C2PA Conformance Explorer: vet your signer before promising credential

Before you promise clients C2PA Content Credentials, look your signing tool up in the C2PA Conformance Explorer. What it lists and how IPTC used it in 2026.

5 min readSume
All posts

Before you promise a client C2PA Content Credentials on delivered video, look your signing tool up in the C2PA Conformance Explorer. It is the public directory of conforming products and the official trust lists, and a tool that is not listed has not passed the conformance program, whatever its marketing says.

I read the Conformance Explorer page, the trust-lists page and IPTC's April 2026 announcement on 2026-10-02. The explorer page is thin as text, so I describe only what it states: product listings, trust lists, lookup and field documentation.

What does the explorer give you?

It works as a reference for the C2PA conformance landscape: which products meet the spec, the trust lists that govern validation, and documentation of the fields. The trust-lists page says it provides readable access to both official trust lists for transparency.

That makes it a procurement check. Ask a vendor, or yourself, whether the product that will sign your file appears there, and which certificate authority sits behind it.

What did IPTC show in 2026?

IPTC announced on 14 April 2026, at its Spring Meeting in Toronto, that its WordPress Signing Tool achieved C2PA Conformance. It also released an updated version of its Origin Verify validator. The announcement says news organizations can obtain signing certificates from several authorities, naming Trufo, SSL.com, GlobalSign and DigiCert.

The point for a video team is that conformance is a process a tool goes through, and that signing tools and validators are separate products.

Signing versus validating (read 2026-10-02)
RoleExample from the sourcesWhat to check
Signing toolIPTC WordPress Signing ToolListed as conforming; certificate chains to the official list
ValidatorIPTC Origin VerifyShows which trust list it used
Certificate authorityTrufo, SSL.com, GlobalSign, DigiCertNamed as certificate sources in the IPTC announcement

Where does Sume fit?

Sume's docs describe what each tool returns and say nothing about a watermark or embedded provenance record on outputs, so treat the output as unmarked until you have checked the delivered file yourself. Sume is not listed in anything I read as a C2PA signer, and I do not claim it is one.

A realistic video pipeline is: generate with Sume, finish edits with Timeline 1.0 or other steps, download the final MP4, and sign it with a conforming tool last. Keep the job id from Jobs and results as your own origin record.

What can go wrong if you skip the check?

A signing step that does not chain to an official trust anchor produces a manifest that validators can read but cannot vouch for. The client sees a warning on a file you described as credentialed, and you are explaining certificate chains to a marketing team.

There is also a timing risk. The trust-lists page says the Interim Trust List froze on 1 January 2026, so a tool that depended on it for new certificates may have stopped being a valid path. Asking the vendor whether it moved to the official list is a one-line email that avoids that surprise.

Finally, separate the promise from the product. Even a conforming tool only signs what you give it. If a later step re-encodes the file, the manifest can be lost, so the commitment you make to a client should name the final file, not the generation step.

Procurement checklist

Use this as a working list and adjust it to your own pipeline and counsel's advice.

  • Find the product in the explorer.
  • Ask which trust-list certificate it uses.
  • Sign after the last edit, never before.
  • Validate the delivered file with a tool that names its trust list.
  • Tell clients plainly that a credential proves who signed, not that content is real.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume