In brief: Digital credentials are moving into real-world use, but physical IDs are not disappearing, creating a hybrid identity environment where organizations need to support both.
Accepting a digital credential requires more than verifying its authenticity. Organizations also need to decide whether the evidence it provides is sufficient for the specific transaction and its risk level.
Rather than building separate verification processes for every new credential type, organizations can use orchestration to integrate credential-specific checks into existing identity journeys and decision logic.
As more digital credentials roll out, physical documents will remain part of identity verification for years to come. Organizations will therefore need to support both, often within the same verification journeys, which creates a practical challenge.
New credential types establish trust in different ways and therefore require different security checks. The resulting complexity falls on the verifier, as reflected in our 2025 survey. According to it, 43% of respondents reported increased challenges with managing their existing identity verification flows as new digital credentials are introduced.
This article draws on Regula's presentation at the 2026 US Identity Week. It explains the common challenges associated with hybrid identity and how organizations can address them through orchestration.
Subscribe to receive a bi-weekly blog digest from Regula
New credentials require new checks, not new verification flows
Different types of credentials require distinct security checks:
-
Physical ID: Inspect the document's security features and confirm they are genuine and consistent.
-
ePassport: Read the embedded chip, verify the issuing authority's digital signature, and confirm the data hasn't been tampered with.
-
mDL: Verify the issuing authority's public key and ensure the credential hasn't been altered since issuance.
When a request for a new supported credential type comes in, it's tempting to build a separate end-to-end verification flow. In practice, that leads to duplicated policy logic, fragmented audit controls, redundant integrations, and exception handling that's hard to keep consistent. Add a few more credentials to the picture, and the whole thing becomes a maintenance burden.
The sustainable approach is to route different verification paths into a shared acceptance process.
Context matters as much as evidence
Checking the security features of a credential can’t provide the full picture, because fraud can exploit how identity evidence is captured, presented, and transmitted.
That’s why it’s important to collect context, such as hardware information, media metadata, device location, and IP address. These signals add nuance to the verified evidence and can affect the outcome.
For example:
-
The user accesses the service from an unexpected location → Require additional proof.
-
Video metadata doesn’t match the user’s device → Escalate the case for further checks or manual review.
-
The presented evidence meets the policy requirements, and no signals conflict with each other → The user can proceed.
Verification and sufficiency are not the same thing
Verifying a credential and assessing the context in which it was presented are only half the job. The other half is deciding whether that evidence is sufficient to justify the requested action.
Consider an age check at a retailer using a mobile credential. A verified, issuer-signed "over 21" attribute can establish eligibility without exposing a full birth date or any other unnecessary identity detail.
Now consider the same mobile credential used to recover access to a bank account. After the credential is verified, the bank still needs to match the identity to its records. Depending on the recovery process, it may also require additional evidence: a one-time code sent to a previously registered number, or a live selfie compared against the client's photo on file.
The credential has not become less trustworthy in the second journey. The transaction in question simply required a different level of proof.
That is the difference between verification and sufficiency:
-
Verification: What has been successfully checked?
-
Sufficiency: Is that evidence adequate for the requested action?
Orchestration turns identity evidence and context into business decisions
Checks establish whether a credential is legitimate. Context can help identify suspicious behavior or signs of fraud. Sufficiency criteria define how much evidence a particular transaction requires.
Orchestration brings all three together. It applies the organization's policies to the results of credential checks and inspects collected context to decide what should happen next.
For hybrid identity, orchestration is especially useful, since it supports scalability. When a new credential is introduced, its security features may differ, but the verification results can still feed into the same acceptance process. The surrounding policy logic, exception handling, audit controls, and downstream integrations can stay in place.
Start with the journey, not the credential
Introducing orchestration through a single identity verification journey is easier than redesigning the entire workflow at once:
-
Choose the journey. Start with an existing transaction that requires identity evidence, such as onboarding, account recovery, or age verification.
-
Set the acceptance criteria. Define what must be established, which risks and regulatory requirements apply, and who owns the final decision.
-
Map the required verification. Determine which credential-specific checks, contextual signals, and other evidence are needed to satisfy those criteria.
-
Map the possible outcomes. Define what should happen when the evidence is sufficient, incomplete, conflicting, or suspicious: proceed, request more evidence, review, or reject.
Once this structure is in place, the required verification components can be connected via orchestration without redesigning the entire journey for each new credential.
Hybrid identity is more about long-term flexibility than quick solutions
Digital credentials won't roll out everywhere at once. Adoption rates will vary widely across geographies and industries, requiring organizations to support both physical and digital IDs for years to come.
The goal is to build an identity infrastructure flexible enough to support emerging credential formats without compromising compliance or creating unnecessary friction for users.
Key takeaways:
-
Give each credential the verification checks it requires without building a separate end-to-end process around it.
-
Keep verification and sufficiency separate.
-
Use orchestration to coordinate credential-specific checks, context, and policy across different identity journeys.
-
Define when to proceed, request more evidence, send a case for review, or reject it.
-
Start with a single existing identity-verification journey, define the acceptance criteria, and expand from there.
Conclusion
Preparing for hybrid identity goes beyond accepting a digital credential alongside a physical document. It's about building an identity verification approach that can adapt as credentials and verification methods evolve — without compromising security, compliance, or control.
Explore how Regula can help your organization build identity verification solutions that are ready for the hybrid era.
