LIVE · UK MARKET INDEXED
NEWNHS Mersey · Compliance audit Q2 2026·£85k·Manchester
GRANTInnovate UK · SME R&D·£250k·UK-wide
NEWTfL · Cybersecurity SOC·£1.2M·London
INVMercia · Series A · ClimateTech·£3M·Birmingham
CORPBarclays · Diverse supplier programme·Invite·Nationwide
NEWCardiff CC · Schools refurbishment·£420k·Wales
GRANTHorizon EU · Energy transition·€800k·EU
NEWManchester CC · Social housing fire doors·£240k·Manchester
CORPKPMG · Digital procurement partner·£600k·UK
INVNorthwest Growth · Seed fund·£500k·NW England
NEWFind a Tender · Rail signalling·£3.6M·Frankfurt
NEWGovTech Singapore · Public services·SGD 1.1M·Singapore
NEWNHS Mersey · Compliance audit Q2 2026·£85k·Manchester
GRANTInnovate UK · SME R&D·£250k·UK-wide
NEWTfL · Cybersecurity SOC·£1.2M·London
INVMercia · Series A · ClimateTech·£3M·Birmingham
CORPBarclays · Diverse supplier programme·Invite·Nationwide
NEWCardiff CC · Schools refurbishment·£420k·Wales
GRANTHorizon EU · Energy transition·€800k·EU
NEWManchester CC · Social housing fire doors·£240k·Manchester
CORPKPMG · Digital procurement partner·£600k·UK
INVNorthwest Growth · Seed fund·£500k·NW England
NEWFind a Tender · Rail signalling·£3.6M·Frankfurt
NEWGovTech Singapore · Public services·SGD 1.1M·Singapore
GUIDANCE · UPDATED 14 JULY 2026

The UK's statutory digital identity trust framework has gone live with 46 certified providers on the public register, and small businesses offering or relying on digital verification services need to understand the new certification, trust mark and information-sharing rules now taking shape.

Office for Digital Identities and Attributes 2026 Annual Report · first published 14 July 2026

What it says, in plain English

The Office for Digital Identities and Attributes (OfDIA) has published its first annual report under the Data (Use and Access) Act 2025, covering the UK's statutory regime for Digital Verification Services (DVS) — services that let people prove things about themselves online (e.g. right to work, age, identity). As of July 2026, 46 providers offering 64 certified services are listed on the public DVS register; they were independently checked against the UK DVS trust framework by accredited Conformity Assessment Bodies (CABs). Version 1.0 of the trust framework was published on 9 June 2026 and comes into force on 1 September 2026 — it introduces the first rules for new service types (orchestration/hub services and holder/wallet services) and unlocks the 'UK CertifID' trust mark for certified and registered providers. An information-sharing power (allowing public authorities to share data about individuals with registered DVS providers) is being prepared for launch once Parliament approves the Code of Practice, expected by end of 2026. No fees are currently charged for joining the DVS register, and OfDIA does not plan to introduce them in the next reporting period. The sector generated an estimated £2.027 billion in revenue in 2024/25, employing over 9,600 people, indicating a growing commercial opportunity for SMEs operating in or buying from this space.

WHO THIS APPLIES TO

Who it binds
All public-sector buyers
Contract values
any value
Applies from
1 September 2026
Sectors
Primarily digital identity/verification providers and any business relying on digital checks for right to work, right to rent, DBS, age verification, anti-money-laundering, or financial services customer due diligence.

THE ENKII VIEW

For SMEs that provide digital identity or verification services, certification against version 1.0 of the DVS trust framework — and the resulting 'UK CertifID' trust mark — is becoming a de facto market-access requirement as regulated use cases (right to work, right to rent, DBS, alcohol age verification) mandate registered DVS. The planned machine-readable DVS register and information-sharing gateway will make being on the register a contractual and regulatory gate in an expanding set of sectors, so early certification gives smaller providers a first-mover advantage before the market consolidates further. SMEs that rely on digital identity checks (e.g. in financial services, letting, or age-restricted retail) should begin tracking which of their incumbent providers hold or are pursuing 1.0 certification, because uncertified providers will lose register status and — increasingly — regulatory acceptability.

What a small business should do about it

1. Begin the process of certifying your services against version 1.0 of the DVS trust framework (in force 1 September 2026) with an accredited CAB — this unlocks the 'UK CertifID' trust mark and keeps you eligible for regulated use cases (right to work, right to rent, DBS, alcohol age verification).

