Anti-spoofing testing and certification

Didit's liveness detection was tested by a NIST-accredited lab under ISO/IEC 30107-3 with 360 presentation attacks across six categories, and Spanish financial regulators judged NFC plus liveness at least as safe as an in-person check.

Short answer

Didit holds iBeta Level 1 PAD certification under ISO/IEC 30107-3 from a NIST-accredited laboratory: 360 presentation attacks across six categories, zero successful. Separately, Spanish financial regulators concluded after a year-long supervised test that Didit's NFC + liveness verification is at least as safe as an in-person ID check.

#What was tested

Presentation attack detection (PAD) testing under ISO/IEC 30107-3 is the standard way liveness claims are checked by someone other than the vendor. A NIST-accredited laboratory ran 360 presentation attacks against Didit's liveness detection across six attack categories - printed photographs, screen replays, masks, and others.

None succeeded. That's the basis of the iBeta Level 1 PAD certification.

#Level 1 and Level 2

These two levels test different threat models, and the distinction matters if your compliance team is asking:

What it covers
Level 1Presentation attacks: artefacts held up to the camera - photos, screens, printed masks
Level 2More sophisticated artefacts, including higher-quality custom-made masks

Didit holds Level 1. If your requirement specifies Level 2, or specifically asks about injection and deepfake resistance, raise it with your Didit contact rather than inferring an answer - certification scope is a factual matter and shouldn't be guessed at from a help page.

#The Spanish regulator validation

Between November 2024 and July 2025, Spain's Tesoro Público, Banco de España, SEPBLAC and CNMV ran a supervised test of Didit's NFC + liveness verification. Their conclusion: it is at least as safe as an in-person ID check under anti-money-laundering rules.

That's a distinct kind of evidence from a lab certification. A lab tests the biometric component against attacks; a financial regulator assessed the whole remote-onboarding method against the in-person baseline their own rules are written around. Didit is the only provider with that validation.

#Age assurance certification

For age-restricted content specifically, Germany's youth-protection self-regulator FSM certified in June 2026 that Didit's age verification reliably establishes a closed user group under Section 4(2) JMStV - so only verified adults reach age-restricted material.

If your obligation is age assurance in another jurisdiction, that FSM certification is evidence of capability but not a licence for that market. Age-assurance rules differ substantially between the US, UK, EU and Brazil, and whether a given method satisfies a given rule is a legal question for your compliance team.

#Getting the reports

Certificates and reports are available from the Security & Compliance centre, or from your Didit contact. Some are available under NDA rather than publicly - the SOC 2 reports in particular.

Note

If your compliance review needs a specific framework or attestation that isn't listed, ask. Certification coverage expands over time, and your Didit contact can tell you what exists today and what's on the roadmap - which is a better answer than an inference from a help article.

#What certification does not do

Certification tells you a system resisted a defined set of attacks in a lab. It does not tell you your configuration is strong. A workflow running passive liveness with a very loose face match threshold and no device signals is weaker than the certification implies, because you've widened the gap the attacker has to cross.

The controls that actually determine your exposure are the ones you set: which liveness method, which thresholds, whether NFC is required, and whether risk signals route to review. See decision rules and thresholds.

#The rest of the compliance picture

Liveness certification is one credential among several - SOC 2 Type 2, ISO/IEC 27001, ISO/IEC 27017 and 27018, GDPR processor commitments, and the EBA / MiCA legal opinion. See certifications and compliance.