W3C publishes Verifiable Credentials Data Model 2.0 as a Recommendation
VC Data Model 2.0 reached W3C Recommendation on 15 May 2025, moving verifiable credentials from a promising draft to a standard the W3C recommends for wide deployment. It admits several securing mechanisms rather than mandating one.
The W3C published the Verifiable Credentials Data Model 2.0 as a Recommendation on 15 May 2025, the stage at which the W3C recommends wide deployment of a specification as a web standard. Version 1.1 had been a Recommendation since 2022, so this is a revision rather than a first arrival.
The substantive shift is that 2.0 does not mandate a single way to secure a credential. It accommodates Data Integrity proofs, JOSE and COSE, and SD-JWT, which matters because those communities had been solving the same problem incompatibly. Selective disclosure and privacy considerations are treated more prominently than in 1.1.
Why it matters
A Recommendation is the point at which procurement and regulation can safely reference a spec, and that is the practical unlock. The EU Digital Identity Wallet work under eIDAS 2 depends on a stable credential format, and member-state implementations were waiting on exactly this.
The caution worth carrying: multiple securing mechanisms means "supports verifiable credentials" is not a specification. Two conforming implementations can still fail to interoperate if one issues SD-JWT and the other expects Data Integrity proofs. When you evaluate a wallet or issuer, ask which securing mechanism and which DID methods it supports, not whether it is standards-compliant. Our implementation guide covers where those choices bite.
Related on Start with Identity
- BlogA loose PHP comparison let attackers sign in as WordPress admin through SAML
Two unauthenticated bypasses in the miniOrange SAML 2.0 Single Sign On plugin, CVE-2026-61979 and CVE-2026-15981, treat OpenSSL's error return as a valid signat
- BlogEMVCo drafts one credential standard so merchants stop building per-wallet integrations
EMVCo published a draft framework for verifiable digital credentials in card-based payments, aimed at giving merchants one consistent data structure to authenti
- BlogGoogle and Mastercard's answer to "can I trust an AI agent to pay for this" is a cryptographic mandate
Google's Agent Payments Protocol and Mastercard's Verifiable Intent framework, both contributed to the FIDO Alliance for standardization, define how an AI agent
- StandardOpenID for Verifiable Credentials (OpenID4VC)
OpenID4VC is the OpenID Foundation family that issues and presents verifiable credentials over OAuth 2.0. It is the transport layer turning decentralized identi
- GuideReusable Identity and KYC with Verifiable Credentials
The clearest enterprise ROI for decentralized identity is reusable KYC: verify a person once, issue a credential, and let them reuse it. How it works, what it s
- ArticleVerifiable Credentials Use Cases: Where They Actually Pay Off in 2026
The verifiable credential use cases that deliver real value in 2026: reusable KYC, government wallets, workforce credentials, education, healthcare, and supply