
Imagine a citizen applying for a new ID card. Instead of waiting weeks for a letter, they receive a verifiable digital proof in their wallet within minutes – tamper-proof, instantly verifiable, and without media discontinuities. This technology doesn’t just offer speed, but also the highest level of security for citizens and authorities. Or consider a company needing to verify supplier certificates: instead of manually checking PDFs, validation happens automatically in the background. Such scenarios are no longer futuristic visions, but are becoming reality through Verifiable Credentials, or VCs.
But what exactly lies behind this term? Verifiable Credentials are more than just a technical data format. They are the key to a new ecosystem of digital trust services that replaces paper-based processes, makes manual verification obsolete, and creates the foundation for the digital sovereignty of citizens, businesses, and authorities.
In this article, we explain why Verifiable Credentials are relevant for organizations of all sizes, how they work, and what strategic decisions are necessary today to benefit from their advantages tomorrow.
VCs are digital proofs that can be issued by a trusted entity and verified by third parties without manual inquiry. They contain structured information about a person, organization, authorization, or characteristic – such as a university degree, official permit, or product certificate.
The crucial difference from conventional documents like PDFs or paper certificates lies in their cryptographic security. Each proof is equipped with a digital signature or electronic seal that confirms its authenticity, integrity, and unaltered state. This ensures that the verifier – whether an authority, employer, or bank – no longer needs to manually contact the issuer to confirm validity.
A simple example: A university issues a digital diploma to a graduate. The graduate stores it in their wallet and can present it to an employer when needed. The employer automatically verifies whether the diploma is genuine, comes from the correct issuer, and hasn’t been tampered with. This process takes seconds – without waiting times, media discontinuities, or manual verification steps.
What roles exist in Verifiable Credentials?
For digital proofs to work, three main actors are required, who stand in a clearly defined relationship to each other:
- The Issuer: The trusted source
The issuer is the entity that creates the digital proof and equips it with a cryptographic signature or seal. Typical issuers include authorities, universities, companies, or certification bodies. Their task is to ensure that the information contained in the proof is correct and that the proof is issued in a tamper-proof manner. They thus lay the foundation for the security of the entire system.
A practical example: A chamber of crafts issues a digital certificate of competence to a master craftsman. The chamber acts as the issuer and officially confirms that the holder possesses the required qualifications. Without this confirmation, the proof would be worthless – who would trust a self-issued certificate?
- The Holder: The owner of the proof
The holder is the person or organization that receives the proof and manages it in a digital wallet. The wallet functions like a digital wallet where various proofs can be securely stored and shared when needed.
An important aspect is the holder’s control over their data. Unlike conventional documents that are often shared uncontrollably, the holder can decide with VCs whom to present which proof to. For example, a citizen could merely confirm that they are over 18 without disclosing their exact date of birth.
- The Verifier: The recipient of the proof
The verifier is the entity that receives the proof and checks its authenticity. This could be an employer verifying a diploma, a bank requiring an identity document, or an authority checking a permit.
The crucial advantage is that the verifier can automatically check the validity of the proof without contacting the issuer. This is made possible by cryptography, which ensures that the proof hasn’t been tampered with and comes from the correct issuer.
How do Verifiable Credentials work?
The process from issuing to verifying a Verifiable Credential can be divided into five steps:
- The issuer creates a digital proof
The issuer creates a digital proof containing the relevant information – such as the holder’s name, issue date, and the confirmed characteristic (e.g., “Bachelor of Science in Computer Science”).
- The proof is cryptographically secured
The proof is then equipped with a digital signature or electronic seal. This signature serves as cryptographic proof that the proof comes from the issuer and hasn’t been altered.
An example: A university creates a digital diploma for a graduate. The diploma contains not only the grades but also a digital signature from the university confirming the proof’s authenticity.
- The holder stores the proof
The issued proof is transferred to the holder, who stores it in their digital wallet. The wallet can be a mobile app, cloud solution, or special hardware – what matters is that it securely manages the proofs and shares them when needed.
An important aspect is interoperability: The holder should be able to use the proof in various contexts – for example, when applying for a job, opening a bank account, or applying for a visa.
