ISO 18013-5 is the international standard that defines how a mobile driving licence (mDL) is structured, stored, and securely shared from a smartphone. It specifies the data format, cryptographic protocols, and communication methods that allow a digital licence to be presented and verified in a privacy-respecting, tamper-proof way. For organisations navigating eIDAS 2.0 and the European Digital Identity Wallet, ISO 18013-5 is one of the core technical building blocks that underpins how credentials are exchanged in the new digital identity ecosystem.

How does ISO 18013-5 actually work as a standard?

ISO 18013-5 defines the technical rules for issuing, presenting, and verifying a mobile driving licence on a smartphone or other mobile device. It covers the data model, encoding format, and the communication protocols used when a holder presents their mDL to a verifier, whether in person or online.

At its core, the standard uses a document format called mdoc, which structures identity attributes as cryptographically signed data elements. When a user presents their mDL, only the specific attributes requested by the verifier are disclosed, such as age or licence category, without exposing the full document. This selective disclosure is built into the standard by design.

Communication between the holder’s device and the verifier happens over two main channels: proximity-based (using Bluetooth Low Energy or NFC for in-person checks) and online (using a browser or app session for remote verification). In both cases, the data exchanged is encrypted and authenticated, ensuring that neither the credential nor the communication can be tampered with.

What is an mDL and how does it differ from a physical driving licence?

An mDL, or mobile driving licence, is a digital representation of a driving licence stored on a smartphone and issued by an authorised authority. Unlike a physical card, an mDL is cryptographically signed, can be selectively shared, and does not need to be physically handed over during a check.

The differences go beyond format. A physical driving licence is a static document: once issued, the data on it cannot be updated without reissuing the card, and presenting it always reveals all the information printed on it. An mDL, by contrast, can reflect real-time updates from the issuing authority, and the holder can choose which attributes to share in a given interaction.

Consider a simple age verification scenario. With a physical licence, a verifier sees your full name, address, date of birth, and licence number. With an mDL compliant with ISO 18013-5, the holder can present only a confirmed “over 18” attribute, sharing nothing else. This is a meaningful privacy improvement with practical consequences for both consumers and organisations handling personal data.

What’s the difference between ISO 18013-5 and W3C Verifiable Credentials?

ISO 18013-5 and W3C Verifiable Credentials (VCs) are both standards for digital credentials, but they use different data models, encoding formats, and trust mechanisms. ISO 18013-5 uses the mdoc format encoded in CBOR, while W3C VCs use a JSON-LD or JWT-based format. They were designed for different primary contexts, though both are relevant to the EUDI Wallet.

ISO 18013-5 (mdoc)

The mdoc format defined in ISO 18013-5 was originally designed for government-issued identity documents, particularly driving licences. It is optimised for proximity use cases, strong cryptographic binding, and integration with physical identity infrastructure. The trust model relies on issuer-signed certificates within a defined Public Key Infrastructure (PKI), making it well-suited for high-assurance government credentials.

W3C Verifiable Credentials

W3C VCs emerged from the decentralised identity community and are designed with broader flexibility in mind. They support a wider range of credential types, including educational qualifications, professional certifications, and membership records. They work well in web-native environments and are often associated with decentralised identifiers (DIDs), though they can also be used with centralised trust registries.

In practice, the European Digital Identity Wallet architecture supports both formats. The EUDI Wallet’s Architecture and Reference Framework (ARF) includes both mdoc and W3C VC as valid credential formats, meaning organisations may need to work with either or both, depending on the credential type and use case. Understanding the distinction helps organisations choose the right format for the right context rather than treating the two as interchangeable.

How does ISO 18013-5 relate to eIDAS 2.0 and the EUDI Wallet?

ISO 18013-5 is one of the foundational technical standards referenced in the EUDI Wallet architecture. The European Digital Identity Wallet is designed to carry government-issued credentials, including the mobile driving licence, using the mdoc format defined in ISO 18013-5. This makes the standard directly relevant to any organisation preparing for eIDAS 2.0 compliance.

eIDAS 2.0 requires every EU Member State to make a European Digital Identity Wallet available to citizens, residents, and businesses. These wallets must support the secure presentation of identity attributes and qualified credentials to both public and private sector relying parties. The mdoc format and the communication protocols from ISO 18013-5 are embedded in the wallet’s technical specifications precisely because they provide a proven, interoperable foundation for high-assurance credential exchange.

