Certifications and compliance

SOC 2 Type 2, ISO/IEC 27001 with cloud extensions, iBeta Level 1 PAD, a German youth-protection certification, a Spanish regulator attestation, and an EBA/MiCA legal opinion - with dates.

Short answer

SOC 2 Type 2 (issued 30 July 2026), ISO/IEC 27001:2022 (valid to 3 June 2027) with the 27017 and 27018 cloud extensions, iBeta Level 1 PAD, German FSM age-assurance certification, a Spanish financial-regulator attestation, and an independent EBA / MiCA legal opinion. Reports come from the Security & Compliance centre or your Didit contact; some are under NDA.

Didit's security and compliance posture is verified by independent auditors, accredited laboratories, and financial regulators - not self-declared.

#At a glance

CredentialFramework / issuerStatus
SOC 2 Type 2AICPA Trust Services CriteriaIssued 30 July 2026 (March–July 2026 observation period)
SOC 2 Type 1AICPA Trust Services CriteriaIssued 9 April 2026
ISO/IEC 27001:2022Accredited certification bodyValid through 3 June 2027
ISO/IEC 27017 & 27018Cloud security & cloud privacy extensionsActive
iBeta Level 1 PADISO/IEC 30107-3, NIST-accredited labPassed - zero successful attacks
FSM Jugendschutz geprüftFSM (Germany), Section 4(2) JMStVCertified 29 June 2026
Regulator attestation (Spain)Tesoro Público, Banco de España, SEPBLAC, CNMVConcluded July 2025
EBA / MiCA compatibilityIndependent legal opinionCurrent
GDPR (EU 2016/679)Data processor, Article 32 measuresCompliant

#What each one actually evidences

SOC 2 Type 2 is the one most security reviews want, because it tests whether controls operated effectively over a period - March to July 2026 - rather than whether they existed on the day of the audit. The report is available under NDA.

SOC 2 Type 1 is the point-in-time audit of control design that preceded the Type 2 observation period.

ISO/IEC 27001:2022 certifies the information security management system covering the verification platform end to end - design, development, and operation. 27017 adds cloud-specific controls and 27018 adds protections for personal data in cloud environments.

iBeta Level 1 PAD is lab-tested biometric anti-spoofing: 360 presentation attacks across six categories, none successful. See anti-spoofing testing and certification.

FSM Jugendschutz geprüft certifies that Didit's age verification reliably establishes a closed user group under Section 4(2) JMStV - Germany's youth-protection framework - so only verified adults reach age-restricted content.

The Spanish regulator attestation is the unusual one. After a supervised test running November 2024 to July 2025, Spain's Tesoro Público, Banco de España, SEPBLAC and CNMV concluded that Didit's NFC + liveness verification is at least as safe as an in-person ID check under anti-money-laundering rules. Didit is the only provider with that validation.

The EBA / MiCA opinion is an independent legal opinion that Didit's remote onboarding meets the EBA Remote Customer Onboarding Guidelines (EBA/GL/2022/15) and is compatible with the EU AML Single Rulebook and MiCA. Memo available on request.

GDPR - Didit operates as your processor with Article 32 measures: AES-256 at rest, TLS 1.3 in transit, EU-default residency, configurable retention, and erasure via API.

#Getting the reports

From the Security & Compliance centre, or from your Didit contact. The SOC 2 reports are available under NDA rather than publicly.

#What a certification does not tell you

Two limits worth being clear about, because both cause real problems when assumed away:

A certification is not a licence for your use case. The FSM certification evidences that the age-assurance method works; it does not establish that using it satisfies a US, UK, or Brazilian age-assurance rule. Whether a given method meets a given obligation in a given market is a legal question for your compliance team, and it depends on your sector and licences as much as on the technology.

A certification does not make your configuration strong. The credentials above describe the platform. Your exposure is determined by the workflow you built - which liveness method, which thresholds, whether NFC is required, whether risk signals route to review. See decision rules and thresholds.

#If you need something that isn't listed

Ask. New certifications are added over time, and your Didit contact can tell you what exists today and what's on the roadmap - which is a better basis for a compliance decision than an inference from this page. Book a demo or contact your account manager with the specific framework your team needs.

Important

Don't design a compliance process around a credential you haven't seen. If your regulator will ask you to evidence a claim, get the underlying report or written confirmation first - a vendor page, including this one, is not evidence.