All articles
Future of Work4 September 2026·7 min read

Tamper-Proof Is Not Trustworthy: What a Verifiable Credential Actually Proves

W3C Verifiable Credentials 2.0 and Open Badges 3.0 have solved credential provenance — but a signature says nothing about the rigour of the assessment behind the claim. The three layers of a credential, the seven evidence fields almost nobody publishes, and when a credential is genuinely enough.

By AssessAll Editorial

A verifiable credential is a digital record whose issuer and contents can be checked cryptographically, so a reader knows it came from the stated issuer and has not been altered since. That proves provenance and integrity. It does not prove that the assessment behind the claim was rigorous, standardised, or related in any measurable way to job performance.

That distinction is about to matter a great deal, because the plumbing is finally real. The Verifiable Credentials Data Model 2.0 became a W3C Recommendation on 15 May 2025, giving the world a stable, royalty-free standard for machine-checkable digital credentials. 1EdTech's Open Badges 3.0 is built directly on it, so a badge is now a verifiable credential rather than a JSON blob with a hosted image. Governments and universities are shipping wallets. The technical problem of "is this document fake?" is close to solved.

The hiring problem was never that document. It was the sentence inside it.

What cryptographic verification actually establishes

Verification answers exactly two questions: did this credential come from the issuer it names, and has anyone changed it since? Both are worth answering. Neither tells you anything about the claim.

Consider two credentials, both cryptographically perfect, both saying "Proficient in Business Communication":

  • One was issued after a 30-minute video course with a four-question multiple-choice quiz and unlimited retakes.
  • One was issued after a proctored, timed assessment with a cut score set by a subject-matter-expert panel, an item bank large enough to survive exposure, and a published reliability coefficient.

A verifier will treat these identically. The signature checks out on both. Every downstream system — an applicant tracking system, a skills-inference engine, a screening agent — will read the same string and score it the same way. The standard is doing its job; the job just isn't the one hiring managers think they are buying.

The supply problem underneath

Credential Engine's 2022 count found 1,076,358 unique credentials in the United States alone. Of those, 430,272 were digital badges and 177,292 were online course-completion certificates. Non-academic providers accounted for 656,505 — the majority. That count predates the current wave of AI-generated course content, and no one seriously expects the number to shrink.

Now add cryptographic portability. A million credential types, each instantly checkable, each rendering as a tidy verified tick in a wallet, is not a trust infrastructure. It is a trust dilution machine, and it dilutes fastest exactly where credentials are cheapest to issue.

Employers already sense this, and compensate manually

A 2025 survey of 150 US hiring decision-makers, published by Eduvantis in March 2026, found that 96% had seen certificates on résumés and 57% had seen digital badges. But 57% said they investigate a microcredential further before giving it weight, citing widely varying quality and unclear skill outcomes. Graduate certificates and industry certifications ranked highest on perceived rigour; digital badges and microdegrees ranked lower. Across the board, microcredentials functioned as a supplementary signal, ranking below experience, interview performance and demonstrated skills.

Read that carefully. The features employers named as credibility-builders were the issuer's category and reputation, clearly articulated learning outcomes, the time investment required, evidence of meaningful assessment, and the ability to verify independently. Only the last of those is what the VC standards deliver — and it was not the one doing the heavy lifting.

Three layers, and only one of them is solved

| Layer | Question it answers | Status in 2026 | |---|---|---| | Provenance | Did the named issuer really issue this, unaltered? | Solved. W3C VC 2.0, Open Badges 3.0, national wallets. | | Portability | Can the holder carry it and can any system read it? | Largely solved. Shared data models, skills-framework alignment. | | Evidential basis | What was measured, how well, under what conditions? | Mostly unsolved, and rarely even expressed. |

Open Badges 3.0 does allow an issuer to embed assessment criteria and evidence in the badge itself. That capability is the most under-used field in the entire ecosystem. Almost nobody populates it with anything a psychometrician would recognise — no reliability estimate, no description of the item pool, no statement of the conditions the candidate sat under, no cut-score rationale.