SMEs providing digital identity or verification servicesVersion 1.0 comes into effect on 1 September 2026 and only providers certified against it can use the trust mark. Providers who remain on older certifications risk losing register status as their certificates expire, as happened to five providers on 1 April 2026.

2. Review the new dedicated rules for orchestration and holder services in version 1.0 of the DVS trust framework and assess whether your service architecture meets them before seeking CAB certification.

SMEs providing orchestration (hub) or holder (wallet) digital identity servicesVersion 1.0 introduces 'the first dedicated rules for orchestration services… and new rules for holder services' — there was no prior certified pathway for these service types, so this is a new market-entry opportunity.

3. Monitor OfDIA's GitHub publication of the working draft of the next DVS trust framework version and submit proposed changes to influence rules before they are finalised.

SMEs providing digital identity services seeking to growOfDIA is 'planning to publish a working draft of the DVS trust framework and its supporting documents on GitHub before finalising their next version' — this is a formal route to shape standards that will govern your market.

4. Track OfDIA's consultation on a potential supplementary code for digital age verification and engage early, especially if you serve age-restricted sectors (alcohol, gambling, social media).

SMEs providing digital identity or age-verification servicesOfDIA is 'considering whether such rules would be best contained in a dedicated supplementary code for digital age verification' — early engagement shapes the rules and positions your service for the new use cases when they launch.

5. Ensure your complaints records are maintained and your annual inclusion monitoring report is submitted to OfDIA on time, covering accessibility features, demographic data collection, and non-digital support routes.

All SMEs certified under the DVS trust frameworkDVS providers are required to 'maintain appropriate records of complaints… and make this information available to OfDIA on request' and to 'submit an inclusion monitoring report at least annually' — failure to comply is a grounds for removal from the register.

6. Before applying, audit your ownership structure, directors' records, and marketing materials to ensure there are no national security concerns, outstanding legal proceedings, or convictions for corruption, bribery or money laundering — and that your promotional claims are accurate.

SMEs applying to join the DVS registerOfDIA performs checks including 'checking a provider's ownership chain for national security risks… prior convictions for corruption, bribery or money laundering, and directors' checks' and reviews marketing materials for misleading claims — issues here can lead to refusal or removal.

7. Verify that your current DVS provider is listed on the DVS register and is pursuing version 1.0 certification — and build a contingency if they are not, given that uncertified providers lose register status automatically when their certificate expires.

SMEs that rely on DVS providers for regulated checks (e.g. right to work, right to rent, DBS, AML due diligence)Services are 'automatically removed from the register if their certificate expires', as evidenced by five providers removed on 1 April 2026 — relying on an unregistered provider could invalidate your regulatory compliance.

8. Read OfDIA's published blog on the section 45 information-sharing power and engage with OfDIA's readiness activities so you are operationally prepared when Parliament approves the Code of Practice (expected by end of 2026).

SMEs providing DVS who want to access government-held data under the new information-sharing powerSection 45 'will be commenced once the Code has been approved' — registered DVS providers will then be able to request government-held data on individuals, but only if they are already on the register and have processes in place.

The rules, anchored to the text

Every rule below quotes the official document verbatim.

The DVS trust framework version 1.0 was published on 9 June 2026 and comes into effect on 1 September 2026, subject to successful accreditation of conformity assessment bodies by UKAS. (All DVS providers seeking certification against the UK DVS trust framework.)

Version 1.0 will come into effect on 1 September 2026, subject to successful accreditation of conformity assessment bodies by the UK Accreditation Service (UKAS).

As of July 2026, the DVS register lists 46 providers offering 64 certified services across identity, attribute, orchestration, holder and component service roles. (DVS providers registered on the UK DVS register.)

As of July 2026, the DVS register lists 46 providers offering 64 certified services across identity, attribute, orchestration, holder and component service roles.

To be listed on the DVS register, providers must be certified against the trust framework by an accredited CAB, submit a compliant application to OfDIA, pass public interest checks, and pay any applicable fee (currently nil). (All DVS providers wishing to join the DVS register.)

To be listed on the DVS register, providers must be certified against the trust framework by an accredited CAB and have made an application to OfDIA to join the register which complies with the determination made under section 38.

Providers certified and registered against version 1.0 of the DVS trust framework will, for the first time, be able to use the 'UK CertifID' trust mark under licence. (DVS providers certified against version 1.0 (in force from 1 September 2026) and listed on the DVS register.)

