Verifiable Credential Formats in the EUDI Wallet - SD-JWT VC and ISO/IEC-mdoc
The European Union Digital Identity Wallet (EUDI Wallet) is a transformative initiative to enable secure and interoperable digital identity solutions across EU Member States. At its core are two recognised verifiable credential formats, detailed in the EU Digital Identity Wallet Implementing Acts as amended in July 2026 by Commission Implementing Regulation (EU) 2026/1731 [3], that ensure security, interoperability and privacy.
Commission Implementing Regulation (EU) 2026/1731 amends the four core EUDI Wallet acts, namely (EU) 2024/2977, (EU) 2024/2979, (EU) 2024/2980 and (EU) 2024/2982, to align them with updated standards and specifications. The recognised credential formats are now IETF SD-JWT VC and ISO/IEC-mdoc. The W3C Verifiable Credentials Data Model remains on the roadmap and is expected to follow once the new W3C VCDM profiles become available.
Recognised Credential Formats
Article 4(1) of Implementing Regulation (EU) 2024/2977 [4], as amended, requires that electronic attestations of attributes issued to wallet units comply with at least one of the standards set out in Annex II of Implementing Regulation (EU) 2024/2979 [5]. That annex, as replaced by Regulation (EU) 2026/1731, applies the technical specifications in clauses 2 to 6 of ETSI TS 119 472-1 V1.2.1 (2026-02) [7]. The same annex governs person identification data: the PID annex states that natural person identification data shall be issued in accordance with clauses 5 (SD-JWT VC format) and 6 (ISO/IEC-mdoc format) [3]. The annex also defines the person identification data sets for both natural and legal persons.
The two recognised formats are:
- IETF SD-JWT VC (SD-JWT-based Verifiable Credentials): A token-based credential format developed at the IETF [1]. It builds on the JSON Web Token family and adds selective disclosure, which allows the wallet user to reveal individual claims without revealing the whole credential. ETSI TS 119 472-1, clause 5 profiles this format for electronic attestations of attributes and person identification data in the EUDI Wallet.
- ISO/IEC-mdoc: The mobile document format specified in ISO/IEC 18013-5 [2], best known from the mobile driving licence (mDL). It defines secure and interoperable methods for representing traditional documents in a digital format, with strong support for in-person verification. ETSI TS 119 472-1, clause 6 profiles this format for the EUDI Wallet.
W3C Verifiable Credentials: on the roadmap
The W3C Verifiable Credentials Data Model (VC DM) [11] is no longer referenced as a recognised format in the operative text of the amended acts. Recital 1 of Regulation (EU) 2026/1731 explains the direction of travel: as the W3C VCDM format is used as the reference format for attestations in sectors such as education, the European Digital Identity Wallets should also support this format once the new profiles on the W3C VCDM format are available [3].
Protocols and Interfaces for Presentation
Article 5 of Implementing Regulation (EU) 2024/2982 [6] requires wallet solutions to support protocols and interfaces for presenting attributes to wallet-relying parties, remotely and, where appropriate, in proximity. The technical specifications are set out in the new Annex II, added by Regulation (EU) 2026/1731. The annex applies Annex C of ISO/IEC 18013-7:2025 [9] together with clauses 4.1, 4.2, 5 and 6 of ETSI TS 119 472-2 V1.2.1 (2026-03) [8], which define two presentation profiles:
| Profile | Built on | Transmission mechanisms |
|---|---|---|
| ISO/IEC-mdoc profile | ISO/IEC 18013-5 [2] and Annex C of ISO/IEC 18013-7:2025 [9] | ISO/IEC 18013-5 for proximity (non-API mediated); ISO/IEC 18013-7 Annex C for API-mediated presentation |
| OpenID4VC-HAIP profile | OpenID4VC High Assurance Interoperability Profile (HAIP) [10] | Redirect-based remote presentation and API-mediated presentation |
In practice:
- ISO/IEC 18013-5 defines the interface specifications for mdocs used in in-person scenarios. It enables credential data to be securely retrieved, authenticated and verified during face-to-face interactions, such as border checks or licence verification by law enforcement.
- ISO/IEC 18013-7:2025, Annex C extends mdoc presentation to API-mediated flows, in which a mediating API on the user's device (for example, a browser or operating system credential API) carries the request and response between the wallet and the relying party.
- OpenID4VC-HAIP profiles OpenID4VP (OpenID for Verifiable Presentations) for high-assurance use. It carries remote, internet-based presentation through redirects and also supports API-mediated flows, for both SD-JWT VC and mdoc credentials.
