Structural Reform
This appendix describes the citizen-facing digital identity system operated by the National Digital Service (NDS). It should be read alongside the companion appendix — NDS: Core Infrastructure — which describes the NDS's institutional design, governance, citizen rights regime (including cryptographic rights, audit trail, and organisational identity), physical infrastructure, and combined budget.
The NDS is a permanent national institution established by the National Digital Service Act, governed by an independent commission accountable to Parliament. The identity system described here is one of its two operational arms; the other is the National Data Infrastructure on which the identity system runs. The governance framework, the citizen's cryptographic entitlement, the audit trail that makes all access visible, and the organisational identity register that ensures two-sided accountability at every tap — these are set out in the Core Infrastructure appendix and apply to everything described below.
Context of UK Identity
The UK has been attempting digital identity for a quarter of a century. From the Government Gateway in 2001 through GOV.UK Verify, successive governments pursued a broadly consistent policy of outsourcing identity assurance to accredited private providers, with near-identical policy statements recurring in 2000, 2011 and 2018; Fishenden (2020) describes the period as "a circular and repetitive odyssey" in which the same lessons were repeatedly relearned. The one statutory departure, the Identity Cards Act 2006 and its national identity register, was repealed by the incoming coalition in 2010 (Clark and McKinney, 2026). Verify, live from 2016, missed every target in its business cases: 3.6 million users against 25 million, 19 connected services against 46, and a 48% verification success rate against a 90% forecast, on a cost of at least £154 million (NAO, 2019). Its commercial verification could not reach people with thin commercial data footprints, and the cost of exclusion flowed back to the state: only 38% of Universal Credit claimants could verify online, and DEFRA reverted to manual registration for rural payments (Whitley, 2018; NAO, 2019). GOV.UK One Login, replacing more than 190 separate departmental login systems, has since re-established a single public identity platform, and in September 2025 the government announced a national digital ID scheme, built in-house with no centralised database, whose initially mandatory right-to-work element was withdrawn after a public backlash including a parliamentary petition of almost three million signatures (Clark and McKinney, 2026).
The identity service described in this appendix is designed against that history: publicly operated rather than outsourced, funded for inclusion rather than surprised by its cost, and bounded by the citizen rights regime in the companion appendix rather than by ministerial assurance.
Assumed state: January 2030
The programme assumes that by the start of 2030, the UK government's existing digital identity programme will have achieved the following baseline — consistent with current trajectories and announced plans.
GOV.UK One Login will have reached approximately 30–35 million verified accounts, covering roughly 55–65% of UK adults. The GOV.UK Wallet will be operational with digital driving licences and a small number of other government-issued credentials. The UK Digital Identity and Attributes Trust Framework (DIATF), placed on statutory footing by the Data (Use and Access) Act 2025, will have 50+ certified private-sector identity verification providers operating commercially. The NFC contactless payment terminal network — approximately 1.3 million devices across the UK, already handling over 85% of in-store transactions — will provide the physical infrastructure upon which tap-to-ID functionality can be built.
The programme further assumes that the national digital ID scheme announced in 2025 and consulted upon in 2026 will have been legislated on a voluntary basis, with the core identity verification architecture operational but adoption still patchy — particularly among older adults, digitally excluded populations, and those without existing photo identification. Approximately 3–4 million adults will still lack any form of verified digital identity, concentrated among the over-75s, people with disabilities, the homeless, care home residents, and undocumented migrants.
The critical gap at the start of 2030 is not technology but coverage and utility. The infrastructure exists; what it lacks is the combination of universal reach and compelling everyday use cases that drives adoption from 60% to 95%. The Prosperity 2030 programme provides both: a political mandate to accelerate inclusion and a suite of universal services that give every resident a concrete reason to hold a digital identity.
The five-year plan: 2030–2035
The programme targets 95% verified digital identity coverage among UK adults by Year 5 (2035), with 85% coverage by Year 2 (2031) sufficient to support the initial rollout of universal services.
Year 1 (2030): Foundation. The first year focuses on three workstreams. First, accelerating One Login enrolment toward 40 million accounts through integration with the programme's universal service registrations — every household that registers for the energy USO, water USO, or Universal Digital Service simultaneously creates or links a verified digital identity. Second, deploying the tap-to-ID protocol on the existing contactless payment terminal network, beginning with public transport operators and school meal systems where the infrastructure is already NFC-enabled. Third, establishing assisted digital identity verification at every Post Office, Citizens Advice location, and Jobcentre Plus site — approximately 15,000 locations nationally — to provide in-person enrolment for the 8–10 million adults who cannot or will not complete online verification.
