The OpenID Foundation has completed conformance test suites for OpenID4VP and OpenID4VCI under the HAIP for self-certification.
The test suites are now open for self-certification, giving governments, wallet providers, issuers, verifiers, and technology vendors a mechanism to formally demonstrate that their implementations conform to the specifications.
OpenID4VP and OpenID4VCI are specifications for digital identity wallets that have been adopted by more than 30 jurisdictions, including the UK, Switzerland, India, and the EU member states through the EU Digital Identity Wallet programme. Until the conformance programme was completed, organisations could implement the specifications but had no independent, publicly recognised way to verify that their systems met the security requirements or would interoperate with other implementations.
The OpenID4VC family of specifications supports the issuance and presentation of digital credentials in a way that limits the amount of personal data disclosed. An individual proving they are over eighteen, for example, can do so without revealing their date of birth or address. Credentials are signed by the issuing organisation, and issuers do not retain visibility into how or where their credentials are later used.
Conformance testing and self-certification process
The conformance tests allow organisations to check whether their implementations meet the specifications, producing reports that identify which requirements have been satisfied and where further work is needed. Testing can be run free of charge on infrastructure hosted by the OpenID Foundation or on an organisation's own systems. Once testing is complete, organisations can apply for self-certification; following review, the Foundation will publish the results publicly.
In addition, self-certification is available across the implementation roles defined in each specification. Under OpenID4VP, organisations can certify as a wallet or as a verifier/relying party. Under OpenID4VCI, certification is available for issuers and wallet providers, with separate test profiles for each role.
Both test suites underwent multiple rounds of real-world interoperability testing, achieving pass rates of more than 90% for OpenID4VP and 87% for OpenID4VCI, before the Digital Credentials Protocols Working Group confirmed the tests as ready in July 2026. Sixteen organisations took part in the interoperability testing programme, including Google, SpruceID, Fikua, Authlete, Meeco, and Turing Space.
Regulatory context and industry implications
The programme follows the certification model previously established for OpenID Connect and the FAPI security profile, both of which are already used in digital identity and Open Banking ecosystems. In Brazil, certification against OpenID Foundation specifications began as a voluntary scheme before becoming a mandatory condition of participation in the country's Open Banking ecosystem.
The OpenID Foundation is in discussions with the EU Digital Identity Wallet ecosystem and other jurisdictions on how its open-source tests and conformance tools could support local ecosystem requirements. While self-certification is not yet mandatory across all ecosystems, the Foundation has indicated this direction is likely to continue. Organisations that self-certify early will be among the first listed publicly on the OpenID Foundation's website, a status that ecosystem partners and regulators may use as a reference point when assessing conformance.