RETROSPECTIVE RECORD · PREPARED 16 SEPTEMBER 2026The archive · 198 retrospective records ↗
Screen Method

The archive / Evidence & limits

Evidence & limits / Craft note · Note note · prepared 16 September 2026

A C2PA trust list, not a marketing phrase, proves conformance

The C2PA's own conformance program and versioned specification define what generators and validators must do, and who has actually passed.

c2pa.orgprimary record

C2PA - Conformance

Document
undated document
Event
no single event
Retrieved
16 September 2026
No visual was published with this record, so its primary document stands in its place.

The shot

As retrieved on 16 September 2026, the Coalition for Content Provenance and Authenticity's own conformance page states that its Conformance Program and an official C2PA Trust List 'were launched in mid-2025,' replacing an Interim Trust List the coalition calls 'a temporary measure for early C2PA implementations.' The program covers generator products, validator products and certification authorities. Alongside it, the coalition's Content Credentials specification lists its own version history, dating version 2.3 to December 2025.

What the documents show

The conformance page describes the program, in its own words, as 'a risk-based, transparent and unbiased governance process intended to hold generator products, validator products and certification authorities accountable to the Content Credentials specification, the Certificate Policy and the Security Requirements,' with conforming products placed on 'a publicly-accessible list.' That is the coalition's account of its own governance, not a claim that every product mentioning 'Content Credentials' has passed it; only entries on the published lists carry that status. The specification's own changelog states 2.3 'introduces several new features,' including live-video-streaming support, expanded embedding for additional audio and text file types, new external-reference assertions for cloud-stored data, and refinements to how actions such as watermarking are recorded.

The workflow

The two documents describe different jobs. The specification defines what a claim generator must do when writing a manifest — such as not writing deprecated constructs for its declared version and preserving existing provenance when an asset is modified — and what a validator must do when reading one, including supporting every non-deprecated construct for its declared version and validating signatures, assertions and content bindings before presenting results to a user. The Conformance Program is the separate governance layer checking whether a shipped product actually does this. The coalition's own migration plan states the Interim Trust List ran with a disclaimer through 31 December 2025 and was frozen to new entries on 1 January 2026, so a product's trust status depends on which list and specification series it was assessed against.

What the tool does not change

This is editorial: a specification stating what a conforming implementation must do is not proof a specific camera, app or platform passed conformance testing, and the coalition's own materials point a reader to the published lists rather than a vendor's marketing claim. Appearing on a trust list also does not certify that content is accurate or unmanipulated — only that cryptographic and structural requirements were met.

  • Does the product in question appear on the C2PA's own Conforming Products List or Trust List, rather than only using the words 'Content Credentials' in marketing?
  • Which specification series, 1.x or 2.x, is the tool's output built against, given the coalition's stated push to retire 1.x-era trust certificates?
  • If a manifest predates the Interim Trust List's freeze on 1 January 2026, does the receiving platform still treat it as trusted, and under what disclaimer?

The conformance program and the versioned specification are two layers of the same system: one defines requirements, the other checks who actually meets them. A claim of 'C2PA support' is only as strong as which list and which version it can be traced to.

Sources & reading trail

C2PA - Conformance ↗

The C2PA's own description of its Conformance Program, the Trust List launched in mid-2025, and the retirement schedule for the Interim Trust List.

Source published: Not established · Retrieved: 16 September 2026

Content Credentials: C2PA Technical Specification (Version 2.3) ↗

The specification's own version-history entry dating 2.3 to December 2025 and listing claim generator and validator requirements.

Source published: 1 December 2025 · Retrieved: 16 September 2026

Documentation, agreements and rulings establish the note; the workflow reading is Screen Method editorial analysis. This retrospective draft does not imply the site published on the event date.