What an evidence layer would actually contain

The measurement profession settled this question decades ago. The Standards for Educational and Psychological Testing, published jointly by AERA, APA and NCME, are built on a single premise: validity is a property of the interpretation and use of scores for a specific purpose, not a badge you attach to an instrument. The EEOC's guidance on employment tests makes the same point in enforcement terms — a selection procedure has to be justified for the job it screens for.

Translated into fields a credential could carry, a defensible claim needs at minimum:

  1. Construct — what was measured, in operational terms, not a marketing noun.
  2. Method — multiple choice, work sample, scored open response, observed simulation.
  3. Conditions — proctored or unproctored, timed or untimed, attempt number, identity check performed.
  4. Standard — the cut score and how it was set, plus who set it.
  5. Precision — reliability, or at least the number of scored items and the score's confidence interval.
  6. Currency — date, and the expiry the issuer is willing to defend.
  7. Fairness check — whether subgroup differences were examined at all.

Seven fields. None require new cryptography. All of them are simply absent from the overwhelming majority of credentials being minted today, which is why a hiring manager who receives one still opens a second browser tab.

This is the design premise behind an AssessAll Skill Passport: the record carries the assessment conditions with it — what was measured, how it was scored, and the AI proctoring integrity band the session earned — so the reader does not have to take the issuer's word for the rigour.

India built the rails first, which makes the gap unusually visible

India's credential infrastructure is now among the largest in the world. As of 2 July 2026, the government reported 26.35 crore verified APAAR IDs generated, with 2,899 higher education institutions and 98 skill awarding bodies registered on the Academic Bank of Credits, and 9.78 crore credit records mapped to learners' APAAR IDs (PIB factsheet, July 2026).

That is an extraordinary piece of public plumbing, and it does exactly what it was built to do: make academic records portable, machine-readable and hard to forge. It also makes the remaining question sharper rather than softer. A recruiter screening 4,000 applicants for a BPO intake can now confirm every marksheet instantly — and still cannot tell from those records which candidate can handle an irate customer in English on a live call. Provenance at national scale does not substitute for a job-relevant measurement.

When a verifiable credential is genuinely enough

It would be silly to argue that credentials should be replaced. Three cases where the credential is the right instrument and re-assessment would be waste:

  • Regulated licensure. A medical council registration or a chartered accountancy membership carries a statutory standard-setting process behind it. Verify it; do not re-test it.
  • Prerequisite gating. Where a credential is a legal or contractual precondition rather than a performance predictor, a cryptographic check is precisely the right tool.
  • Narrow, well-specified certifications with published exam blueprints. Several vendor and industry certifications publish their blueprints, pass rates and recertification rules. When that documentation exists, the evidence layer is public even if it is not embedded in the badge.

The failure mode is not credentials. It is treating an unspecified credential and a documented one as the same object because both show a green tick.

What to ask before you trust one

A practical screen, in order of cost:

  1. Does the credential state what was assessed, and how?
  2. Was the assessment supervised, and is the supervision level recorded?
  3. Is a cut score published, and can the issuer explain how it was set?
  4. Is there any reliability or precision figure at all?
  5. If the answer to 1–4 is mostly no, does the role justify measuring the skill yourself?

For most volume roles, question 5 resolves quickly. A short, scenario-based, AI-graded assessment aimed at the two or three behaviours that actually differentiate performance costs less than the recruiter hours spent squinting at credentials of unknown provenance — and unlike the badge, it produces a record you set the standard for. On pay-as-you-go credits at ₹30 / US$0.50, with free credits on signup, the arithmetic rarely favours guessing.

The takeaway

Cryptographic verification has solved the question of whether a credential is real, and solved it well; the industry should adopt the standards and move on. The harder question — whether the claim inside it was ever measured properly — is still answered by assessment design, not by signatures, and pretending otherwise just makes an unverified claim travel faster.

#verifiable-credentials#open-badges#skill-passports#credentials#skills-based-hiring#assessment

Measure it, don't guess it.

Start free with 100 credits — or write to solutions@bodhih.com.

Start free