Year 2 (2031): Service launch. The second year coincides with the launch of the first universal services and is the critical adoption milestone. The tap-to-ID system goes live across all universal bus services, Community Food Centres, school meal systems, and participating food venues. Every person aged 6 and over — the Universal Digital Service eligibility threshold — receives a digital identity token, either as a smartphone wallet credential or as a physical NFC card for those without compatible devices. The physical card programme is essential: approximately 5–7 million adults and a significant proportion of children will require a contactless card rather than a smartphone credential, at an estimated cost of £8–12 per card including personalisation, encoding, and logistics. NFC cards carry two key pairs following the Estonian model — one for authentication and one for digital signature — with keys generated inside the card's secure element.
Year 3 (2032): Deepening. Coverage reaches approximately 90% of adults. The remaining unenrolled population is disproportionately hard-to-reach: care home residents, rough sleepers, people with severe cognitive impairments, and undocumented migrants. Year 3 focuses on proxy and delegated identity — allowing carers, social workers, and family members to manage digital identity credentials on behalf of those who cannot manage their own. The participating venue network expands, and the tap-to-ID credential becomes accepted for age verification, library access, NHS appointment check-in, and local authority service access. The organisational identity register reaches full coverage of programme-participating entities and opens to the wider private sector.
Year 4 (2033): Maturity. Coverage reaches approximately 93–94%. The focus shifts to operational efficiency and cost reduction. The identity verification process becomes increasingly automated as the biometric database matures; re-verification costs fall. The physical NFC card refresh cycle begins for Year 2 cards approaching expiry. Private-sector acceptance expands — DIATF-certified providers integrate tap-to-ID verification into commercial services, reducing government subsidy requirements.
Year 5 (2034–35): Near-universal. The target of 95% coverage is reached — approximately 51 million adults with verified digital identities, plus age-appropriate credentials for the approximately 10 million children aged 6–17. The remaining 5% comprises individuals who actively decline (voluntary system), those in transient circumstances, and a small residual of people whom the system has been unable to reach.
Tap-to-ID: how it works
The NDS's tap-to-ID system repurposes the UK's existing contactless payment infrastructure — the same NFC terminals, readers, and protocols that currently process approximately 20 billion contactless transactions per year — for identity verification and service access.
The user holds a digital identity credential, stored either in the GOV.UK Wallet app on a smartphone (using the device's NFC capability, identical to Apple Pay or Google Pay) or on a physical NFC card issued by the NDS. On tapping, the terminal reads a cryptographically signed identity token that confirms one or more of: the holder's verified identity, their age band (for age-gated services), their household registration (for household-linked entitlements), and their service eligibility (for means-tested or category-specific services). No biometric data is transmitted at the point of tap. The transaction is logged against the service provider's allocation system, enabling real-time usage tracking for programme monitoring without requiring the user to present documents, complete forms, or authenticate beyond the physical tap.
The protocol operates at three assurance levels. Level 1 (presence only) confirms that the holder has a valid NDS credential — sufficient for universal bus boarding, library access, and community space entry. Level 2 (identity confirmed) additionally verifies the holder's name and age band — sufficient for school meal check-in, participating venue meals, and age-restricted service access. Level 3 (full identity with household) links the holder to their registered household and service entitlements — required for energy and water USO registration, Universal Digital Service device and voucher claims, and any means-tested service top-ups.
Every tap-to-ID transaction is a two-sided credential exchange. The citizen's wallet presents their identity credential; the terminal presents the service provider's organisational credential. Both sides are cryptographically verified. The citizen's wallet can log which organisations have verified their identity, and the NDS gateway records the organisational credential alongside the access event in the audit trail. This means a citizen reviewing their audit log sees not just "accessed by Greggs" but "accessed by Greggs plc (Company No. 00502851), terminal ID 4471, responsible officer J. Smith."
How universal services use tap-to-ID
Public transport. The tap replaces both fare payment and eligibility verification in a single gesture. The bus operator's existing electronic ticket machine — already NFC-enabled for contactless payment — reads the NDS credential at Level 1 and registers a boarding event. No fare is charged. The operator claims reimbursement from the programme based on verified boarding counts.