- Presentation of the proof to a verifier
When the holder needs to present the proof, they select the corresponding credential in their wallet and transmit it to the verifier. This can happen through various channels – such as QR code, NFC, or an API interface.
An example: A graduate applies to a company. They open their wallet, select their digital diploma, and send it to the employer. The employer receives the proof in a machine-readable format that can be automatically processed.
- Automated verification by the verifier
The verifier receives the proof and checks its authenticity. For this, the digital signature or seal of the issuer is verified. Additionally, it’s checked whether the proof is still valid – for example, whether it hasn’t been revoked.
A crucial advantage: The verification happens fully automatically. The verifier doesn’t need to manually contact the issuer to check if the proof is genuine. Instead, validity is checked in real-time, significantly speeding up the process.
What’s the difference between Verifiable Credentials, PDFs, and traditional certificates?
Many organizations still work with conventional documents like PDFs or traditional certificates. However, these approaches have significant disadvantages.
PDFs are widespread but only conditionally suitable for digital proof processes. While they can be equipped with a digital signature, verification often happens manually. Moreover, PDFs are document-centered – meaning they must be shared as a whole, even if only part of the information is relevant.
Another problem: PDFs are difficult to automate. When a company needs to verify supplier certificates, each PDF must be manually opened and checked. This is time-consuming and error-prone.
Digital certificates are an important component for secure digital processes. They confirm the identity of a person or server and enable encrypted communication.
However, they have one crucial disadvantage: They’re not designed for sharing proofs. A TLS certificate, for example, confirms that a website is trustworthy. It says nothing about whether the website operator possesses a particular qualification.
VCs combine the advantages of PDFs and digital certificates but go a step further by putting not just security but also cyber resilience at the forefront:
- Structured and machine-readable: The contained data structures can be automatically processed.
- Tamper-proof: Through cryptographic signatures and seals, manipulation is impossible.
- Controllable: The holder decides whom to present which proof to.
- Interoperable: They can be used in various systems and wallets.
What roles do digital identities and wallets play?
Digital proofs only reach their full potential in combination with digital identities and wallets.
A wallet serves as the interface between issuers, holders, and verifiers. It not only stores proofs but also enables their targeted sharing. The holder can decide which information to disclose – for example, only their driver’s license without simultaneously revealing their address.
For them to work, it must be ensured that the issuer is actually who they claim to be. This is where digital identities come into play. They confirm the issuer’s identity and enable the verifier to check their trustworthiness.
The European Digital Identity Wallet (EUDI Wallet) or in Germany called d-you, will play a central role in the coming years. It will enable citizens to store digital proofs in a standardized wallet and present them when needed – for example, during official procedures, banking transactions, or travel.
For companies and authorities, this means they must make their proof processes wallet-compatible. Those who still rely on PDFs or paper today will have difficulty keeping up with the requirements of the digital age tomorrow.
Why are digital proofs relevant for companies and authorities?
They are not a niche topic for IT experts, but a cornerstone of digitalization. They offer concrete benefits for organizations of all sizes and industries. Advantages include:
Efficiency gains through automation
Manual verification processes are time-consuming and error-prone. Verifiable Credentials enable automatic validation of proofs, for example in supplier qualification, customer onboarding, or official approval procedures.
Higher tamper resistance through secure signature methods
Paper-based proofs can be easily forged. Even digital documents like PDFs can be manipulated. Digital proofs, on the other hand, are cryptographically secured – any change would be immediately noticeable.
Better user experience for citizens and customers
No one likes having to present the same documents repeatedly. Verifiable Credentials enable users to store their proofs once and share them when needed, for example during a move, job change, or loan application.
Future-proofing through eIDAS 2.0 and EUDI Wallet
The eIDAS Regulation 2.0 and the d-you will strongly advance the use of digital proofs in Europe. Organizations that still rely on paper or PDFs today will have difficulty keeping up with regulatory requirements tomorrow.
In summary, Verifiable Credentials simplify processes wherever proofs need to be frequently issued, verified, or shared.
Use Cases for Authorities and Companies
VCs are already being used in various areas today. Here are some concrete examples:
Digital diplomas for universities and educational institutions
The Technical University of Sample City issues digital diplomas equipped with an electronic seal. Graduates can present these diplomas when applying for jobs, and employers can verify their authenticity in seconds.
