EMVCo drafts one credential standard so merchants stop building per-wallet integrations
EMVCo published a draft framework for verifiable digital credentials in card-based payments, aimed at giving merchants one consistent data structure to authenticate against regardless of which wallet or payment network a customer uses.
EMVCo, the body that maintains the global EMV chip-card specifications, put out a draft framework on July 6, 2026 proposing a single standard for verifiable digital credentials in card-based payments. The problem it targets is integration sprawl: merchants currently build separate integrations for each wallet and payment network they support, each with its own credential format and validation logic. EMVCo's proposal would let a merchant implement one consistent data structure for digital credential authentication and have it work the same way regardless of which wallet or network a given customer's card runs on. The framework is still in draft, and no adoption timeline has been set.
Why it matters
Every fragmented credential format a merchant has to individually support is also a fragmented attack surface, more integration code means more places for authentication logic to have a gap. A single verified data structure across wallets and networks is the same standardization logic that made WebAuthn valuable for login: one correctly implemented validation path beats a dozen wallet-specific ones that each have to get it right independently.
This is worth tracking alongside Google and Mastercard's separate AP2 agentic payments work, both are EMVCo-adjacent efforts to standardize how payment authorization gets verified as the number of parties in a transaction, wallets, agents, issuers, keeps growing.
Source: FIDO Alliance
Related on Start with Identity
- BlogA loose PHP comparison let attackers sign in as WordPress admin through SAML
Two unauthenticated bypasses in the miniOrange SAML 2.0 Single Sign On plugin, CVE-2026-61979 and CVE-2026-15981, treat OpenSSL's error return as a valid signat
- BlogMCP's 2026-07-28 spec hardens OAuth and adds enterprise-managed authorization
RFC 9207 issuer validation is now mandatory, dynamic client registration is deprecated in favour of client ID metadata documents, and an enterprise extension le
- BlogNIST Digital Identity Guidelines (SP 800-63-4): from draft to final
NIST's rewrite of the Digital Identity Guidelines reached final publication in July 2025 after roughly four years and about 6,000 public comments. It brings syn
- ArticleAccess Review and Certification Best Practices: Preventing Rubber-Stamping and Building Effective Governance
How to design access review and certification programs that actually work, moving beyond compliance theater to meaningful governance through micro-certification
- RankingBest Verifiable Credential Platforms: Issuance & Verification Infrastructure
The best verifiable credential platforms in 2026: MATTR, Procivis, SpruceID, walt.id, and Hyperledger. Ranked for standards conformance (W3C VC, SD-JWT, OpenID4
- ArticleBuilding a 5-Year IAM Roadmap: Long-Term Strategy for Identity Programs
Create a complete 5-year IAM roadmap with capability maturity planning, phased implementation, stakeholder alignment, and budget strategies for sustainable iden