Skip to main content

Renew an intermediate certificate

Your intermediate sub-CA certificate is valid for the duration of your time as a registered Digital Verification Service (DVS) on the trust framework. Its expiry date is linked to the expiry date of your certificate of conformity from your conformity assessment body (CAB).

You must renew your intermediate sub-CA certificate to continue consuming and verifying credential data. You’ll need to create and send a new Certificate Signing Request (CSR) to your engagement manager to start the renewal process.

CSR requirements

You will need to create and send a new CSR to your engagement manager. It must contain the same:

  • immutable serialNumber UUID
  • CommonName unless you’ve changed your legal business name

GOV.UK Wallet also recommends you generate a new cryptographic key pair to reduce long-term cryptographic risk.

Transitioning between certificates

You may use multiple intermediate sub-CA certificates while transitioning between old and new intermediate certificates. Once your old certificate has expired, you can only use your new certificate to issue verifier certificates as a CA.

This page was last reviewed on 14 July 2026. It needs to be reviewed again on 14 January 2027 by the page owner #di-mobile-wallet-tech-docs .