Community Food Centres and school meals. A tap at the serving point confirms identity (Level 2) and logs the meal. For school meals, the child's credential — linked to a parent or guardian's verified identity, carrying the child's age band and school enrolment status — provides automatic check-in. No child needs to be identified as receiving a free meal; every child taps the same way.
Participating food venues. The example of Greggs illustrates the model. The venue's existing point-of-sale terminal is updated with the tap-to-ID protocol via a software update to its payment processing system. A customer taps their card or phone; the terminal confirms eligibility (Level 2: verified identity, eligible age/category); the meal is served; the venue submits a reimbursement claim against the programme's participating venue allocation. The customer experience is identical to a contactless payment — tap, confirmation beep, done. No cash changes hands, no voucher is presented, no visible distinction exists between a programme-funded meal and a paid one. This is a deliberate design choice: the system must not stigmatise users.
Energy and water USOs. Registration for standing-charge-free energy and water requires a Level 3 tap or online verification linking the credential to the household's meter point. Once registered, the household's standing charges are absorbed by the programme without further interaction.
Universal Digital Service. Each eligible person receives a voucher code linked to their digital identity. The voucher is redeemed with any participating mobile operator; the operator verifies eligibility via the NDS and applies the credit. Device provision follows the same identity-linked process: eligibility is confirmed, and a device is dispatched or collected from a distribution point.
Children's credentials. For children aged 6–17, a simplified digital identity is issued — linked to a parent or guardian's verified identity — that carries the child's age band and school enrolment status. This enables school meal check-in, age-appropriate transport access, and Universal Digital Service device/voucher claims without requiring the child to complete adult-level identity verification. The child's credential is managed through the parent's GOV.UK Wallet until the child reaches 16, at which point they transition to an independent adult credential.
The citizen's wallet as a lifetime credential store
The NDS wallet is designed to hold more than identity and service entitlements. The same cryptographic architecture — W3C Verifiable Credentials, citizen-controlled keys, selective disclosure — supports a broader set of credentials that accumulate over a citizen's lifetime.
Skills and qualifications. The GOV.UK Wallet already uses the W3C Verifiable Credentials Data Model 2.0. The EU's European Digital Credentials for Learning initiative has demonstrated that educational qualifications, professional certifications, and micro-credentials can be issued as verifiable credentials and stored in citizen wallets. The UK Badging Commission's 2025 report recommended a national skills wallet linked to GOV.UK One Login, populated initially with school-leaving qualifications and available for lifelong use. The NDS provides the infrastructure for this: a citizen's GCSE results, university degree, professional registrations, and employer-issued skill badges can sit alongside their driving licence and NDS identity credential in a single wallet, presented selectively to employers, training providers, or public services as the citizen chooses.
Personal data and AI portability. As AI systems increasingly personalise services — from NHS triage bots to career guidance to energy usage recommendations — they build profiles of individual preferences, behaviour patterns, and expressed values. Without sovereign infrastructure, these profiles are owned by whichever AI provider built them, locked inside proprietary systems, and unavailable to the citizen who generated them. The NDS wallet, combined with the citizen's cryptographic keys, provides the mechanism for portable, citizen-controlled personal data. A citizen can encrypt their AI interaction history, preference vectors, and derived personality profiles to their own keys, store them in their wallet or a linked personal data store, and grant time-limited access to any service provider — carrying their digital context between services rather than starting from scratch with each new provider. This is not a speculative ambition; the technical standards exist (W3C Verifiable Credentials, Solid data pods, the Data Transfer Initiative's portability framework), and the EU's eIDAS 2.0 regulation mandates wallet-based selective disclosure. What is missing is the sovereign infrastructure to host and protect it. The NDS provides that infrastructure.
Budget
The Digital Identity budget totals £4.50 billion over five years: £0.50 billion in Year 1 and £1.00 billion per year in Years 2–5. The combined NDS budget (Digital Identity plus National Data Infrastructure) is £12.50 billion, presented in the companion Core Infrastructure appendix.
