Certifications and compliance
SOC 2 Type 2, ISO/IEC 27001 with cloud extensions, iBeta Level 1 PAD, a German youth-protection certification, a Spanish regulator attestation, and an EBA/MiCA legal opinion - with dates.
SOC 2 Type 2 (issued 30 July 2026), ISO/IEC 27001:2022 (valid to 3 June 2027) with the 27017 and 27018 cloud extensions, iBeta Level 1 PAD, German FSM age-assurance certification, a Spanish financial-regulator attestation, and an independent EBA / MiCA legal opinion. Reports come from the Security & Compliance centre or your Didit contact; some are under NDA.
Didit's security and compliance posture is verified by independent auditors, accredited laboratories, and financial regulators - not self-declared.
#At a glance
| Credential | Framework / issuer | Status |
|---|---|---|
| SOC 2 Type 2 | AICPA Trust Services Criteria | Issued 30 July 2026 (March–July 2026 observation period) |
| SOC 2 Type 1 | AICPA Trust Services Criteria | Issued 9 April 2026 |
| ISO/IEC 27001:2022 | Bureau Veritas, certificate ES144068 | Valid through 3 June 2027 |
| ISO/IEC 27017 & 27018 | Cloud security & cloud privacy extensions | Active |
| iBeta Level 1 PAD | ISO/IEC 30107-3, NIST-accredited lab | Passed - zero successful attacks |
| FSM Jugendschutz geprüft | FSM (Germany), Section 4(2) JMStV | Certified 29 June 2026 |
| Regulator attestation (Spain) | Tesoro Público, Banco de España, SEPBLAC, CNMV | Concluded July 2025 |
| EBA / MiCA compatibility | Independent legal opinion | Current |
| GDPR (EU 2016/679) | Data processor, Article 32 measures | Compliant |
| Swiss FADP | Federal Act on Data Protection | Compliant |
| DORA | EU Digital Operational Resilience Act | Aligned on every plan, including pay-as-you-go |
#What each one actually evidences
SOC 2 Type 2 is the one most security reviews want, because it tests whether controls operated effectively over a period - March to July 2026 - rather than whether they existed on the day of the audit. The report is available under NDA.
SOC 2 Type 1 is the point-in-time audit of control design that preceded the Type 2 observation period.
ISO/IEC 27001:2022 certifies the information security management system covering the verification platform end to end - design, development, and operation. 27017 adds cloud-specific controls and 27018 adds protections for personal data in cloud environments.
iBeta Level 1 PAD is lab-tested biometric anti-spoofing: 360 presentation attacks across six categories, none successful. See anti-spoofing testing and certification.
FSM Jugendschutz geprüft certifies that Didit's age verification reliably establishes a closed user group under Section 4(2) JMStV - Germany's youth-protection framework - so only verified adults reach age-restricted content.
The Spanish regulator attestation is the unusual one. After a supervised test running November 2024 to July 2025, Spain's Tesoro Público, Banco de España, SEPBLAC and CNMV concluded that Didit's NFC + liveness verification is at least as safe as an in-person ID check under anti-money-laundering rules. Didit is the only provider with that validation.
The EBA / MiCA opinion is an independent legal opinion that Didit's remote onboarding meets the EBA Remote Customer Onboarding Guidelines (EBA/GL/2022/15) and is compatible with the EU AML Single Rulebook and MiCA. Memo available on request.
GDPR - Didit operates as your processor with Article 32 measures: AES-256 at rest, TLS 1.3 in transit, EU-default residency, configurable retention, and erasure via API. The same posture covers the Swiss FADP, and the platform is DORA-aligned for financial-sector customers on every plan tier.
#Which company you are contracting with
Procurement forms ask for it, so here it is plainly. The contracting entity for customers in the EU, EEA, Switzerland and Latin America is Didit Identity Spain, S.L., the Spanish operating company. Its parent is a US (Delaware) entity, which is the one that signs for US customers. When support asks "Spain or US?" before sending an NDA or an agreement, that is the choice being made; if you are unsure, say where your company is incorporated and they will pick the right one.
#Getting the reports
From the Security & Compliance centre, or from your Didit contact. The ISO/IEC 27001 certificate, the iBeta report and the technical and organisational measures (TOMs) can be shared directly on request. The SOC 2 reports and the penetration test report are available under NDA rather than publicly - to request one, have three things ready, because support will ask for exactly these before sending the signature link:
- Your company's legal name
- The email of the person signing the NDA
- Which Didit entity should sign: Spain or US
With those, support sends a standardized NDA for e-signature and the report follows once it's signed.
#What a certification does not tell you
Two limits worth being clear about, because both cause real problems when assumed away:
A certification is not a licence for your use case. The FSM certification evidences that the age-assurance method works; it does not establish that using it satisfies a US, UK, or Brazilian age-assurance rule. Whether a given method meets a given obligation in a given market is a legal question for your compliance team, and it depends on your sector and licences as much as on the technology.
A certification does not make your configuration strong. The credentials above describe the platform. Your exposure is determined by the workflow you built - which liveness method, which thresholds, whether NFC is required, whether risk signals route to review. See decision rules and thresholds.
#If you need something that isn't listed
Ask. New certifications are added over time, and your Didit contact can tell you what exists today and what's on the roadmap - which is a better basis for a compliance decision than an inference from this page. Book a demo or contact your account manager with the specific framework your team needs.
Don't design a compliance process around a credential you haven't seen. If your regulator will ask you to evidence a claim, get the underlying report or written confirmation first - a vendor page, including this one, is not evidence.