How OS and crypto agility strengthen identity security
© Jubemo / Shutterstock
As cyber threats evolve and certification frameworks tighten, governments must secure digital identity ecosystems throughout the entire document lifecycle – not only at deployment.
Citizens’ identity is a strategic national asset. Protecting it is not only a matter of fraud prevention, but fundamental to public trust, national sovereignty and the resilience of government services.
As governments accelerate digitalisation and decentralisation to improve convenience and efficiency, the attack surface continues to expand. Identity ecosystems now operate in an environment shaped by rapidly evolving technologies, geopolitical tensions and increasingly sophisticated cyber threats – both external and insider driven.
While secure-by-design documents and systems remain the essential foundation, security can no longer be treated as a one-time deployment milestone. It must be maintained across the entire identity lifecycle. Drawing on decades of experience in identity and cybersecurity, Thales supports governments in building resilient digital identity ecosystems designed to adapt securely over time.
© Thales / Colas Isnard
Why long identity document lifecycles create cybersecurity challenges
Modern identity documents and their associated systems must remain resilient against years of evolving vulnerabilities, including increasingly advanced AI-driven attacks and, in the near future, quantum computing threats.
At the same time, certification and regulatory frameworks are shifting towards continuous assurance. European regulations including the EU Cybersecurity Act, the EUCC certification scheme, the Cyber Resilience Act (CRA) and eIDAS 2 increasingly emphasise ongoing security monitoring, vulnerability management and periodic security reassessment.
Common Criteria certification, the global reference for identity documents is based on a five-year validity period, extendable only through reassessment against the evolving threat landscape. This creates a structural risk of misalignment between certification timelines and document validity periods.
While identity documents often remain in circulation for ten years or more, the underlying technologies must stay secure far longer once product development, certification, procurement and deployment cycles are considered.
This also raises an operational challenge: how can governments ensure continuity if a certification is suspended or revoked before an updated certified version becomes available? Security agencies and the applicable legal framework must also consider the time required for public authorities to deploy replacement solutions at national scale.
Enabling lifecycle security through OS agility and crypto agility
To maintain trust over time, governments need a global security approach across the entire identity chain – from design and certification to issuance, usage, monitoring and controlled evolution.
This approach combines robust identity documents, resilient infrastructures and operational cybersecurity capabilities, with one decisive requirement: the ability to adapt securely after issuance.
Identity documents also play a critical role in risk containment. By design, they distribute risk: compromising a single document affects only one credential, whereas an attack on a centralised identity system can expose the personal data of entire populations.
To sustain this distributed trust model over time, OS agility and crypto agility are becoming essential enablers of lifecycle security.
OS agility enables secure, controlled updates to embedded software – even after documents have been deployed in the field. It allows vulnerabilities to be patched and protections to be strengthened without forcing costly large-scale document replacement programmes.
Update mechanisms must themselves be security-assured and independently evaluated, ensuring corrective actions do not introduce new vulnerabilities and that the overall integrity of the identity scheme is preserved.
OS agility is already becoming operational reality. Five European governments have adopted OS agile-capable profiles, demonstrating a clear shift towards post-issuance security as a core requirement for modern identity ecosystems.
Flexible deployment models for secure digital identity systems
In a fast-moving security and regulatory landscape, agility must also be deployable with flexibility.
Governments face different constraints in terms of sovereignty, operational control, cost efficiency and response times. As a result, OS agility can be implemented through different deployment models while maintaining the same security objectives.
On-premises deployment for sovereignty and operational control: This model provides full control over infrastructure, operations and security governance. It is particularly suited to administrations with strong in-house capabilities and strict sovereignty requirements.
Secure SaaS deployment for scalable identity security: This approach combines rapid deployment, cost efficiency and industrial-grade security. Governments benefit from ready-to-use services with continuous maintenance and proven operational processes, while preserving data sovereignty principles because security updates do not require access to citizens’ personal data.
Both deployment models support the same objective: maintaining certified and resilient identity documents throughout their lifecycle despite evolving threats, regulatory changes and emerging technologies.
Improving citizen access through secure digital identity services
Beyond cybersecurity resilience, OS agility can also improve accessibility and convenience for citizens.
Identity credentials can be updated securely through self-service kiosks in government offices, from home using a PC, or on the move via mobile devices leveraging NFC-enabled smart ID documents.
This enables governments to strengthen both user experience and authentication security across multiple usage scenarios while supporting the growing demand for digital public services.
Preparing digital identity ecosystems for post-quantum cybersecurity
Crypto agility complements OS agility by enabling identity ecosystems to transition cryptographic keys or algorithms in response to compromise, policy changes or evolving standards.
With security agencies including ENISA, ANSSI, BSI and NIST urging organisations to prepare now for the post-quantum era, crypto agility provides a practical path towards hybrid and quantum-resistant cryptography.
It also enables governments to transition PKI infrastructures progressively as standards mature and operational readiness increases, without requiring large-scale document reissuance.
The operational benefits of agile digital identity security
A lifecycle-driven and agile security model delivers significant operational and strategic advantages for governments and identity authorities:
- Sustained trust and sovereignty across the full identity lifecycle
- Reduced disruption and cost by avoiding emergency document replacement programmes
- Alignment with evolving certification and regulatory requirements
- Faster response to newly emerging attack techniques and vulnerabilities
- Improved resilience against future quantum threats
- Secure cryptographic migration without document reissuance
- Enhanced citizen access through multi-channel update services across kiosks, PCs and mobile devices
Why digital identity security must continue beyond deployment
Identity security can no longer stop at issuance. As cyber threats, regulations and technologies continue to evolve, governments need identity ecosystems designed for continuous resilience.
Through lifecycle security approaches reinforced by OS agility and crypto agility, Thales helps governments maintain trust, strengthen sovereignty and securely adapt throughout the entire identity journey.