Digital identity providers are facing a more formal test of compliance as the OpenID Foundation opens conformance testing and self-certification for its digital credential protocols. The move gives organisations a way to assess implementations directly against the relevant specifications, rather than relying primarily on whether their systems work with individual counterparties.
The development is particularly relevant to companies building infrastructure for European Digital Identity Wallets (EUDI Wallets). Analysis from Hopae, which provides EUDI Wallet verification infrastructure across several EU Member States, points to the importance of conformance testing as eIDAS 2.0 moves towards implementation. The new testing framework could give providers a clearer way to identify interoperability and compliance issues before systems are deployed at scale.
The protocols covered by the testing framework are part of the OpenID4VC family, developed by the OpenID Foundation’s Digital Credentials Protocols Working Group. OpenID4VCI governs how digital credentials are issued to wallets through an OAuth 2.0-based API, while OpenID4VP covers how wallets present credentials to verifiers.
The High Assurance Interoperability Profile (HAIP) sits across both standards. Rather than introducing another protocol, it narrows the implementation choices available within OpenID4VCI and OpenID4VP. It also works alongside credential formats including IETF SD-JWT VC and ISO mdoc to establish a more consistent technical baseline for high-assurance applications.
The timing of the standards is significant. OpenID4VP 1.0 reached Final status on 9 July 2025, followed by OpenID4VCI 1.0 on 16 September 2025 and HAIP 1.0 on 24 December 2025. Standards generally need to reach Final status before regulators can directly reference them in legislation, making these milestones important as digital identity frameworks develop.
One of the main issues is that technical compliance does not automatically result in interoperability. OpenID4VCI and OpenID4VP allow developers to select from different credential formats, signature algorithms, wallet invocation methods and client authentication approaches. While individual choices can comply with the underlying standards, incompatible combinations can still prevent two systems from communicating effectively.
HAIP addresses this by reducing the number of technical choices available for high-assurance deployments. It specifies the use of SD-JWT VC or ISO mdoc credentials, ES256 signatures and SHA-256 digests, while requiring X.509 certificate-based issuer key resolution and excluding self-signed certificates.
For credential issuance, HAIP requires the Authorisation Code Flow, FAPI 2.0 Security Profile compliance, DPoP for sender-constrained tokens and wallet attestation. For credential presentation, it requires DCQL queries, response encryption using ephemeral keys and the x509_hash Client Identifier Prefix for signed requests.
HAIP also has defined limits. The profile does not cover every requirement for eIDAS Level of Assurance High, while trust management and certain extension points remain for individual digital identity ecosystems to determine. It therefore provides a common technical baseline rather than a complete framework for interoperability.
Previously, interoperability was often assessed by connecting two implementations and checking whether they worked together. While this approach can identify compatibility problems, it can also result in two systems appearing interoperable because they share the same interpretation of a specification. Pairwise testing also becomes increasingly difficult as more providers enter the ecosystem.
The OpenID Foundation’s conformance suites instead test implementations against the specifications themselves. They include negative tests designed to check whether systems correctly reject invalid requests. This is particularly relevant for verifiers, where accepting an invalid or malformed request could introduce security risks.
Hopae’s analysis also points to the shift towards specification-based testing. The company participated in a November 2025 interoperability event focused on HAIP 1.0 before the profile reached Final status. Findings from the event were shared with the Digital Credentials Protocols Working Group and contributed to the development of the test suites.
OpenID4VP 1.0 with HAIP 1.0 subsequently achieved a 98% pass rate. The result provides an indication of how conformance testing can give providers a more consistent way to assess implementations before relying on individual integrations.
Self-certification is now available across the relevant OpenID protocols. Under OpenID4VP, organisations can certify implementations as wallets or verifiers, while OpenID4VCI allows certification as issuers or wallet providers. Wallets can also certify against the W3C Browser API appendix of OpenID4VP, with the conformance tests available free of charge.
Hopae’s analysis ultimately highlights a broader change for digital identity providers: interoperability is moving from something organisations demonstrate through individual connections to something they can test against a defined technical benchmark. As EUDI Wallet infrastructure develops, that distinction could become increasingly important for providers seeking to demonstrate compliance, identify weaknesses and operate across multiple ecosystems.
Copyright © 2026 RegTech Analyst
Copyright © 2026 RegTech Analyst





