Blog
Ecosystem of trusted issuers: How trust chains support digital credential verification

Ecosystem of trusted issuers: How trust chains support digital credential verification

Explore how EBSI’s ecosystem of trusted issuers makes the authority behind digital credentials independently verifiable.

Explainers
July 17, 2026

A digital credential can be cryptographically authentic and still leave one question open: was the issuer authorised to issue it? EBSI’s ecosystem of trusted issuers helps verifiers answer that question without contacting the issuer. Its issuer trust model makes the accreditation chain behind a credential independently verifiable.

The trust question behind every digital credential

An employer receives a digital university diploma. The signature checks out. One question remains: was the organisation that signed it authorised to award that diploma?

The instinctive answer is to call the university. That works for one diploma. It does not work for thousands of diplomas, licences and attestations issued across different countries.

The key distinction:
Cryptographic proof answers: did this issuer sign the credential?
Issuer trust answers:
was this issuer authorised to issue this type of credential?

A university issues the diploma, the graduate holds it in a wallet, and an employer verifies it. The digital credential exchanged between them is known as a verifiable credential.

Why direct issuer verification does not scale

Contacting the issuer each time a credential is checked carries three costs:

  • Issuers must operate a sufficiently available verification service so third parties can check credentials awarded years earlier.
  • Verifiers must build and maintain a connection to every issuer they may encounter, potentially hundreds across borders.
  • Holders face additional privacy risks, because an issuer contacted on every check may learn where and when a credential is used.

It also answers the wrong question: how to reach the issuer, rather than whether the issuer was authorised.

How the ecosystem of trusted issuers works

EBSI’s issuer trust model makes the public information needed for verification available through shared registries. Issuers are identified by decentralised identifiers, or DIDs, which link an organisation to the public keys used to check its signatures. Verifiable accreditations record what an issuer may issue, and credential schemas describe how that credential should be structured. [Learn more about credentials schemas]

The ledger does not create trust. It makes evidence of an established trust decision independently verifiable.

The ministry, regulator or accreditation body still makes the trust decision. And each verifier decides which trust roots, jurisdictions and policies it accepts. Registration does not oblige anyone to accept an issuer.

For platforms and networks, this provides a structural way to define who may participate as an issuer, what each issuer is authorised to issue, and how authority is delegated through different accreditation layers.

Who participates in an EBSI trust chain?

Roles in EBSI's ecosystem of trusted issuers
Role What it does Illustrative example
Root Trusted Accreditation Organisation Holds authority at the top of a trust chain for a sector or jurisdiction. Ministry of Education
Trusted Accreditation Organisation Accredits issuers under that authority. National higher education accreditation body
Trusted Issuer Issues credentials within the scope of its accreditation. University

Examples are illustrative. Governance arrangements may differ by country, sector and jurisdiction.

The following is one possible education trust chain. Governance structures may differ between countries and sectors.

An illustrative education trust chain. The employer verifies the diploma by following the accreditation chain back to a trust root it recognises.

This is particularly important for platforms and networks where many organisations issue credentials under a shared set of rules. In these environments, the integrity of each issuer affects trust in the ecosystem as a whole.

How a university becomes a trusted digital credential issuer

  1. The rules are set. Authorities agree a credential schema for the diploma.
  2. The university establishes its identity. It registers a DID with the public key information others need to check its signatures.
  3. The university is accredited. The accreditation body issues a verifiable accreditation stating which credentials, jurisdiction and schemas apply.
  4. The trust information is registered. Identifier, keys, accreditation and schema become available through EBSI's registries. The diploma itself and the graduate's personal data stay off the ledger.
  5. The diploma is issued and used. The university issues it to the graduate's wallet, and the graduate presents it to an employer.

What an employer can verify

  • who issued the credential
  • whether the cryptographic proof is valid
  • what the issuer was accredited to issue
  • whether the accreditation chain reaches a trust root the employer recognises
  • whether the credential uses the expected schema

Credential status, meaning expiry, suspension or revocation, is a separate check. Issuer trust answers who stands behind a credential, not everything about it.

No call to the university is needed, so the check does not routinely notify the issuer.

What EBSI does, and does not do

  • Available through shared infrastructure: issuer identifier, public key information, accreditation evidence, credential schemas.
  • Not published on the ledger: the diploma itself, the graduate's personal data.
  • Decisions stay with institutions: relevant authorities make accreditation decisions, and each verifier sets its own trust policies.

Why issuer trust matters for cross-border credentials

Once a chain is in place, checking the organisation behind a credential becomes a lookup. A university in one Member State can issue a diploma that an employer in another can evaluate, with no bilateral integration between them. Issuers can rotate signing keys without repeating accreditation. Education, social security and other sectors can define their own authorities and schemas on the same infrastructure.

The institutions keep their existing responsibilities. EBSI makes evidence of their authority reusable across services and borders.

Share with others

Explore EBSI in Education

Explore how EBSI supports cross-border trust in education and in other sectors

EBSI in education
EBSI projects
Related articles
No items found.