Providers certified and registered against the 1.0 version will, for the first time, be able to use the 'UK CertifID' trust mark.

To be certified against a supplementary code (right to work, right to rent, DBS), a service must also be certified against the corresponding version of the DVS trust framework. (DVS providers seeking supplementary code certification for right to work, right to rent, or DBS checks.)

To be certified against a supplementary code, a service must also be certified against the corresponding version of the DVS trust framework.

OfDIA does not currently charge fees for joining or remaining on the DVS register and does not plan to introduce fees in the next reporting period. (All DVS providers applying to or listed on the DVS register.)

During this reporting period, OfDIA has not implemented fee regulations and did not charge fees to providers… At this stage, OfDIA does not plan to introduce fees for joining or remaining on the DVS register.

The information-sharing power under section 45 of the Act (allowing public authorities to share individual data with registered DVS providers on request) is planned to be commenced once the Code of Practice has been approved by Parliament, with the Code aimed to be published by end of 2026. (All UK public authorities (excluding initially HMRC, Revenue Scotland and the Welsh Revenue Authority) and registered DVS providers.)

OfDIA plans to finalise the draft Code and lay it before Parliament for approval, with the aim of it being published by the end of 2026. Once the Code has been approved, section 45 will be commenced.

The information-sharing power under section 45 will NOT initially apply to HMRC, Revenue Scotland, or the Welsh Revenue Authority. (Registered DVS providers and public authorities using the section 45 information-sharing power.)

All UK public authorities are in scope, but as outlined above, the power will not initially be in force with regards to HMRC, Revenue Scotland and the Welsh Revenue Authority.

All certified DVS providers are required to submit an inclusion monitoring report at least annually. (All DVS providers certified under the DVS trust framework.)

all DVS providers are required to submit an inclusion monitoring report at least annually.

DVS providers are required to maintain appropriate records of complaints and make this information available to OfDIA on request. (All DVS providers certified under the DVS trust framework.)

DVS providers are required to maintain appropriate records of complaints in accordance with their information management policies and to make this information available to OfDIA on request.

OfDIA performs public interest checks on all registered providers including ownership chain (national security), outstanding proceedings, prior convictions for corruption/bribery/money laundering, directors' checks, and marketing materials. (All providers applying to or listed on the DVS register.)

The type of checks OfDIA performs include, but are not limited to, checking a provider's ownership chain for national security risks, whether they are involved in any outstanding proceedings such as patent disputes, have any prior convictions for corruption, bribery or money laundering, and directors' checks.

The digital identity sector in the UK comprises 275 firms generating an estimated £2.027 billion in annual revenue (2024/25) and employing approximately 9,624 full-time equivalents. (UK digital identity sector (market context).)

275 firms are currently providing digital identity related products and services in the UK. The sector generated an estimated £2,027 million in annual revenue in 2024/2025.

A machine-readable layer of the DVS register enabling programmatic checking is in development with a planned launch date of Winter 2026. (Registered DVS providers, relying parties and public authorities using the DVS register.)

This service is in development with a planned launch date of Winter 2026.

Version 1.0 of the DVS trust framework includes the first dedicated rules for orchestration services (hub services) and new rules for holder services (e.g. digital wallets). (DVS providers operating orchestration or holder (wallet) services seeking certification under version 1.0.)

The 1.0 version of the trust framework also includes the first dedicated rules for orchestration services, such as 'hub' services that allow relying parties to work with others, and new rules for holder services.

OfDIA is exploring a dedicated supplementary code for digital age verification to enable use of registered DVS for alcohol purchases and other age-restricted products. (DVS providers offering age-verification services; retailers and others in age-restricted sectors.)

OfDIA is exploring whether to publish new rules on trustworthy digital age verification checks. OfDIA is considering whether such rules would be best contained in a dedicated supplementary code for digital age verification.

OfDIA plans to publish a working draft of the next version of the DVS trust framework on GitHub to allow stakeholders to propose specific changes before finalisation. (All DVS providers and stakeholders wishing to influence future versions of the trust framework.)

it is planning to publish a working draft of the DVS trust framework and its supporting documents on GitHub before finalising their next version. This will enable stakeholders to propose specific changes to the content of the trust framework.

This briefing is enkii's interpretation of the official document — the official text always governs.

Official document on GOV.UK

Source document © Crown copyright, reused under the Open Government Licence v3.0 via the GOV.UK Content API. enkii tracks every Procurement Policy Note and briefs changes the day they land — see all briefings.