Digital register extracts for authorities
A company applies for a loan. Instead of having to present a physical commercial register extract, it transmits the digital proof from its wallet. The bank automatically verifies the authenticity and decides on the loan application.
Supplier proofs for companies
An automobile manufacturer requires its suppliers to provide proof of compliance with quality standards. Instead of manually checking each certificate, validation happens automatically in the background.
Employee authorizations for companies
A company issues its employees digital IDs equipped with an electronic seal. During a security check, the ID can be automatically verified without an employee having to intervene manually.
Platform integration for software providers
An HR software provider integrates the issuance and verification of digital diplomas into its platform. Companies can thus automatically verify applications and validate the authenticity of diplomas.
Whether for companies or authorities, VCs will play a central role in the future. Authorities must not only provide digital proofs but also make them verifiable and usable for citizens, companies, and other institutions.
For companies, VCs are particularly valuable when proofs need to be repeatedly verified, documented for regulatory purposes, or integrated into digital processes.
What infrastructure do Verifiable Credentials need?
A VC needs more than just a data format or a wallet. For them to function in a trustworthy, scalable, and legally compliant manner, various components are required:
Electronic signatures and seals:
Electronic signatures and seals are the backbone of security for digital proofs. While an electronic signature comes from a natural person (e.g., for contracts), an electronic seal is used by an organization – such as an authority or company.
Certificates and Public Key Infrastructure (PKI)
Certificates confirm the identity of the issuer and enable the cryptographic security of the proofs. A Public Key Infrastructure (PKI) manages these certificates and ensures they are valid.
Timestamps: Proof of the time of issuance
Timestamps confirm when a proof was issued or verified. They are particularly important for legally relevant processes, such as contracts or official approvals.
Revocation mechanisms: Handling invalid proofs
Not all proofs are indefinitely valid. Revocation mechanisms allow invalid proofs to be blocked – for example, when a certificate has expired or an employee leaves the company.
Trust Service APIs: Integration into existing systems
APIs enable the integration of digital proofs into existing systems – such as specialized procedures, HR software, or compliance platforms.
The trustworthiness of digital proofs depends on many factors and is created through the combination of credential logic, cryptographic security, trustworthy issuers, and robust trust service infrastructure.
What questions should organizations clarify before a Verifiable Credentials project?
Before companies or administrations start with Verifiable Credentials, they should clarify some questions:
Which proofs should be digitized?
Not all proofs are suitable for digitization. Organizations should first examine which processes are particularly complex and where digital proofs would bring the greatest benefit.
Who issues the proofs?
The trustworthiness of a proof depends significantly on the issuer. Organizations must clarify whether they will act as issuers themselves or rely on external certification bodies.
How are the proofs verified?
The verification of VCs should happen as automatically as possible. Organizations must clarify which systems and APIs are needed for this.
What legal requirements apply?
Verifiable Credentials often need to meet certain legal requirements – for example, within the framework of eIDAS 2.0 or national regulations like the German Signature Act.
How is the infrastructure operated?
Organizations must decide whether to operate the infrastructure themselves, use a standard solution, or rely on a partner.
The questions listed only show a portion of the possible points to be clarified. For successful implementation, technical, legal, and economic aspects must be systematically analyzed and clarified.
d-you and eIDAS 2.0: What’s coming for companies and authorities?
Both concepts will strongly advance the use of digital proofs in Europe. For companies and administrations, this means they must make their processes wallet-compatible.
The d-you will enable citizens to store digital proofs in a standardized wallet and thus open up new application scenarios, such as driver’s licenses, professional qualifications, or official certificates. Companies and authorities must ensure that their proofs are technically compatible with the wallet.
eIDAS 2.0 creates the legal framework for digital identities and trust services in Europe. Organizations must ensure that their proofs meet the requirements of the regulation.
Organizations should already be addressing the requirements of EUDI Wallet and eIDAS 2.0 today. This includes:
- The wallet compatibility of their own proofs.
- The integration of trust services like signatures and seals.
- The connection to digital identity ecosystems.
Build, Buy, or Partner: How can organizations get started?
