Certifications and compliance
SOC 2 Type 2, ISO/IEC 27001 with cloud extensions, iBeta Level 1 PAD, a German youth-protection certification, a Spanish regulator attestation, and an EBA/MiCA legal opinion - with dates.
SOC 2 Type 2 (issued 30 July 2026), ISO/IEC 27001:2022 (valid to 3 June 2027) with the 27017 and 27018 cloud extensions, iBeta Level 1 PAD, German FSM age-assurance certification, a Spanish financial-regulator attestation, and an independent EBA / MiCA legal opinion. Reports come from the Security & Compliance centre or your Didit contact; some are under NDA.
Didit's security and compliance posture is verified by independent auditors, accredited laboratories, and financial regulators - not self-declared.
#At a glance
| Credential | Framework / issuer | Status |
|---|---|---|
| SOC 2 Type 2 | AICPA Trust Services Criteria | Issued 30 July 2026 (March–July 2026 observation period) |
| SOC 2 Type 1 | AICPA Trust Services Criteria | Issued 9 April 2026 |
| ISO/IEC 27001:2022 | Accredited certification body | Valid through 3 June 2027 |
| ISO/IEC 27017 & 27018 | Cloud security & cloud privacy extensions | Active |
| iBeta Level 1 PAD | ISO/IEC 30107-3, NIST-accredited lab | Passed - zero successful attacks |
| FSM Jugendschutz geprüft | FSM (Germany), Section 4(2) JMStV | Certified 29 June 2026 |
| Regulator attestation (Spain) | Tesoro Público, Banco de España, SEPBLAC, CNMV | Concluded July 2025 |
| EBA / MiCA compatibility | Independent legal opinion | Current |
| GDPR (EU 2016/679) | Data processor, Article 32 measures | Compliant |
#What each one actually evidences
SOC 2 Type 2 is the one most security reviews want, because it tests whether controls operated effectively over a period - March to July 2026 - rather than whether they existed on the day of the audit. The report is available under NDA.
SOC 2 Type 1 is the point-in-time audit of control design that preceded the Type 2 observation period.
ISO/IEC 27001:2022 certifies the information security management system covering the verification platform end to end - design, development, and operation. 27017 adds cloud-specific controls and 27018 adds protections for personal data in cloud environments.
iBeta Level 1 PAD is lab-tested biometric anti-spoofing: 360 presentation attacks across six categories, none successful. See anti-spoofing testing and certification.
FSM Jugendschutz geprüft certifies that Didit's age verification reliably establishes a closed user group under Section 4(2) JMStV - Germany's youth-protection framework - so only verified adults reach age-restricted content.
The Spanish regulator attestation is the unusual one. After a supervised test running November 2024 to July 2025, Spain's Tesoro Público, Banco de España, SEPBLAC and CNMV concluded that Didit's NFC + liveness verification is at least as safe as an in-person ID check under anti-money-laundering rules. Didit is the only provider with that validation.
The EBA / MiCA opinion is an independent legal opinion that Didit's remote onboarding meets the EBA Remote Customer Onboarding Guidelines (EBA/GL/2022/15) and is compatible with the EU AML Single Rulebook and MiCA. Memo available on request.
GDPR - Didit operates as your processor with Article 32 measures: AES-256 at rest, TLS 1.3 in transit, EU-default residency, configurable retention, and erasure via API.
#Getting the reports
From the Security & Compliance centre, or from your Didit contact. The SOC 2 reports are available under NDA rather than publicly.
#What a certification does not tell you
Two limits worth being clear about, because both cause real problems when assumed away:
A certification is not a licence for your use case. The FSM certification evidences that the age-assurance method works; it does not establish that using it satisfies a US, UK, or Brazilian age-assurance rule. Whether a given method meets a given obligation in a given market is a legal question for your compliance team, and it depends on your sector and licences as much as on the technology.
A certification does not make your configuration strong. The credentials above describe the platform. Your exposure is determined by the workflow you built - which liveness method, which thresholds, whether NFC is required, whether risk signals route to review. See decision rules and thresholds.
#If you need something that isn't listed
Ask. New certifications are added over time, and your Didit contact can tell you what exists today and what's on the roadmap - which is a better basis for a compliance decision than an inference from this page. Book a demo or contact your account manager with the specific framework your team needs.
Don't design a compliance process around a credential you haven't seen. If your regulator will ask you to evidence a claim, get the underlying report or written confirmation first - a vendor page, including this one, is not evidence.