If you read the spec sheet of any mobile driver's license wallet in the United States, you will find the same phrase: ISO 18013-5 compliant. Read the spec sheets of the verification products too, same phrase. From a distance it looks like a solved problem. Everyone speaks the same standard, so everything works with everything.
Then you put readers in front of real customers, and the field teaches you what the spec sheet leaves out. We verify mobile driver's licenses at more than 10,000 locations across 21 US states and territories, and the wallet support details behind that number are public on our In Production page. This post is about what that matrix taught us.
A standard full of options
ISO 18013-5 is a good standard. It is also, like every interoperability standard, a menu. Engagement can happen over a QR code or over NFC. NFC handover comes in negotiated and static variants. The data transfer channel is typically Bluetooth Low Energy, and there the wallet can act in central or peripheral mode. Every one of those choices is legal. Every combination you can construct from them exists in a shipping wallet today.
Compliance means a wallet picked options from the menu correctly. Interoperability means your reader handles every option every wallet actually picked. Those are different achievements, and only one of them is written on the box.
Engagement: the first fork in the road
The first thing we learned in the field is that you cannot assume how a credential will arrive.
Most state DMV wallets engage by QR code only. The holder opens the app, a QR code appears, the reader scans it. Apple Wallet sits at the other end of the spectrum: the holder taps the phone to the reader and engagement happens over NFC. Google Wallet and Samsung Wallet do both, QR and NFC, depending on the moment and the phone.
A verifier that only scans QR codes turns away every Apple Wallet tap. A verifier that only reads NFC turns away most DMV wallets. At the counter, both look identical to staff: the customer did the right thing and the reader did nothing. Supporting engagement is not a feature checkbox. It is table stakes for not stranding real users.
NFC handover: two dialects in production
Within NFC engagement there is a second fork. The handover that moves the session from the NFC tap to the Bluetooth channel comes in two variants, negotiated and static, and both are live in production wallets today. Apple Wallet and Google Wallet use negotiated handover. Samsung Wallet uses static handover.
A reader that speaks only one dialect passes every test you run against the wallet you tested, then fails in the field against the one you did not. This is the kind of detail no procurement document will ever ask about, and it decides whether a third of the phones in the room can present at all.
Bluetooth roles: who connects to whom
The third fork is the quietest one. Once the session moves to Bluetooth Low Energy, someone has to be the central and someone the peripheral. Most wallets in our matrix run in BLE central mode. But Utah's GET Mobile ID and Virginia's CBN wallet run in BLE peripheral mode, which flips the connection model at the radio level.
If your reader assumes one role, credentials from those states simply do not connect. Nothing errors loudly. The transfer just never starts. We learned to support both roles because customers from every state walk into stores in every other state, and a Virginia license needs to verify in Arizona just as reliably as it does at home.
The matrix is alive
Here is the deepest lesson: none of the above is static. Wallets update. Phone operating systems update. A wallet that engaged one way last quarter can behave differently after this quarter's release. Interoperability is not a milestone you pass once. It is a matrix you retest continuously, wallet by wallet, state by state, release by release.
That reframes what a verification vendor actually sells. The cryptography is necessary and it is the easy part. What you are really buying is the maintained matrix: the accumulated, continuously retested knowledge of how every production wallet actually behaves, and a commitment that when the matrix shifts, someone catches it before your customers do.
"Supports ISO 18013-5" is the beginning of that work. The other 10,000 locations of it come after.


