Skip to content

Digital Identity Is Becoming Infrastructure, Not Just Authentication

Kexter Chiedu Ogobueze

7 min read

For much of the history of enterprise technology, digital identity has been treated primarily as an access problem. A user presents a username, password, certificate or other authenticator; a system verifies it; and access is granted according to the permissions associated with that account. That model remains important, but it describes only part of what digital identity is becoming.

Governments, standards bodies and technology providers are increasingly building systems in which identity information can be issued, stored, shared and independently verified across organizational boundaries. Instead of every service repeatedly asking a person to establish who they are, trusted credentials can potentially travel with the individual and be presented when required.

A driver's licence, professional qualification, employment credential, proof of age or government permit can therefore become more than a document that exists in a physical wallet or within one organization's database. It can become a machine-verifiable digital credential that another service can validate without rebuilding the entire identity process from the beginning. That changes the role of digital identity.

Authentication answers a relatively narrow question: should this user be allowed into this system? Digital identity infrastructure addresses a broader set of questions: Who or what is this entity? Who established that fact? What information about it can be trusted? What can it prove, and will another organization accept that proof? Those questions are becoming increasingly important as more economic and administrative activity moves online.

Identity is moving beyond the account

The traditional account model works reasonably well inside a single organization. An employer creates an account for an employee. An identity provider authenticates that person. Applications trust the identity provider, while IAM systems determine which resources the employee can access. The model becomes more difficult when trust needs to cross organizational boundaries.

Consider something as ordinary as proving a professional qualification. One institution issues the qualification. An employer needs to verify it. The individual may also need to present it to a regulator, customer or another employer later.

Today, those interactions often involve separate databases, uploaded documents, emails, manual checks and duplicated identity verification. Each organization builds its own process for determining whether the evidence can be trusted. Verifiable credentials offer a different model.

In May 2025, the World Wide Web Consortium finalized its Verifiable Credentials 2.0 standards. The model allows an issuer to create a cryptographically verifiable credential, a holder to possess it, and another party to verify it. The standards are intended to support credentials such as licences, academic qualifications and other attestations in a form that can be verified electronically and protected against tampering. The important idea is not the digital version of the document itself. Organizations have been digitizing documents for decades. The more consequential development is portable trust.

If one party can issue a trustworthy digital assertion and another can verify it using interoperable standards, identity stops being something every service needs to reconstruct independently. It begins to behave more like infrastructure.

Digital wallets demonstrate what this could look like

Europe provides one of the clearest examples of how far this idea is moving beyond authentication. Under the European Digital Identity framework, EU Member States are expected to make digital identity wallets available to citizens, residents and businesses by the end of 2026. The wallets are intended to support public and private services, electronic signatures and the storage and presentation of digital credentials. This is a substantially different proposition from creating another government login.

A person might use a wallet to demonstrate a qualification, prove eligibility for a service or establish that they meet an age requirement. Importantly, the architecture also introduces the possibility of sharing only the information required for a transaction. The EU's age-verification work illustrates the distinction. Its current approach is designed to allow someone to prove that they exceed a particular age threshold without necessarily disclosing their precise age or broader identity information.

Under many traditional identity processes, organizations collect more information than they actually need because the underlying document contains it. A business verifying that someone is over 18 might see a full date of birth, address and photograph even if none of those additional attributes is relevant to the transaction. A credential-based system can potentially answer the narrower question: Does this person meet the age requirement?

That does not automatically make digital identity private or secure. Wallets, issuers, verifiers and the surrounding ecosystem still need strong controls. But the architecture creates opportunities to minimize the disclosure of personal information rather than treating excessive disclosure as an unavoidable consequence of identity verification.

Canada is moving in a similar direction, although the ecosystem is at a different stage. The Government of Canada is developing CanadaLogin alongside a system called GC Issue and Verify, which is intended to allow departments to issue digital versions of credentials such as work permits and licences that people can store on mobile devices and present electronically.

The Canadian government's broader guidance also treats trusted digital identity as an interoperability issue, emphasizing trust frameworks that allow identities to be accepted across government jurisdictions and potentially the private sector. That is infrastructure thinking rather than simply authentication thinking.