Demonstrating Credential Issuance in various formats with iGrant.io
At iGrant.io, we bring these regulations and standards to life with the iGrant.io Organisation Wallet Suite. The issuance and verification functions in the Organisation Wallet Suite support all three formats, namely IETF SD-JWT VC, ISO/IEC-mdoc and W3C Verifiable Credentials, in OpenID4VC protocol flows. The salient features of the iGrant.io documentation include:
Credential Issuance and Verification: Practical examples of workflows for issuing and verifying credentials.
YouTube Tutorials: Step-by-step guides to assist developers and organisations in issuing credentials
Interactive Developer Workflows: Hands-on tools for integrating OpenID4VCI, OpenID4VP and related standards. You can try them out at:
- Credential issuance (InTime): https://docs.igrant.io/docs/openID4vci-issue-credential-intime/
- Credential Issuance (Deferred): https://docs.igrant.io/docs/openID4vci-issue-credential-deferred/
- Dynamic Credential Request: https://docs.igrant.io/docs/openID4vci-issue-dynamic-credential-request/
Why These Standards Matter
The integration of credential formats and protocols ensures:
- Interoperability: Standardised formats and interfaces allow seamless digital interactions across EU Member States.
- Security: Robust mechanisms safeguard user data and build trust.
- Flexibility: Support for diverse credentials, from general-purpose to specialised documents.
References
[1] IETF, 2026. SD-JWT-based Verifiable Credentials (SD-JWT VC). [online] Available at: https://datatracker.ietf.org/doc/draft-ietf-oauth-sd-jwt-vc/ [Accessed 11 August 2026].
[2] International Organization for Standardization, 2021. ISO/IEC 18013-5:2021 Personal identification - ISO-compliant driving licence - Part 5: Mobile driving licence (mDL) application. [online] Available at: https://www.iso.org/standard/69084.html [Accessed 11 August 2026].
[3] European Union, 2026. Commission Implementing Regulation (EU) 2026/1731 of 15 July 2026 amending Implementing Regulations (EU) 2024/2977, (EU) 2024/2979, (EU) 2024/2980 and (EU) 2024/2982 as regards applicable standards and specifications. [online] Available at: https://eur-lex.europa.eu/eli/reg_impl/2026/1731/oj [Accessed 11 August 2026].
[4] European Union, 2024. Commission Implementing Regulation (EU) 2024/2977 of 28 November 2024 laying down rules for the application of Regulation (EU) No 910/2014 as regards person identification data and electronic attestations of attributes issued to European Digital Identity Wallets. [online] Available at: https://eur-lex.europa.eu/eli/reg_impl/2024/2977/oj [Accessed 11 August 2026].
[5] European Union, 2024. Commission Implementing Regulation (EU) 2024/2979 of 28 November 2024 laying down technical specifications and procedures for the European Digital Identity Wallets - Integrity and core functionalities. [online] Available at: https://eur-lex.europa.eu/eli/reg_impl/2024/2979/oj [Accessed 11 August 2026].
[6] European Union, 2024. Commission Implementing Regulation (EU) 2024/2982 of 28 November 2024 laying down technical specifications and procedures for the European Digital Identity Wallets - Protocols and interfaces to be supported. [online] Available at: https://eur-lex.europa.eu/eli/reg_impl/2024/2982/oj [Accessed 11 August 2026].
[7] ETSI, 2026. ETSI TS 119 472-1 V1.2.1 (2026-02): Electronic Signatures and Trust Infrastructures (ESI); Profiles for Electronic Attestations of Attributes; Part 1: General requirements. [online] Available at: https://www.etsi.org/deliver/etsi_ts/119400_119499/11947201/ [Accessed 11 August 2026].
[8] ETSI, 2026. ETSI TS 119 472-2 V1.2.1 (2026-03): Electronic Signatures and Trust Infrastructures (ESI); Profiles for Electronic Attestations of Attributes; Part 2: Presentation protocols. [online] Available at: https://www.etsi.org/deliver/etsi_ts/119400_119499/11947202/ [Accessed 11 August 2026].
[9] International Organization for Standardization, 2025. ISO/IEC 18013-7:2025 Personal identification - ISO-compliant driving licence - Part 7: Mobile driving licence (mDL) add-on functions. [online] Available at: https://www.iso.org/standard/82772.html [Accessed 11 August 2026].
[10] OpenID Foundation, 2026. OpenID4VC High Assurance Interoperability Profile (HAIP). [online] Available at: https://openid.net/specs/openid4vc-high-assurance-interoperability-profile-1_0.html [Accessed 11 August 2026].
[11] W3C, 2025. Verifiable Credentials Data Model 2.0. [online] Available at: https://www.w3.org/TR/vc-data-model-2.0/ [Accessed 11 August 2026].