Annex A: Complete Requirements Index

Req ID Domain Cite Description
SEDI-BOR-01 BOR 101(1) Identity is innate and inalienable
SEDI-BOR-02 BOR 101(2) Right to management and control
SEDI-BOR-03 BOR 101(3) Right to physical identity
SEDI-BOR-04 BOR 101(4) Right to not be compelled to use digital
SEDI-BOR-05 BOR 101(5) Right to endorsement on uniform standards
SEDI-BOR-06 BOR 101(6) Right to legislatively established standards
SEDI-BOR-07 BOR 101(7) Right to transparency
SEDI-BOR-08 BOR 101(8) Right to choose disclosed attributes
SEDI-BOR-09 BOR 101(9) Right to service regardless of format
SEDI-BOR-10 BOR 101(10) Right to freedom from surveillance
SEDI-BOR-11 BOR 101(11) Right to not surrender device
SEDI-PRG-01 PRG 202(2) SEDI issuance compliance
SEDI-PRG-02 PRG 202(3)(a)(ii)(A) Publish technical standards
SEDI-PRG-03 PRG 202(3)(a)(ii)(B) Data governance standards
SEDI-PRG-04 PRG 202(3)(b)(i) 45-day public comment period
SEDI-PRG-05 PRG 202(3)(b)(ii) Response to public comments
SEDI-PRG-06 PRG 202(5)(a) Fee structure publication
SEDI-PRG-07 PRG 202(6) Annual program reporting
SEDI-PRG-08 PRG 203(2) Program manager qualifications
SEDI-PRG-09 PRG 204(1) Interagency coordination
SEDI-PRG-10 PRG 204(2) Use case development
SEDI-PRG-11 PRG 204(3) Coordination standards and guidance
SEDI-SDI-01 SDI 301(1)(a) Compromise detection
SEDI-SDI-02 SDI 301(1)(a) Recovery mechanisms
SEDI-SDI-03 SDI 301(1)(a) Cross-context correlation protections
SEDI-SDI-04 SDI 301(1)(b) Authenticity and integrity
SEDI-SDI-05 SDI 301(1)(c) Interoperability
SEDI-SDI-06 SDI 301(1)(d) Online and offline presentation
SEDI-SDI-07 SDI 301(1)(e)(i) Selective disclosure
SEDI-SDI-08 SDI 301(1)(e)(ii) Age verification without disclosure
SEDI-SDI-09 SDI 301(1)(f) Wallet choice
SEDI-SDI-10 SDI 301(1)(g) Usability
SEDI-SDI-11 SDI 301(2)(a) Identity proofing validation
SEDI-SDI-12 SDI 301(2)(b) Technological compliance mandate
SEDI-SDI-13 SDI 301(2)(c) State data center requirement
SEDI-SDI-14 SDI 301(2)(d) Data center best practices
SEDI-SDI-15 SDI 301(2)(e) Open standards mandate
SEDI-SDI-16 SDI 301(2)(f) Endorsed attribute set
SEDI-SDI-17 SDI 301(3) Anti-surveillance
SEDI-SDI-18 SDI 301(4)(a) Purpose limitation
SEDI-SDI-19 SDI 301(4)(b) Individual authorization
SEDI-SDI-20 SDI 301(4)(c) Retention limitation
SEDI-SDI-21 SDI 301(4)(d) In-state data storage
SEDI-SDI-22 SDI 301(4)(e) Disclosure restrictions
SEDI-SDI-23 SDI 301(5) Revocation constraints
SEDI-SDI-24 SDI 301(6) Breach reporting
SEDI-APP-01 APP 302(1) Age and emancipation eligibility
SEDI-APP-02 APP 302(2) Guardian consent for minors
SEDI-APP-03 APP 302(3) Guardian-initiated applications
SEDI-APP-04 APP 302(5) No mandatory enrollment
SEDI-APP-05 APP 302(6) Three eligibility criteria
SEDI-APP-06 APP 302(7)(a) Data minimization in application
SEDI-APP-07 APP 302(7)(b) Enumerated data collection fields
SEDI-IDP-01 IDP 303(1)(a)(i) Follow accepted proofing standard
SEDI-IDP-02 IDP 303(1)(a)(ii) Risk-commensurate proofing
SEDI-IDP-03 IDP 303(1)(a)(iii) Privacy-consistent proofing
SEDI-IDP-04 IDP 303(1)(b) Four verified assertions
SEDI-IDP-05 IDP 303(1)(c)(i) Sufficient for age assurance reliance
SEDI-IDP-06 IDP 303(1)(c)(ii) Online and offline suitability
SEDI-IDP-07 IDP 303(1)(d) Point-in-time endorsement
SEDI-APP-08 APP 303(2)(b) Fraud prohibition
SEDI-IDP-08 IDP 303(3)(a) Independence from physical ID system
SEDI-IDP-09 IDP 303(3)(b) No physical document surrender
SEDI-IDP-10 IDP 303(4)(b)(ii)(A) Multiple proofing methods
SEDI-IDP-11 IDP 303(4)(b)(iv) Proofing entity authorization
SEDI-GOV-01 GOV 304(1)(a) No material benefit for SEDI use
SEDI-GOV-02 GOV 304(1)(b) No service withholding for physical ID
SEDI-GOV-03 GOV 304(1)(c) No device surrender
SEDI-GOV-04 GOV 304(2)(a) New systems must accept SEDI
SEDI-GOV-05 GOV 304(2)(b) Technical infeasibility exemption