Trust matters more than the wallet

There is a risk, however, in reducing the digital identity discussion to wallets and credentials. A wallet can store information. Cryptography can help prove that a credential was issued by a particular party and has not been altered. Standards can make different systems technically interoperable. None of those things independently establish whether the underlying claim should be trusted.

If a digital credential states that someone holds a professional licence, the important question is not merely whether the credential is cryptographically valid. It is whether the issuer was authorized to make that claim, whether its identity-proofing process was appropriate, whether the credential is still valid, and whether the receiving organization recognizes the issuer. This is where identity infrastructure begins to resemble other forms of critical digital infrastructure. Technology alone is insufficient. The ecosystem needs governance.

Trust frameworks define which participants can issue credentials, what assurance is required, what standards they follow and how relying parties decide what to accept. Revocation processes are needed when credentials become invalid. Privacy rules determine what can be requested or retained. Security requirements govern wallets, issuers and verification systems.

NIST's current Digital Identity Guidelines reflect this broader view of identity assurance. The 2025 revision addresses identity proofing, enrollment, authentication and federation as related but distinct components, while placing greater emphasis on fraud, risk management and the lifecycle surrounding digital identity. The practical lesson for organizations is that implementing digital identity cannot simply mean purchasing a wallet platform or integrating a new authentication protocol.

The more difficult work is deciding what evidence the organization trusts and under what conditions. A university may issue a degree credential. A regulator may issue a licence. An employer may issue an employment credential. A financial institution may establish that an individual passed a particular identity-proofing process. The technology can help those assertions move between systems. Governance determines what they mean.

Organizations will need to rethink identity architecture

For enterprise technology teams, this evolution creates several consequences. The first is that identity architecture will increasingly extend beyond workforce IAM and customer login systems.

Applications may need to consume credentials issued by external organizations. Enterprises may become credential issuers themselves. IAM teams may need to distinguish authentication from proof of attributes. Procurement teams may need to assess whether identity products support interoperable standards rather than creating another proprietary identity silo. The second consequence is that identity data itself may become more decentralized.

Organizations are accustomed to collecting information into central directories and customer databases. A credential-based model can sometimes allow information to remain with the individual until it is required. That has potential benefits for privacy and data minimization, but it also requires organizations to reconsider how verification, auditing and records management work. Security teams will have new problems as well.

Digital credentials need protection against theft and fraudulent issuance. Wallet recovery has to balance usability with assurance. Revocation needs to work reliably. Organizations need mechanisms for determining whether an issuer remains trustworthy. Fraudsters will inevitably target onboarding and identity-proofing processes if obtaining a legitimate credential gives them access to many downstream services.

The existence of a cryptographically valid credential therefore cannot eliminate risk. In some circumstances, it may concentrate it. A compromised identity provider that previously affected one service could become more consequential if many organizations rely on its credentials. That is why the infrastructure comparison matters. Infrastructure creates efficiency precisely because many other services depend on it. That also means failures propagate farther.

Digital identity is becoming a shared trust layer

None of this means passwords, enterprise directories or conventional IAM are about to disappear. Organizations will continue to authenticate employees and customers. Accounts will still exist. Applications will still need authorization models that determine what users can do after they sign in. The change is that authentication is increasingly becoming one component of a larger identity ecosystem.

A person may authenticate to a wallet, present a credential issued by one organization, prove a specific attribute to another and receive authorization based on that evidence. Organizations may increasingly rely on assertions they did not create themselves. That is a fundamentally different architecture from asking every application to maintain its own isolated representation of identity.

The transition will not happen uniformly. Standards will compete, national approaches will differ, interoperability will be imperfect and many organizations will continue using conventional identity systems for years. But the direction is becoming clearer. Digital identity is moving from something attached to individual applications toward a reusable layer for establishing trust across services, organizations and transactions. Authentication will remain essential. It simply will no longer describe the whole system.

  • Identity
  • IAM
  • Risk Management
  • NIST
  • Third-Party Risk

Kexter Chiedu Ogobueze

AI × Cybersecurity × Product × Risk × Emerging Technology

Related reading

Perspective/Security//7 min read

Attackers Are Stealing Sessions, Not Passwords

Attackers can steal authenticated sessions without defeating MFA itself. Enterprises need phishing-resistant authentication, token protection and session-aware incident response.

Stay close to what matters.

New perspectives and practical analysis on security, risk, AI and product.