# SP-052 Decentralised Identity & Verifiable Credentials

Status: draft. Release 26.03. Modified 2026-03-10. Licence: CC BY-SA 4.0.

Scope: Security architecture for decentralised identity (DID/SSI) systems covering W3C DID method selection and resolution, Verifiable Credential (VC) issuance and verification, holder wallet architecture, EU Digital Identity Wallet (EUDIW) eIDAS 2.0 compliance, zero-knowledge selective disclosure (ZK proofs, BBS+ signatures, SD-JWT), trust registry governance, revocation mechanisms (StatusList2021, accumulator-based), and...
Use when: Use this pattern when: building a digital identity wallet for citizens or employees; implementing cross-organisational credential exchange without a shared IdP; implementing KYC portability (verify once, reuse across institutions); deploying age verification with privacy preservation; participating in EUDIW as an issuer, wallet provider, or relying party; implementing professional licence verification or academic...
Not when: Do not use DID/SSI as the primary enterprise identity layer if you need real-time provisioning/de-provisioning (SCIM + OIDC is simpler and more mature).

## Controls (35, NIST SP 800-53 ids)
- Critical (10): IA-04, IA-05, IA-08, IA-12, SC-12, SC-13, AU-10, PT-01, PT-02, PT-03
- Important (20): IA-01, IA-02, IA-13, AC-03, AC-04, AC-16, AC-19, SC-08, SC-17, SC-28, AU-02, PM-07, PM-18, PT-05, SA-09, SA-11, CM-03, IR-04, RA-03, SI-07
- Standard (5): AC-01, AU-06, SA-04, CM-06, IR-09

## What each critical control mitigates (10)
- IA-04 Identifier Management: none of the threats below
- IA-05 Authenticator Management: T-DID-001, T-DID-003, T-DID-008, T-DID-009
- IA-08 Identification and Authentication (Non-organizational Users): T-DID-002
- IA-12 Identity Proofing: T-DID-009
- SC-12 Cryptographic Key Establishment and Management: T-DID-003, T-DID-006, T-DID-008, T-DID-009
- SC-13 Cryptographic Protection: T-DID-001, T-DID-004
- AU-10 Non-repudiation: T-DID-001, T-DID-005, T-DID-008
- PT-01 Policy and Procedures: T-DID-004, T-DID-009
- PT-02 Authority to Process Personally Identifiable Information: T-DID-004
- PT-03 Personally Identifiable Information Processing Purposes: T-DID-004

## Threats and the controls that mitigate them (10)
- T-DID-001 undefined: IA-05, AU-10, SC-08, SC-13
- T-DID-002 undefined: IA-08, SA-09, PM-07, RA-03
- T-DID-003 undefined: IA-05, SC-12, SC-28, AC-19, IR-04
- T-DID-004 undefined: PT-01, PT-02, PT-03, SC-13, AC-04
- T-DID-005 undefined: SA-09, PM-07, CM-03, AU-10, RA-03
- T-DID-006 undefined: SC-17, SC-08, SC-12, SI-07, AU-02
- T-DID-007 undefined: IR-04, AU-02, CM-06, SC-08
- T-DID-008 undefined: SC-12, IA-05, AU-10, IR-04, SA-11
- T-DID-009 undefined: IA-05, IA-12, SC-12, IR-04, PT-01
- T-DID-010 undefined: CM-06, SA-04, AC-03, SI-07

## More
- The critical controls and what each mitigates, as JSON (a few KB): /api/v1/patterns/SP-052/crosswalk?emphasis=critical
- The same for every control, with its clauses in a framework: /api/v1/patterns/SP-052/crosswalk?framework={framework id}. Framework ids are listed in /llms.txt
- The pattern's prose, examples and references as JSON, 43 KB: /api/v1/patterns/SP-052
- Page for people: /patterns/sp-052/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
- Related: SP-029 Zero Trust Architecture; SP-033 Passkey Authentication; SP-040 Post-Quantum Cryptography and Quantum Readiness; SP-044 SaaS Identity Lifecycle Management; SP-051 Tokenised Asset Security Architecture

This card, the API and the page are generated from one file. Checking one against another adds no evidence.
