Blog · design note

How we grade identity — and how we keep it fresh

What each MintID assurance grade A1–A4 certifies, mapped onto eIDAS, ISO/IEC 29115, ETSI TS 119 461, NIST IAL and the EU anti-money-laundering regimes — and why freshness is a second axis (bands F1–F4) rather than a decaying grade, with re-verification periods taken from the standards.

Two decisions taken this month shape what a MintID attestation means. Each follows a published standard rather than a number we picked; the parts that are ours are stated as such.

Grades measure strength, and they follow eIDAS

A MintID credential carries an assurance grade, A1 to A4. We had to answer what each grade certifies, and the honest answer was: whatever the European framework already certifies. Every current standard tiers identity proofing by how robust the identification was — evidence, biometric liveness, screening, supervised presence — never by how old it is.

Europe’s framework has three tiers (eIDAS low · substantial · high). MintID has four. Rather than inventing a fourth European level, we anchor on the four-level backbone eIDAS itself is built on, ISO/IEC 29115, and we use the one step that European anti-money-laundering law inserts between a substantial identification and a qualified one: enhanced due diligence.

GradeWhat it certifieseIDASISO/IEC 29115Remote proofing (ETSI) · US (NIST)AML regime
A1Identity document validated against authoritative sources; for a company, the legal entity validated at the registrylowLoA 2— · IAL1customer due diligence
A2A1 plus possession proven with biometric liveness; for a company, a verified representative entitled to actsubstantialLoA 3Baseline · IAL2customer due diligence
A3A2 plus sanctions, PEP and adverse-media screening; for a company, beneficial owners identified and screenedsubstantial + EDDLoA 3⁺Baseline + screening · IAL2 + EDDenhanced due diligence
A4A3 plus qualified proofing: a high-assurance eID, the EU Digital Identity Wallet, or a qualified providerhighLoA 4Extended · IAL3enhanced, qualified

Two consequences worth noting. ISO’s lowest level — a self-asserted identity — sits below MintID’s floor and is simply out of scope: every MintID credential is backed by a real verification. And the vendor certifications that matter in Europe (ETSI TS 119 461, the standard behind qualified remote onboarding) map directly onto A2 and A4, so a certified provider slots in without a bespoke mapping exercise.

What this does not change. The protocol specification already described the four grades in these terms. The standards columns are mappings, not redefinitions, so this was recorded as an architecture decision and required no change to the frozen specification.

Freshness is a second axis, not a grade

A natural instinct is to let grades decay: a month-old verification is “better” than a year-old one. We looked at whether any standard does this. None does. eIDAS, ETSI and NIST all leave the validity of a proofing result to policy; anti-money-laundering law governs updating by risk and by events, not by the level of the original check.

So MintID reports age separately, next to the grade, as a band rather than a date — a date would let observers correlate records; a band does not.

Strength · how well we know whoFreshness · how recently
A4 — + qualified proofingF4 — under 30 days
A3 — + screeningF3 — under 90 days
A2 — + livenessF2 — under 180 days
A1 — document, no biometricF1 — under a year

A weak grade can be very fresh and a strong one can be old; a relying party states what it needs on both axes. The public claim an agent makes on MintID, human-backed, is defined as at least A2 and at least F1.

How long a verification can be reused

Once a person or company has been verified, that verification can back further attestations for a bounded period — after which the credential is suspended, visibly, until a re-verification completes. We wanted that period to come from a standard, not from us. It does, at two layers:

  • The legal envelope is the EU anti-money-laundering regulation: customer information must be updated at most every year for customers under enhanced due diligence (our A3 and A4) and at most every five years otherwise.
  • Inside that envelope, the period is the protocol specification’s own default validity per grade: twelve months for A1 and A2, six for A3, three for A4 — stricter than the law, and the same for natural and legal persons. No framework distinguishes the two in update periodicity, and the company-specific facts (representative, beneficial owners) already live in the grade, not in the clock.

Nothing is ever revoked by the calendar alone. An overdue re-verification suspends; only a withdrawal of consent or a deliberate issuer action revokes. The rest of MintID is unchanged underneath: the grade and the band travel as provable claims inside a zero-knowledge presentation, so a verifier receives “grade ≥ A2, fresher than F1” and never the document, the date or the person.

What does a MintID assurance grade certify?
How robust the identification was — evidence, biometric liveness, screening, qualified proofing — mapped onto published frameworks: eIDAS low/substantial/high, ISO/IEC 29115 levels 2–4, ETSI TS 119 461 Baseline/Extended for remote proofing, NIST IAL1–3, and the customer/enhanced due-diligence regimes of EU anti-money-laundering law. A1 is a validated document, A2 adds liveness, A3 adds screening, A4 adds qualified proofing.
eIDAS has three levels. Why does MintID have four?
Because MintID anchors on the four-level backbone eIDAS is built on, ISO/IEC 29115, and uses the one step European anti-money-laundering law inserts between a substantial identification and a qualified one: enhanced due diligence. That step is A3. ISO’s lowest level — a self-asserted identity — sits below MintID’s floor and is out of scope.
Does a grade decay as the verification ages?
No. No standard tiers identity proofing by age, so neither does MintID. Freshness is reported as a second axis, as a band (F4 under 30 days, F3 under 90, F2 under 180, F1 under a year) rather than a date — a date would let observers correlate records; a band does not.
How long can one verification be reused?
Inside the legal envelope of EU anti-money-laundering law (customer information updated at most every year under enhanced due diligence, at most every five years otherwise), the protocol’s default validity per grade is stricter: twelve months for A1 and A2, six for A3, three for A4 — the same for natural and legal persons. An overdue re-verification suspends the credential, visibly, until a re-verification completes. Nothing is revoked by the calendar alone.
Did this change the protocol specification?
No. The frozen specification already described the four grades in these terms. The standards columns are mappings, not redefinitions, so the decision was recorded as an architecture decision and required no change to the specification.

Strength and freshness, stated on their own axes

If you issue credentials under eIDAS, ETSI or an AML regime, the mapping is already done. We would like to hear where it does not fit.