-trust-certification

