DSIT publishes UK CertifID trust mark rules and promises action over unauthorised use
Guidance issued on Monday sets out which digital verification providers may display the government's trust mark, and states that the Office for Digital Identities and Attributes will act against organisations using it without authorisation.
The Department for Science, Innovation and Technology published guidelines on Monday governing use of the UK CertifID trust mark, and said the Office for Digital Identities and Attributes will take action against organisations that display it without authorisation.
The guidance went live at 11.19am on 7 September. It applies to digital verification service providers that are certified against version 1.0 of the UK digital identity and attributes trust framework and have services published on the register of digital identity and attribute services. Both conditions have to hold, and hold continuously, for a provider to keep using the mark.
What the mark is, and who owns it
The trust mark is owned by the Secretary of State for Science, Innovation and Technology, and its use is managed by OfDIA, which sits inside the department. Its stated purpose is to let consumers and organisations identify which digital identity and verification services meet UK government standards.
It is not simply a logo. The department describes it as a trade mark registered with the UK Intellectual Property Office and protected by law, citing the Trade Marks Act 1994 and section 50 of the Data (Use and Access) Act 2025. The guidance states plainly that OfDIA will take action against any unauthorised use.
What providers have to do
Eligibility is set out in section 14 of the trust framework rather than in the new document, which supplements those rules. The practical points for a provider are:
- the mark is licensed to a qualifying service, not to the company as a whole, so a provider with several services cannot apply it across all of them by default
- certification against trust framework v1.0 and publication on the register both have to remain current
- use requires authorisation from OfDIA
- the department has published technical application rules and illustrations showing how the mark should appear when it denotes a registered service
DSIT has given correspondence@dsit.gov.uk as the contact address for questions about eligibility.
Why it matters for founders
For the identity and verification companies on the register, this converts a marketing asset into a compliance obligation with a named enforcer. A provider that loses certification, or whose service comes off the register, no longer has a licence to display the mark, and the department has said in terms that it will act.
For companies buying verification services, the mark now carries a checkable meaning. Whether a supplier is entitled to display it can be confirmed against the public register rather than taken on trust, which is the point of publishing the rules in the first place.