Digital Identity budget detail
All figures in £ billions, 2025 prices.
| Component | Year 1 | Year 2 | Year 3 | Year 4 | Year 5 | Total |
|---|---|---|---|---|---|---|
| Terminal protocol and tap-to-ID deployment | 0.20 | 0.25 | — | — | — | 0.45 |
| Assisted verification infrastructure | 0.15 | — | — | — | — | 0.15 |
| NFC card production, distribution, and refresh | — | 0.35 | 0.05 | 0.35 | 0.25 | 1.00 |
| Enrolment acceleration and service integration | 0.10 | — | 0.25 | 0.20 | — | 0.55 |
| Backend identity resolution and fraud prevention | — | 0.20 | 0.25 | 0.15 | 0.20 | 0.80 |
| Inclusion outreach and proxy identity systems | — | 0.10 | 0.30 | — | 0.15 | 0.55 |
| Operational running costs and service desk | — | 0.10 | 0.15 | 0.30 | 0.40 | 0.95 |
| Security, testing, and contingency | 0.05 | — | — | — | — | 0.05 |
| Digital Identity total | 0.50 | 1.00 | 1.00 | 1.00 | 1.00 | 4.50 |
The Digital Identity budget follows a capital-to-operational curve: Year 1 is predominantly capital (terminal deployment, assisted verification infrastructure setup), while Years 4–5 are predominantly operational (card refresh, running costs, ongoing inclusion). NFC cards carrying two key pairs (following the Estonian model) cost approximately £1–2 more per card than single-key cards; this is absorbed within the £1.00 billion card production line. At steady state beyond Year 5, digital identity operations require approximately £1.00 billion per year, funded from the programme's fiscal space.
International benchmarks support the budget's scale. The total Digital Identity spend of £4.50 billion across five years is approximately £83 per UK adult — substantially above India's Aadhaar cost of £1–5 per person but consistent with the UK's higher labour costs, privacy-by-design architecture, physical NFC card programme, and the inclusion infrastructure required to reach the 8–10 million adults who cannot complete online verification. It is roughly 2.5 times the OBR's 2025 estimate of £1.80 billion for the government's own national digital ID scheme, reflecting the programme's more ambitious 95% coverage target, the tap-to-ID terminal deployment across approximately 1.3 million NFC terminals, and the physical card programme for digitally excluded populations.
The budget also prices in the documented failure modes of previous UK identity programmes. Verify's benefits case was revised down 75%, from £873 million to £217 million, and the NAO could not validate even the reduced figure; no equivalent benefits case is made here, and no administrative savings are netted against this budget. Verify's exclusion costs flowed straight back to departments, with DWP expecting around £40 million of manual verification costs over ten years; the assisted verification and inclusion outreach lines (£0.70 billion combined) exist because that record shows unfunded inclusion is not avoided cost but displaced cost. Verify's provider prices were also forecast to fall with volume and never did, remaining above £20 per verified identity. The decision to operate verification as a public service on public infrastructure, rather than purchase it per head from commercial providers, is a direct response to that experience.
The OBR's £1.80 billion estimate was rejected by the government as dependent on design choices not yet made, and the Commons Science and Technology Committee has criticised the absence of answers on cost. This appendix publishes a full five-year budget by component precisely so the programme's cost claims can be examined. For scale, the certified private digital verification sector already generates £2.10 billion a year in revenue under the trust framework; a £1.00 billion a year public identity service is not out of proportion to what the economy already pays for verification, and it does not displace that market, which continues to serve commercial use cases under DIATF certification.
References
Clark, A. and McKinney, C.J. (2026) Digital ID in the UK. Research Briefing CBP-10369. London: House of Commons Library. Available at: https://commonslibrary.parliament.uk/research-briefings/cbp-10369/ (Accessed: 16 July 2026).
Fishenden, J. (2020) Federated Identity for Access to UK Public Services: 1997–2020. An Overview. Available at: https://ntouk.wordpress.com/wp-content/uploads/2020/06/federated-identity-for-access-to-uk-public-services-1997-2020-jerry-fishenden-1.pdf (Accessed: 16 July 2026).
National Audit Office (2019) Investigation into Verify. HC 1926, Session 2017–2019. London: National Audit Office. Available at: https://www.nao.org.uk/reports/investigation-into-verify/ (Accessed: 16 July 2026).
Whitley, E.A. (2018) Trusted Digital Identity Provision: GOV.UK Verify's Federated Approach. Washington, DC: Center for Global Development. Available at: https://www.cgdev.org/publication/trusted-digital-identity-provision-gov-uk-verify-federated-approach (Accessed: 16 July 2026).
All figures in 2025 prices. Coverage targets assume a voluntary identity system; mandatory enrolment would accelerate adoption but is not proposed. The 95% target excludes individuals who actively decline participation and those in circumstances that prevent identity verification under current law. The citizen's cryptographic rights, the audit trail, and the organisational identity register — which govern all interactions described in this appendix — are established in the companion NDS: Core Infrastructure appendix.
Source: IGP Social Prosperity Network.