deepidv
KYC ComplianceSeptember 11, 20265 min read
247

Jumio vs Sumsub vs deepidv: The Mobile Driver's License Era

Jumio, Sumsub, and deepidv compared on verifiable digital credential support after the five-agency CIP FAQ made mobile driver's licenses bank-grade ID.

An operational engineering analysis evaluating deepidv, Jumio, and Sumsub against the September 8 interagency FAQs that made verifiable digital credentials, mobile driver's licenses foremost, an accepted documentary method under the Customer Identification Program rule.

The document-photo era of bank onboarding just received its retirement notice. With five agencies jointly approving verifiable digital credentials for CIP compliance, every institution's vendor stack faces a new question: can it validate a cryptographically signed mDL end to end, issuer chain, revocation, device binding, presenter liveness, and produce the evidence file an examiner will request? Photographing the credential and running image forensics on it, the workflow most stacks default to, misses the point of the guidance entirely. This analysis compares deepidv, Jumio, and Sumsub on the workload the FAQ actually creates.

The VDC readiness scorecard

CapabilitydeepidvJumioSumsub
mDL / VDC cryptographic validationNative via Arc: issuer chain, revocation, bindingDocument-pipeline heritage, credential support emergingWorkflow toolkit, credential blocks configurable
eIDAS 2.0 / EUDI attestation ingestionNative, with selective disclosure supportRegional roadmapRegional roadmap
Presenter verification on credential flowsdeepeye liveness in the same sessionSelfie match add-onConfigurable liveness step
Fallback path parity (plastic documents)Same evidence standard, NFC + forensicsCore strengthCore strength
CIP evidence trail per validationDecision-trail native, examiner-readyCase recordsCase records
Regulatory change absorptionLuna maps FAQ terms to program gapsCompliance contentCompliance content

Three stacks, three starting points

deepidv: built for the credential era the FAQ just opened

deepidv treats a credential as a cryptographic object first. Arc validates the issuer signature chain against trusted authorities, checks revocation in real time, and confirms device binding before the credential counts for anything, while deepeye verifies the presenter with structural liveness in the same session, closing the stolen-phone gap the FAQ leaves to institutions. Because Arc already ingests eIDAS 2.0 attestations and ZKP tokens, the same integration covers the EUDI wallets arriving in Europe within the quarter. Luna folds the FAQ's terminology into the institution's CIP documentation, so the program text and the validation flow stay reconciled. The deepidv vs Jumio comparison and deepidv vs Sumsub comparison carry the full head-to-heads.

Jumio: document pipeline excellence, credential transition underway

Jumio's document verification pipeline remains an industry reference for photographed and NFC-read physical documents, and institutions with heavy plastic-document volume rely on it well. The FAQ shifts the center of gravity: an mDL is not a document image to forensically score but a signature to validate, and pipelines organized around image capture absorb that shift as an add-on rather than a native workload. Institutions should ask precisely how mDL validation runs, cryptographic verification against issuing authorities, or capture-and-inspect of the phone screen, because the two produce very different examiner conversations.

Sumsub: configurable workflows, assembly still required

Sumsub's workflow toolkit can be configured to accept digital credentials, and its breadth across KYC, KYB, and monitoring keeps it on shortlists. The consideration is the same one that shaped the stablecoin CIP analysis: configuration is the customer's work. A conforming VDC program needs issuer trust policy, revocation cadence, binding checks, and fallback routing expressed and maintained by someone, and on a toolkit that someone is the institution's team. At mDL adoption scale that is sustainable; at EUDI-plus-mDL-plus-ZKP scale it becomes a standing engineering commitment.

Suggested read: Verifiable digital credentials just became CIP-grade ID

Ready to get started?

Start verifying identities in minutes. No sandbox, no waiting.

Get Started Free

The test that decides it: the stolen phone

Every vendor in this comparison can be made to say yes to an mDL. The differentiating scenario is the credential that should fail: a stolen device with a cached mDL, presented by someone who is not its subject. Signature validation passes, revocation passes, binding to the device passes. Only presenter verification, liveness plus face match against the credential's portrait, catches it, and only if it runs in the same session as the credential exchange rather than as a separable step a fraudster can satisfy differently.

Institutions evaluating VDC support should run exactly that red-team scenario in the proof of concept, and ask each vendor for the evidence file the attempt generates. The stack that produces one coherent record, credential validation plus presenter verification plus device telemetry, is the stack that was designed for this rather than adapted to it.

The window is a competitive asset

The FAQ landed September 8; examiner expectations will crystallize over quarters, and early adopters will shape them. Institutions that stand up conforming VDC acceptance this year get the conversion dividend of photo-free onboarding while competitors are still scheduling vendor demos, and their examination files become the reference examples. The same build, pointed at Europe, is EUDI readiness a quarter before the wallets ship. Credential verification is briefly a differentiator; it will not stay one.

Frequently Asked Questions

Which IDV vendors support mobile driver's licenses?

Most major vendors are adding support, but architectures differ: deepidv validates mDLs cryptographically through Arc with presenter liveness in the same session, while document-pipeline vendors like Jumio and workflow platforms like Sumsub are layering credential support onto image-centric stacks. Ask whether validation is cryptographic or capture-based.

What did the September 2026 CIP FAQ change for banks?

The OCC, FinCEN, Federal Reserve, FDIC, and NCUA jointly clarified that state-issued mobile driver's licenses and other government-issued verifiable digital credentials can satisfy the CIP rule's documentary verification requirement, provided the bank's program defines how credentials are validated. It applies to institutions of all sizes.

Is a mobile driver's license safer than a physical ID for verification?

For document authenticity, yes: an mDL is validated by the issuing state's cryptographic signature, which AI forgeries cannot fake, while physical documents are judged visually or by chip where present. Presenter risk remains, so mDL flows still need liveness to confirm the holder.

How should banks handle customers without digital credentials?

With a fallback path at equal assurance: NFC chip reading where documents carry chips, forensic document analysis plus liveness where they do not. The CIP program should route wallet, mDL, and plastic paths to the same evidence standard rather than gating on credential ownership.

Does the CIP FAQ apply to the EUDI wallet?

Directly, no: the FAQ is US banking guidance. Architecturally, yes: EUDI attestations are verifiable digital credentials of the same shape, due from EU member states by the end of 2026. A validation layer built for mDLs that also ingests eIDAS 2.0 attestations covers both regimes with one integration.

Start verifying identities today

Go live in minutes. No sandbox required, no hidden fees.

Related Articles

All articles

Sumsub vs 1Kosmos vs deepidv: The Stablecoin CIP Build-Out

Sumsub, 1Kosmos, and deepidv compared for GENIUS Act stablecoin CIP compliance: bank-grade identification, watchlist screening, and the 12-month build window.

Sep 4, 20265 min
Read more

Jumio vs Trulioo vs deepidv: AUSTRAC Tranche 2 Readiness

Jumio, Trulioo, and deepidv compared for AUSTRAC Tranche 2 compliance: enrolment-to-examination readiness, SMR quality, and AML programs that match practice.

Sep 4, 20265 min
Read more

Jumio vs Sumsub vs deepidv: Moving to Continuous Financial Trust Layers

A technical evaluation comparing deepidv, Sumsub, and Jumio on continuous transaction risk scoring, voice deepfake detection, and sub-150ms execution.

Aug 28, 20268 min
Read more