Technology

Mobile Driver's Licenses: Where ISO 18013-5 Stands in 2026

Mobile driver's licences are moving from pilot programs toward practical use, but a shared technical standard has not yet produced universal acceptance. ISO 18013-5 gives issuers and readers a secure way to exchange credential data, while leaving major operational and privacy questions unresolved.

Mobile Driver's Licenses: Where ISO 18013-5 Stands in 2026

A mobile driver's licence, or mDL, is a digital version of a driving credential held in a smartphone wallet or a dedicated state application. It is not simply an image of a plastic card. Properly implemented, an mDL lets its holder prove specific facts, such as being over a required age, while allowing a business or government agency to verify that the information came from the issuing authority and has not been altered.

The technology is gaining ground in US state programs and international trials, including schemes aligned with broader digital identity wallets. Yet its everyday utility remains constrained by a familiar problem in identity technology: possession of a valid credential does not guarantee that the person behind the counter, at the checkpoint, or on the website can accept it.

What ISO 18013-5 standardizes

ISO/IEC 18013-5 is an international standard for the presentation of mobile driving licences and the interface used by a verifier, often called a reader. It sets out common data structures, security mechanisms and communication methods for showing an mDL from a phone to a nearby reader. In practice, this can involve a QR code, Bluetooth Low Energy or near-field communication, depending on the implementation and use case.

The standard's central feature is issuer authentication. A motor vehicle agency or other authorized issuer cryptographically signs the credential data. Cryptography here means mathematical techniques that allow a verifier to check that the data originated with the issuer and has not been changed. A reader can validate that signature against trusted issuer certificates rather than relying on visual inspection of a screen.

ISO 18013-5 also supports selective disclosure. Instead of handing over every field printed on a physical licence, a holder can share only the attributes requested for a transaction. A venue checking eligibility for alcohol sales, for example, may need confirmation that a person is over 21, not a home address or licence number. The exact data request and user consent experience still depend on the issuer's wallet and the reader.

  • A signed digital credential can be checked for authenticity and integrity.
  • Selective disclosure can reduce the amount of personal data shared.
  • A compatible reader can verify many presentations offline, without contacting the issuer in real time.
  • Offline operation requires current trust information, including issuer certificates and status data.

Offline verification is important for roadside encounters, venues with unreliable connectivity and some travel settings. It does not mean the system has no operational dependencies. Readers need trusted certificates and may need periodically updated information about expired, suspended or revoked credentials. Policies also determine whether a verifier may retain any data after a transaction.

Why it is not a photo of a licence

A photograph, screenshot or scanned image of a licence is easily copied, edited or reused. It generally cannot prove which agency issued it, whether it remains valid, or whether the person presenting it controls the original credential. A well-designed mDL presentation adds cryptographic proof and can require the holder's phone to participate in the transaction, often after local device authentication such as a passcode or biometric check.

That distinction matters, but it is not absolute protection against fraud. A verifier still needs procedures for checking that the presenter is the credential holder, recognizing suspicious behavior and using approved reader software. The technology reduces some forgery risks; it does not eliminate the need for human judgment or security controls.

Adoption is growing, acceptance remains fragmented

A growing group of US states has issued mDLs or run deployment programs, through state apps, platform wallets or both. Outside the US, governments and regional initiatives are testing mobile credentials that overlap with driving licences, national identity credentials and future digital wallet frameworks. The direction of travel is clear, but rollout models, legal authority and technical profiles continue to vary.

Acceptance is the larger challenge. An mDL may be recognized at selected airport security checkpoints, participating retail locations or state services while remaining unusable at another airport, bank, car rental desk or police agency. Businesses need compatible readers, staff training, privacy policies and confidence that their process meets applicable age, consumer protection and recordkeeping rules.

Use cases extend beyond the checkpoint

Age assurance is among the most immediate uses because it can be limited to an over-age result. Airport identity checks are another visible application, although acceptance depends on the relevant security authority, airport and checkpoint. mDLs can also support online identity verification, where a website requests verified attributes from a holder's device.

Remote presentation is developing alongside proximity use. ISO/IEC 18013-7, a related standard, addresses remote mDL use cases. That distinction is significant: a standard designed for an in-person phone-to-reader exchange does not by itself settle how a website should authenticate a credential, prevent phishing or bind the credential to a particular online session.

The limits are technical, social and legal

An mDL depends on a working, charged device and accessible wallet software. People can lose phones, lack compatible hardware or choose not to use a smartphone credential. For the foreseeable future, physical licences remain necessary for broad inclusion and as a fallback. Readers, too, must be available and interoperable before the digital version can become routine.

Privacy is both an advantage and an unresolved concern. Selective disclosure can reveal less than a physical card, but a reader may still record transaction details, requested attributes or device-related information. Offline verification can reduce routine calls to a central issuer, yet logging practices are set by verifiers and governed by law and contract. Clear limits on collection, retention and sharing will be as important to public trust as cryptographic design.

By 2026, ISO 18013-5 is an important interoperability foundation, not a finished identity ecosystem. Its value lies in making trustworthy digital presentation possible across issuers and readers. Whether mDLs become commonplace will depend less on the existence of the standard than on consistent acceptance, accountable data practices and usable alternatives for people who cannot or do not want to rely on a phone.

More in Technology

Is My Passport Biometric?Technology

Is My Passport Biometric?

Most passports issued in recent years are biometric, but the quickest way to tell is not the photo page. Look for the small international chip symbol on the cover and understand what it can, and cannot, verify at the border.

Elena Marsh ·
eKYC: How Remote Onboarding Replaced the Branch VisitTechnology

eKYC: How Remote Onboarding Replaced the Branch Visit

Electronic know-your-customer, or eKYC, has shifted account opening from the branch counter to a smartphone screen. Its spread reflects not only better software, but also the identity infrastructure and laws that make remote verification possible.

Elena Marsh ·
Reusable Identity: The Push to Verify Once and Use EverywhereTechnology

Reusable Identity: The Push to Verify Once and Use Everywhere

Reusable identity promises to let people prove facts such as age, address or professional credentials without repeatedly handing over documents. The model could reduce fraud and friction, but it also raises hard questions about interoperability, privacy and who controls the wallet.

Elena Marsh ·