What the C2PA conformance registry actually lists
Content Credentials claims are checkable, because the conformance registry is a public file anyone can read.
What the C2PA conformance program certifies
The C2PA conformance program validates that a product adheres to the Content Credentials specification and meets a set of security requirements [1]. It covers three kinds of participant: generator products, which create Content Credentials; validator products, which read and check them; and certification authorities [1]. Conformance is therefore a statement about a specific product at a specific version, not a badge a company wears.
The useful consequence is that the result is published. The Conforming Products List is a JSON file in a public repository [2], which means a provenance claim can be checked rather than taken on trust, by the person relying on it, at the moment they need to rely on it.
What the registry contained on 29 August 2026
Retrieved on 29 August 2026, the list held 174 records, every one with a status of conformant [2]. Of those, 153 were generator products and 21 were validator products [2]. The registry is dominated by cloud services, editing tools and platform pipelines rather than cameras, which is worth knowing before reading anything into the handful of capture devices in it.
The capture devices and capture applications present, with the maximum assurance level recorded for each, were:
- Pixel Camera, Google, assurance level 2 [2]
- Snapdragon 8 Elite Gen 5, Qualcomm Technologies, assurance level 2 [2]
- Pixel Recorder, Google, assurance level 1 [2]
- Xiaomi Camera, assurance level 1 [2]
- vivo Camera and JOVI Camera, vivo Mobile Communication, assurance level 1 [2]
- Proofmode for Android and Proofmode for iOS, assurance level 1 [2]
- InReality Capture for Android and for iOS, assurance level 1 [2]
Assurance level is worth attending to, because it is not evenly distributed. Across all 174 records, 7 reached level 2, 146 were at level 1, and the 21 validator products carried no assurance level at all [2]. A reader evaluating a provenance claim should look at which level applies to the specific product that made it, rather than treating certification as a single undifferentiated status.
One detail is easy to miss and matters for how provenance will spread. Snapdragon 8 Elite Gen 5 is a mobile chipset rather than a finished camera [2]. Certification at that layer reaches every device built on the part, which is a different distribution mechanism from certifying one handset at a time.
Most of the registry is certified against an older specification
Specification version 2.4 is published, and the C2PA site points adopters at 2.3 [3]. The registry tells a slower story: of the 174 records, 166 were certified against specification 2.2, seven against 2.4, and one against both [2]. Published, recommended, and actually certified against are three different things, and only the third describes the software a reader will encounter in the wild.
Camera manufacturers listed as members but not in the registry
Canon Inc, Fujifilm Corporation, Leica Camera and Nikon Corporation are listed as C2PA general members [4]. None of the four appeared anywhere in the Conforming Products List as retrieved [2].
That fact needs stating carefully, because it is easy to over-read. Absence from the registry means no product from that manufacturer has been certified under the conformance program. It does not establish that a manufacturer has never shipped a Content Credentials feature in any product, and this article makes no claim about that. Certification and shipping are separate questions, and only the first is answered by the registry. Anyone who needs the second should ask the manufacturer about a specific model and firmware version.
How to check the registry yourself
The list is a single public JSON file in the C2PA conformance repository [2], so a claim about it is verifiable in about a minute without specialist tooling. Each record carries the applicant, the product name, the product type, the assurance level, the specification versions, the container formats the product can generate or validate, and dates for creation, conformance and last modification [2].
Two habits follow from that. First, when a product claims Content Credentials support, check whether it appears in the registry and at what assurance level, rather than accepting the marketing description. Second, when reading a claim about the registry, including this one, retrieve the file and confirm it, because the registry changes and any published summary of it is a snapshot with a date attached.
What the registry does not tell you
Conformance is not a statement that a given file's credentials are intact, that its signature validates, or that the content is truthful. It says a product met a specification and a set of security requirements at a point in time. A signed capture from a certified device still needs its manifest validated, and a credential can be absent for entirely innocent reasons, including an editing step that did not preserve it. Provenance narrows the question of where a file came from; it does not answer whether what the file depicts is true.
- What Content Credentials establish, and what they do not , what a credential proves before the registry means anything
- Synthetic media disclosure obligations now in force , the marking obligation this infrastructure is meant to satisfy
Sources
- [1]C2PA. Conformance Program.
- [2]C2PA. Conforming Products List, public registry, retrieved 29 August 2026.
- [3]C2PA. Technical specification index.
- [4]C2PA. Coalition for Content Provenance and Authenticity, membership and overview.
Common questions on this topic
Which capture devices are in the C2PA Conforming Products List?
As retrieved on 29 August 2026 the registry recorded Pixel Camera and the Qualcomm Snapdragon 8 Elite Gen 5 chipset at assurance level 2, and Pixel Recorder, Xiaomi Camera, vivo Camera, JOVI Camera, Proofmode for Android and iOS, and InReality Capture for Android and iOS at assurance level 1. The registry is a public JSON file and can be checked directly.
Does absence from the C2PA registry mean a camera has no Content Credentials support?
No. Absence means no product from that manufacturer has been certified under the conformance program. It does not establish that a manufacturer has never shipped a Content Credentials feature. Certification and shipping are separate questions and only the first is answered by the registry.
Which specification version are certified products built against?
Of the 174 records retrieved on 29 August 2026, 166 were certified against specification 2.2, seven against 2.4, and one against both, even though version 2.4 is published and the C2PA site points adopters at 2.3. Published, recommended and certified against are three different things.