For organisations that will act as relying parties under eIDAS 2.0, this means their verification infrastructure will need to be capable of reading and validating mdoc credentials. The standard is not optional background knowledge; it is a practical technical requirement for wallet-ready systems. Organisations in financial services and government are among those most directly affected, as they are explicitly named as sectors where wallet-based identity verification will become a standard interaction.

Which sectors and use cases does ISO 18013-5 apply to?

While ISO 18013-5 was originally developed for driving licences, its underlying mdoc format and protocols are now applied across a growing range of sectors and use cases wherever secure, privacy-preserving credential presentation is needed.

The following use cases illustrate where ISO 18013-5-based credentials are already in use or actively being piloted:

  • Transport and mobility: Digital driving licences accepted by traffic police, car rental companies, and border control agencies
  • Financial services: Identity verification for account opening, KYC checks, and strong customer authentication under PSD2 and eIDAS 2.0
  • Healthcare: Secure patient identification and sharing of health-related attributes without exposing unnecessary personal data
  • Age verification: Selective disclosure of an “over 18” or “over 21” attribute without revealing full identity details
  • Government services: Access to public sector portals and cross-border identity recognition within the EU
  • Travel: Digital Travel Credentials for border crossings, tested as part of the EU Digital Identity Wallet large-scale pilots

The breadth of these use cases reflects the standard’s design philosophy: a secure, flexible credential format that works across sectors because the underlying cryptographic and communication mechanisms are robust and interoperable. Organisations in healthcare and regulated industries are increasingly evaluating how mDL-compatible infrastructure fits into their digital identity strategies.

What should organisations do to prepare for ISO 18013-5 adoption?

Organisations should start by assessing whether they will act as a credential issuer, a verifying relying party, or both under the emerging EUDI Wallet framework. This determines which parts of ISO 18013-5 are most immediately relevant and shapes the technical and compliance work required.

For most private sector organisations, the most pressing task is preparing to accept and verify mdoc credentials. This involves evaluating existing identity verification infrastructure against the standard’s requirements and identifying gaps. The steps below provide a practical starting point:

  1. Map your use cases: Identify which customer interactions currently involve identity verification and which of these could involve wallet-presented credentials under eIDAS 2.0
  2. Assess your technical stack: Determine whether your current systems can handle mdoc-formatted credentials, CBOR encoding, and the proximity or online communication protocols defined in ISO 18013-5
  3. Understand the trust model: Familiarise your team with the PKI-based trust infrastructure that underpins mDL verification, including how issuer certificates are validated
  4. Review the EUDI Wallet ARF: The Architecture and Reference Framework published by the European Commission details how ISO 18013-5 fits within the broader wallet ecosystem and what relying parties are expected to support
  5. Engage with pilots and industry groups: The large-scale pilots running across EU Member States are generating practical insights about real-world implementation. Following their outputs helps organisations stay ahead of emerging requirements

Organisations should also factor in the timeline. The EUDI Wallet is expected to be widely available across Member States in 2026, meaning the window for preparation is narrowing. Early engagement with the standard reduces the risk of last-minute compliance pressure and positions organisations to benefit from faster, more trusted digital interactions from the outset. For a broader view of how to approach this transition, exploring TrustTech’s implementation approach can offer useful framing for organisations at different stages of readiness.

How TrustTech helps with ISO 18013-5 and digital identity readiness

Preparing for ISO 18013-5 and the broader shift towards wallet-based digital identity is not just a technical challenge. It touches compliance, architecture, user experience, and long-term business strategy. TrustTech supports organisations across all of these dimensions.

Working with TrustTech, organisations can:

  • Assess their current identity infrastructure against ISO 18013-5 and EUDI Wallet requirements
  • Implement wallet-ready verification flows that support both mdoc and W3C Verifiable Credentials
  • Enable selective disclosure and privacy-by-design credential exchanges that meet eIDAS 2.0 and GDPR requirements
  • Build reusable identity flows that reduce onboarding friction and eliminate repeated verification across touchpoints
  • Connect identity verification, qualification checks, and qualified digital signatures into a single trusted process

TrustTech’s platform is built on European digital identity standards and is designed to be eIDAS 2.0 ready from day one. Whether your organisation is in finance, government, healthcare, or another regulated sector, TrustTech brings both the technical depth and the practical implementation experience to make your digital identity transition manageable and future-proof. Ready to take the next step? Get in touch with TrustTech to discuss how your organisation can prepare for ISO 18013-5 and the EUDI Wallet.