deepidv
KYC ComplianceSeptember 4, 20265 min read
244

Sumsub vs 1Kosmos vs deepidv: The Stablecoin CIP Build-Out

Sumsub, 1Kosmos, and deepidv compared for GENIUS Act stablecoin CIP compliance: bank-grade identification, watchlist screening, and the 12-month build window.

An operational engineering analysis evaluating deepidv, Sumsub, and 1Kosmos against the proposed customer identification program requirements for permitted payment stablecoin issuers under the GENIUS Act.

Stablecoin issuers are about to inherit bank-grade identity obligations, and the extended comment window closing October 23 is the last quiet stretch before the build. The five-agency proposal requires each permitted payment stablecoin issuer to run a written CIP: collecting name, date of birth or formation, address, and identification number; verifying through risk-based documentary or non-documentary procedures; screening against terrorist watchlists; and retaining records for five years, with compliance due 12 months after the final rule. Issuers comparing Sumsub, 1Kosmos, and deepidv for the build-out are comparing three different distances from that finish line.

The CIP requirements scorecard

RequirementdeepidvSumsub1Kosmos
Bank-grade CIP collection and verificationNative single-session flowConfigurable KYC workflowsWallet enrolment flow
Watchlist and sanctions screeningLuna, continuous and event-drivenIntegrated screening moduleVia integration
Institutional and entity onboarding (KYB)Arc-routed entity credentials and registry proofKYB product lineWorkforce-identity heritage
Evidence retention and audit trailFive-year decision-trail architectureCase management recordsCredential event logs
Verifiable credential and wallet ingestionArc: eIDAS 2.0, mDLs, ZKP tokensRoadmap-stage supportNative wallet, proprietary format
Regulatory change trackingLuna maps rulemaking to program gapsCompliance content resourcesNot a product focus

Three architectures meet one rulebook

deepidv: built on the assumption crypto would be regulated like banking

deepidv's verification engine and agentic compliance suite treats the CIP list as its native workload. The platform collects and verifies the four required data elements in one session, with document forensics, NFC chip validation, and deepeye liveness underneath the verification verdict. Luna runs watchlist screening continuously rather than at onboarding only, tracks the rulemaking docket itself, and maintains the five-year evidence trail examiners will request. For issuers whose customers arrive holding credentials, Arc ingests eIDAS 2.0 attestations, mobile driver's licenses, and ZKP tokens. The deepidv vs Sumsub comparison details the head-to-head.

Sumsub: broad KYC toolkit, assembly required

Sumsub offers one of the widest KYC/KYB toolkits in the market, and crypto-native firms know it well. For GENIUS Act CIP specifically, the questions are around the edges: continuous screening cadence, credential ingestion for institutional counterparties, and how much program logic the issuer's team must configure and maintain themselves. A capable compliance team can assemble a conforming program on Sumsub; the twelve-month clock makes the assembly cost a real line item.

1Kosmos: strong identity binding, different center of gravity

1Kosmos brings hardened credential binding and passwordless authentication from its workforce heritage, valuable for securing issuer operations and repeat institutional access. As the primary CIP engine, its wallet-centric model aligns less directly with a rule written around collection, verification, screening, and retention for arbitrary new customers, including entities. Issuers drawn to its authentication strengths often pair it with a dedicated verification engine; the platform comparison hub covers where the boundary falls.

Suggested read: Stablecoin CIP comment window extended to October 23

Ready to get started?

Start verifying identities in minutes. No sandbox, no waiting.

Get Started Free

The clock is the requirement

The most underweighted line in the proposal is the compliance date: 12 months after the final rule. Subtract vendor selection, integration, testing, and examiner-ready documentation, and the effective build window is closer to two quarters. Issuers should therefore score vendors on time-to-conforming-program, not feature checklists. Three questions cut through demos. How much of the CIP obligation does the platform operate versus merely enable? What does the evidence trail look like on day one of an examination? And when the final rule moves the perimeter, who reconciles the program: the vendor's agent or the issuer's staff?

Primary-market scope is the wildcard. Commenters are pressing the agencies to redraw the primary/secondary boundary, and a final rule that moves it will reward platforms that can extend verification outward without re-architecture.

What to ask every vendor before October 23

The comment window's extension gives issuers one more quarter of leverage: vendors answer harder questions before contracts are signed than after. Five belong in every evaluation. Show the evidence file an examiner would receive for one contested onboarding decision, produced live, not mocked. Demonstrate watchlist screening propagation time from a list update to an alert on an existing customer. Walk through exactly what changes in the platform, and who performs the change, if the final rule extends obligations beyond the primary market. Produce latency distributions for the full CIP collection-and-verification flow on real mobile traffic. And name the red-team cadence: when the platform's own defenses were last attacked with current fraud tooling, and what was found.

Frequently Asked Questions

What does the GENIUS Act CIP rule require of stablecoin issuers?

The proposal requires permitted payment stablecoin issuers to maintain a written customer identification program: collecting name, date of birth or formation, address, and ID number before account opening; verifying identity through risk-based procedures; screening against terrorist watchlists; providing customer notice; and retaining CIP records for five years. Compliance is due 12 months after the final rule.

Which platform is best for stablecoin CIP compliance?

Issuers with large compliance teams can assemble conforming programs on configurable toolkits like Sumsub. Issuers that need the platform to operate the program, continuous screening, evidence trails, rulemaking tracking, and credential ingestion included, are the profile deepidv was built for. 1Kosmos fits best as an authentication and credential layer alongside a verification engine.

Do stablecoin CIP obligations cover secondary market transfers?

Not under the current proposal, which limits CIP to primary-market relationships between the issuer and its direct customers. Commenters have asked the agencies to reconsider that boundary, so issuers should prefer architectures that can extend verification scope without rebuilding.

What is a customer identification program?

A customer identification program, or CIP, is the Bank Secrecy Act requirement that a financial institution collect and verify identifying information, name, date of birth or formation, address, and ID number, before opening an account, screen against terrorist watchlists, and retain records. The GENIUS Act rulemaking extends this banking obligation to permitted payment stablecoin issuers.

When will stablecoin CIP compliance be mandatory?

The extended comment period closes October 23, 2026. A final rule in 2027 would make compliance mandatory 12 months later, putting live, examinable CIP programs in the 2028 timeframe, with the practical build window considerably shorter once selection and integration are subtracted.

Start verifying identities today

Go live in minutes. No sandbox required, no hidden fees.

Related Articles

All articles

Jumio vs Trulioo vs deepidv: AUSTRAC Tranche 2 Readiness

Jumio, Trulioo, and deepidv compared for AUSTRAC Tranche 2 compliance: enrolment-to-examination readiness, SMR quality, and AML programs that match practice.

Sep 4, 20265 min
Read more

Jumio vs Sumsub vs deepidv: Moving to Continuous Financial Trust Layers

A technical evaluation comparing deepidv, Sumsub, and Jumio on continuous transaction risk scoring, voice deepfake detection, and sub-150ms execution.

Aug 28, 20268 min
Read more

Jumio vs Sumsub vs deepidv: Intercepting Section 311 Foreign Banking Risks

An operational engineering analysis evaluating deepidv, Sumsub, and Jumio against USA PATRIOT Act Section 311 findings and foreign correspondent risk.

Aug 20, 202610 min
Read more