SEDI-GOV-06 GOV 305(1) Health care provider SEDI acceptance
SEDI-GOV-07 GOV 305(2) Health care infeasibility exemption
SEDI-WAL-01 WAL 401(1)(a) Identity protection safeguards
SEDI-WAL-02 WAL 401(1)(b) Secure attribute processing
SEDI-WAL-03 WAL 401(1)(c) Technological compliance
SEDI-WAL-04 WAL 401(1)(d) Tamper resistance
SEDI-WAL-05 WAL 401(1)(e) Online and offline presentation
SEDI-WAL-06 WAL 401(1)(f) Secure presentation log
SEDI-WAL-07 WAL 401(1)(g)(i) Selective disclosure
SEDI-WAL-08 WAL 401(1)(g)(ii) Age predicate proof
SEDI-WAL-09 WAL 401(1)(h) Guardian presentation
SEDI-WAL-10 WAL 401(2)(a) Attribute processing limitation
SEDI-WAL-11 WAL 401(2)(b) Conspicuous notice
SEDI-WAL-12 WAL 401(2)(c) Per-transaction consent
SEDI-WAL-13 WAL 401(3)(a) Primary purpose limitation
SEDI-WAL-14 WAL 401(3)(b) No unauthorized retention or sharing
SEDI-WAL-15 WAL 401(4) Utah data protection law compliance
SEDI-VER-01 VER 501(1)(a) Identity protection safeguards
SEDI-VER-02 VER 501(1)(b) Technological compliance
SEDI-VER-03 VER 501(1)(c) Secure attribute processing
SEDI-VER-04 VER 501(1)(d) Minimum attribute processing
SEDI-VER-05 VER 501(1)(e) Accept guardian presentations
SEDI-VER-06 VER 501(2) Four-condition processing gate
SEDI-VER-07 VER 501(3) No device surrender
SEDI-VER-08 VER 501(4) Utah data protection law compliance
SEDI-RPY-01 RPY 601(1)(a) Identity protection safeguards
SEDI-RPY-02 RPY 601(1)(b) Technological compliance
SEDI-RPY-03 RPY 601(1)(c) Secure attribute processing
SEDI-RPY-04 RPY 601(1)(d) Minimum attribute processing
SEDI-RPY-05 RPY 601(1)(e) Accept guardian presentations
SEDI-RPY-06 RPY 601(2) Four-condition processing gate
SEDI-RPY-07 RPY 601(3) No device surrender
SEDI-RPY-08 RPY 601(4) Permissive SEDI acceptance
SEDI-RPY-09 RPY 601(5) Utah data protection law compliance
SEDI-LOY-01 LOY 701(1) No conflicting practices
SEDI-LOY-02 LOY 701(2) No exploitation of individuals
SEDI-LOY-03 LOY 701(3) No disproportionate risk
SEDI-LOY-04 LOY 701(4) No detriment
SEDI-LOY-05 LOY 701(5) No harm
SEDI-PRC-01 PRC 702(1) Purpose-limited record processing
SEDI-PRC-02 PRC 702(2)(a) Primary purpose limitation
SEDI-PRC-03 PRC 702(2)(b) Notice and consent for secondary use
SEDI-ENF-01 ENF 801(1) Complaint submission mechanism
SEDI-ENF-02 ENF 801(4) Attorney general enforcement support
SEDI-ENF-03 ENF 802(1) Legislative audit
SEDI-ENF-04 ENF 802(2)(b) Anti-surveillance architectural proof
SEDI-ENF-05 ENF 802(3)(a) Audit report deadline
SEDI-CRY-01 CRY 201(4) Non-callback signature verification
SEDI-CRY-02 CRY 201(20) Holder-controlled key binding
SEDI-CRY-03 CRY 301(1)(e)(i) Selective disclosure and predicate proofs
SEDI-CRY-04 CRY 301(2)(e) Open, royalty-free algorithms
SEDI-CRY-05 CRY 301(2)(e) Cryptographic agility
SEDI-PRV-01 PRV 301(1)(a) Protocol-level unlinkability
SEDI-PRV-02 PRV 301(1)(e)(ii) Leak-resistant predicate evaluation
SEDI-PRV-03 PRV 301(3) Architectural anti-surveillance
SEDI-PRV-04 PRV 301(4) Lifecycle data minimization
SEDI-INT-01 INT 301(2)(e) Open standards for protocols and APIs
SEDI-INT-02 INT 301(1)(d) Common format across presentation modes
SEDI-INT-03 INT 301(2)(g)(i)(E) Wallet portability
SEDI-INT-04 INT 301(1)(c) No privacy-degrading fallback
SEDI-KMS-01 KMS 301(1)(a) Key lifecycle policy
SEDI-KMS-02 KMS 301(1)(a) Key generation ceremonies
SEDI-KMS-03 KMS 301(1)(a) Hardware security modules
SEDI-KMS-04 KMS 301(1)(a) Key rotation
SEDI-KMS-05 KMS 301(1)(a) Key compromise response
SEDI-ORG-01 ORG 301(2)(b) Access management
SEDI-ORG-02 ORG 301(2)(b) Personnel security
SEDI-ORG-03 ORG 301(2)(b) Vulnerability management
SEDI-ORG-04 ORG 301(2)(b) Logging and monitoring
SEDI-ORG-05 ORG 301(1)(a) Incident response
SEDI-ORG-06 ORG 301(2)(b) Third-party compliance
SEDI-ORG-07 ORG 301(2)(b) Change management

Total: 142 requirements