There are three basic approaches to implementing VCs:
Build: An organization builds large parts of the infrastructure itself
Some organizations choose to develop their own solution. This offers maximum control but comes with high effort, particularly regarding compliance, security, and scaling.
This option is suitable when:
- High internal technical competence is available
- Full control is needed
- Long-term strategic operation is planned
Buy: An organization uses a ready-made solution
Many organizations opt for standard solutions that can be quickly implemented. These solutions are often less flexible but more cost-effective and easier to operate.
This option is suitable when:
- Fast implementation is a priority
- Standard processes are to be mapped
- Limited internal resources are available
Partner: An organization works with a specialized trust service or infrastructure partner
Most organizations choose to partner with a Trust Service Provider that provides the necessary infrastructure. This offers the best balance between flexibility, compliance, and scalability.
This option is suitable when:
- Individual requirements exist
- Integration into existing systems is necessary
- Compliance, scaling, and operation are important
- Digital sovereignty and control are relevant
An example: A company cooperates with SIGN8 to efficiently issue and verify digital proofs. In doing so, it receives comprehensive support – from the trust service infrastructure to standardized APIs to specific components such as:
- Qualified signatures & seals for legal validity
- Certificate management for secure identity verification
- Timestamps for provable documentation
- Scalable processes for integration into existing workflows
This solution enables companies to not only technically implement digital proofs but also to design them in a legally secure, efficient, and future-proof manner.
Checklist: Is your organization ready for Verifiable Credentials?
Digital proofs offer enormous potential – but is your organization already prepared for them? This checklist helps you assess the maturity level of your digital proof processes and identify needs for action:
✅ Current Processes & Pain Points
- Do you currently issue proofs as paper or PDF?
- Are proofs verified manually (e.g., by comparing with databases or physical documents)?
- Do citizens, customers, or partners have to present the same proofs multiple times (e.g., at public institutions, banks, or service providers)?
- Are there processes with high verification or documentation requirements (e.g., compliance, audits, supply chains)?
- Do you want to make proofs wallet-compatible in the future (e.g., for mobile identity solutions)?
✅ Technical & Legal Requirements
- Do you need electronic signatures or seals (e.g., for legally binding contracts or official notices)?
- Should proofs be automatically verified (e.g., through machine-readable data or blockchain-based verification)?
- Do you work with regulated data (e.g., health data, financial proofs) or critical processes (e.g., customs, security)?
- Do you need APIs for connecting to specialized procedures, platforms, or portals?
- Do you have specific operational requirements (e.g., on-premise, private cloud, multi-tenant operation)?
✅ Future-Proofing & Regulatory Developments
- Are you preparing for eIDAS 2.0, the EUDI Wallet, or digital identity ecosystems?
- Do you plan to integrate into cross-sector trust frameworks (e.g., GAIA-X, EBSI)?
- Do you want to create interoperable solutions that are compatible with other systems (e.g., administrations, companies, IoT)?
The more questions you answer with “Yes,” the greater the value of Verifiable Credentials for your organization.
Next steps:
- Start pilot projects (e.g., in a defined area like certificate management or customer onboarding).
- Involve technical partners like SIGN8 to implement trust infrastructures and APIs.
- Keep an eye on regulatory developments (e.g., eIDAS 2.0) and adapt early.
Conclusion
Verifiable Credentials are significant for digital transformation. Three things are crucial:
- Verifiable Credentials make digital proofs verifiable – without manual verification steps, without media discontinuities, and with high tamper resistance.
- The practical benefit arises through concrete use cases – whether in administration (e.g., register extracts, approvals), business (e.g., supply chains, certificates), or on platforms (e.g., employee authorizations, customer onboarding).
- For trustworthy, scalable, and legally robust proof processes, appropriate trust service infrastructure is needed – from qualified signatures and seals to certificate management to wallet readiness and secure operating models.
Now is the right time to take action: Companies and authorities should identify relevant use cases and examine what infrastructure – whether through their own solutions, standard software, or partners like SIGN8 – is needed. Those who act early will be well-prepared for the future of digital proofs and can benefit from more efficient, secure, and user-friendly processes.








