- $25 billion: Projected market size for Identity and Access Management (IAM) in 2026.
- 180+ countries: Global reach of SLC Digital’s SIM-based authentication technology.
- 20 years: CertiPath’s experience in high-assurance identity solutions.
Experts would likely conclude that this partnership represents a significant advancement in enterprise security by leveraging existing SIM/eSIM technology to create a phishing-resistant, hardware-rooted authentication system, potentially setting a new standard for digital identity management.
Your SIM Card Is Your New Fortress: The End of Passwords as We Know It?
RESTON, Va. and NEW YORK, Sept. 03, 2026 – In a move that could fundamentally reshape digital security, identity management firm CertiPath and mobile authentication specialist SLC Digital have announced a strategic partnership to transform the humble SIM card into a hardware-rooted key for the enterprise. The collaboration integrates CertiPath’s enterprise-grade TrustSuite identity platform with SLC Digital’s technology, which leverages the secure element within a phone’s SIM or eSIM to create a phishing-resistant digital credential.
This partnership aims to solve one of the most persistent vulnerabilities in cybersecurity: ensuring the person accessing a network is who they claim to be, long after their initial identity has been verified. By anchoring a vetted identity directly to a physical piece of hardware already in nearly every employee's pocket, the two companies are making a bold play to close the gap between high-assurance identity proofing and day-to-day authentication.
“This partnership brings together two complementary strengths,” said Jeff Nigriny, Founder and CEO of CertiPath, in the announcement. He explained that while CertiPath has spent two decades building platforms for high-assurance credentials, SLC Digital provides a “ubiquitous, hardware-rooted, low-friction way to bind a verified identity to a trusted mobile credential.” The goal, Nigriny added, is to “maintain confidence in who—and where—the user is thereafter.”
For enterprises grappling with the security paradox of a distributed workforce, this represents a significant shift. Instead of relying on vulnerable methods like passwords or SMS codes, authentication could soon be cryptographically tied to the one device that rarely leaves a user’s side.
Closing the Trust Gap in a Zero-Trust World
The modern enterprise operates without a traditional perimeter. The transition to remote work and cloud-based infrastructure has dissolved the old model of a secure internal network, giving rise to the “Zero Trust” security framework, which mandates the principle of “never trust, always verify.” Yet, this model is only as strong as the identity verification at its core. The market for Identity and Access Management (IAM) is exploding, projected to hit $25 billion in 2026, as organizations race to secure access in this new reality.
The critical challenge, which this partnership directly addresses, is the “trust gap.” An organization might spend significant resources vetting an employee or contractor during onboarding, but that high level of assurance degrades the moment they are issued a simple password and username. Sophisticated phishing attacks and credential theft can easily compromise these legacy credentials, leaving high-value systems exposed. The combined CertiPath and SLC Digital solution aims to bridge this gap by creating a persistent, hardware-bound link between the vetted person and their digital credential.
CertiPath provides the enterprise platform that manages the entire identity lifecycle—from initial proofing and onboarding to provisioning access to physical buildings and IT systems. At a critical point in that process, SLC Digital’s technology cryptographically binds that verified identity to the user's mobile SIM or eSIM. From that moment on, every authentication request isn't just a password check; it's a cryptographic challenge that only the specific, trusted device can answer. This provides ongoing “presence assurance”—a high-confidence signal that the legitimate user and their trusted device are present for the transaction.
From Passwords to Cryptographic Proof: How it Works
The security of the joint offering hinges on elevating the SIM card from a mere network access token to a full-blown hardware root of trust. Unlike credentials stored in software, which can be copied or stolen, the cryptographic keys used for authentication are generated and stored within the tamper-resistant secure element of the SIM/eSIM. They are designed to never leave the chip.
When a user attempts to log in, the system sends a unique challenge to the device. The SIM’s secure element uses its private key to sign this challenge, creating a cryptographic proof of possession that is sent back to the server for verification. This public-key cryptography model is inherently resistant to phishing, as any stolen credentials would be useless without the physical device to perform the signing operation. This stands in stark contrast to SMS-based one-time passcodes (OTPs), which can be intercepted, or push-notification fatigue attacks, which trick users into approving fraudulent logins.
While dedicated hardware security keys like YubiKeys offer a similar level of phishing resistance and are considered the gold standard by agencies like CISA, this partnership’s approach leverages the hardware people already carry. With SLC Digital's technology available across more than 180 countries, the solution offers a path to global scalability without the logistical overhead of distributing and managing a separate fleet of physical tokens.
“SLC Digital was founded to make hardware-rooted identity available on the device nearly every person already carries,” noted Travis M. McGregor, CEO and Co-Founder of SLC Digital. “By pairing our SIM-based authenticator and presence capabilities with CertiPath’s TrustSuite, organizations can finally close the loop between strong initial proofing, ongoing authentication, and presence assurance.”
The New Enterprise Standard for Physical and Digital Access
This partnership is about more than just secure logins; it’s about weaving a unified “Trust Fabric” across an entire organization. CertiPath has a 20-year history in the high-assurance identity space, notably as an operator of a bridge certification authority cross-certified with the Federal Bridge. This experience gives it a unique perspective on creating interoperable trust between different organizations and systems—a crucial capability for government and complex supply chains.
The integrated platform extends this philosophy by unifying physical and logical access. The same high-assurance identity anchored to an employee’s phone could be used to unlock their laptop, access a secure cloud database, and even open the door to a sensitive facility. This convergence is particularly critical for industries facing intense regulatory scrutiny and high stakes from fraud, such as government, banking, healthcare, and critical infrastructure.
For federal agencies and their contractors, this approach aligns with increasing mandates for stronger identity verification. For financial institutions, it offers a powerful tool to combat account takeover fraud. And for healthcare, it provides a robust method for protecting sensitive patient data while ensuring medical staff have seamless access.
As authentication technologies evolve, the platform is designed to be future-proof. By handling the complexity at the central identity layer, enterprises can consistently receive signed, high-assurance assertions for access decisions, regardless of the underlying method. This strategy promises to simplify security architecture while strengthening its foundation, building a future where digital trust is not just assumed but cryptographically proven.
Topics & Related
Zero Trust
📝 This article is still being updated
Are you a relevant expert who could contribute your opinion or insights to this article? We'd love to hear from you. We will give you full credit for your contribution.
Contribute Your Expertise →