MOSIP is an open-source platform countries use to build foundational national identity systems, covering enrolment, biometrics, ID issuance, authentication, eKYC and credential management. It is a reference example of identity DPI: API-first, modular, privacy-engineered, and deployed or being deployed in the Philippines, Morocco, Sri Lanka, Ethiopia, Guinea, Togo and elsewhere.
All DPGs in the DPGs for DPI Collection are assessed by the DPGA Secretariat against the DPGs for DPI criteria v2.0. Assessments use publicly available documentation and link to their evidence below. Assessed September 2026.
Layer 1
Recognised DPG
Layer 2
DPI Relevance
Layer 3
DPI Architecture Alignment

Does it provide a foundational DPI function, reusable across sectors, at population scale?
It is a foundational national identity platform, the core of the Digital Identity domain. A national ID is used by every sector — banking, health, social protection, telecoms and government services — and the platform is deployed at country scale across several continents.
How the solution's architecture reflects the principles that distinguish DPI from conventional digitisation.
Can other systems connect without modifying the core, using documented open standards?
The design is API-first, with full RESTful API documentation and OpenAPI specifications for every module. Standards adoption spans FIDO2, OAuth 2.0, OpenID Connect, ISO 19794 biometrics, CBEFF and X.509 PKI, with JSON, CBOR and standard biometric formats exchanged against published schemas.
Is it a modular building block that does one thing well, rather than a monolithic platform?
A microservices architecture makes each module independently deployable and replaceable through technology bundles. The MOSIP platform core is clearly distinct from reference implementations and country-specific applications, and countries swap components through configuration rather than forking.
Can other public and private actors build on top of it?
A partner management system, APIs and SDKs support an ecosystem of biometric device vendors and system integrators, and multiple countries and technology partners build on the platform today. The MPL-2.0 licence, MOSIP Foundation governance and implementation partners across continents rule out single-vendor dependence.
Can it run in distributed or federated deployments suited to national infrastructure?
A cell-based architecture supports linear scaling and independent national instances across hybrid cloud or on-premise deployment. Data never leaves the jurisdiction by design, and the same cell-based approach is what delivers high availability without single points of failure.
Does it meet the security and privacy bar for population-scale infrastructure?
Security covers encryption at rest and in transit, role-based access control and comprehensive audit logging within a zero-knowledge architecture, backed by a dedicated security team, regular assessments and a responsible disclosure process. Privacy is engineered in through data minimisation, consent management, tokenisation and zero-knowledge proofs.
Criteria: DPGs for DPI Collection criteria v2.0 · Co-stewarded by CDPI, Co-Develop and the DPGA Secretariat.
Spot something out of date? Contact the DPGA