# ICAO VDS-NC

> Source: https://docs.barcoder.ai/docs/standards/icao-vds-nc
> research date 2026-06-03 · extracted at 2026-10-03
> Publisher: Barcoder — encyclopedia of QR, barcode and payment-code standards

Specifications:
- [Guidance for Visible Digital Seals (VDS-NC) for Travel-Related Public Health Proofs — ICAO](https://www.icao.int/sites/default/files/TRIP/Publications/Guidance-for-Visible-Digital-Seals-VDS-NC-for-Travel-Related-Public-Health-Proofs.pdf)
- [Guide for Handling ICAO VDS-NC Health Proofs and EU DCC — ICAO](https://www.icao.int/sites/default/files/TRIP/Publications/Guide-Handling-ICAO-VDS-NC-Health-Proofs-and-EU-DCC-V1.0.pdf)

## Overview

The **ICAO Visible Digital Seal for Non-Constrained environments (VDS-NC)** is a cryptographically signed data structure, encoded in a 2D barcode (typically a **[QR Code](https://docs.barcoder.ai/docs/standards/qr-code)**, optionally **[Data Matrix](https://docs.barcoder.ai/docs/standards/data-matrix)**), that carries the essential information of a travel or health document together with a digital signature protecting it against tampering <sup>[1][1], [2][2]</sup>. It was defined by the **International Civil Aviation Organization (ICAO)**, a United Nations agency, as part of the **Machine Readable Travel Documents standard, Doc 9303**, and reuses the same **eMRTD trust framework** (country-level PKI) that underpins ePassports <sup>[3][3]</sup>.

A VDS-NC is structured as three parts — a **header**, a **message**, and a **signature** — serialized as canonicalized JSON and signed with **ECDSA (ES256 / ES384)** <sup>[4][4]</sup>. During the COVID-19 pandemic ICAO published a VDS-NC profile for **travel-related public-health proofs** (vaccination and test certificates), making it a direct peer of the **[EU DCC](https://docs.barcoder.ai/docs/standards/eu-dcc)** and **[SMART Health Cards](https://docs.barcoder.ai/docs/standards/smart-health-cards)** formats <sup>[1][1]</sup>.

## History

**Doc 9303 lineage.** The VDS concept extends ICAO's long-running **Doc 9303 Machine Readable Travel Documents** standard, the same framework that defines ePassports and the eMRTD PKI <sup>[3][3]</sup>. The "Non-Constrained" variant (VDS-NC) targets environments where data size is less restricted than on a chip — i.e. printed/displayed barcodes.

**COVID-19 health proofs.** During the pandemic ICAO produced specific **VDS-NC guidance for travel-related public-health proofs**, enabling member states' ministries (interior, foreign affairs, health, technology) to issue verifiable vaccination and test certificates for international travel <sup>[1][1]</sup>. ICAO also published a **Guide for Handling ICAO VDS-NC Health Proofs and the EU DCC**, addressing interoperability between the two systems at borders <sup>[2][2]</sup>.

**Capacity-building.** ICAO offered implementation packages (**iPACK**) and training to help designated authorities deploy VDS-NC issuance and inspection, aiming for global interoperability and mutual recognition of health proofs <sup>[1][1], [5][5]</sup>.

## Technical specification

A VDS-NC is a signed JSON object with three top-level parts <sup>[4][4]</sup>:

```
{ "hdr": { "t": "icao.vacc", "v": 1, "is": "UTO" },
  "msg": { ... document-specific fields ... },
  "sig": { "alg": "ES256", "cer": "...", "sigvl": "..." } }
```

- **Header (`hdr`)** — document `type` (`t`, e.g. `icao.vacc` for vaccination, `icao.test` for test), schema `version` (`v`), and `issuing country` (`is`, ISO 3166-1) <sup>[4][4]</sup>.
- **Message (`msg`)** — the health/travel payload (e.g. for a vaccination proof: holder identity, vaccine/prophylaxis, doses, dates, certificate ID) <sup>[1][1], [4][4]</sup>.
- **Signature (`sig`)** — the signing `alg` (**ES256** = ECDSA P-256/SHA-256, or **ES384**), the signer certificate `cer`, and the signature value `sigvl` <sup>[4][4]</sup>.

**Canonicalization & signing.** The JSON protected by the signature is canonicalized per **RFC 8785 (JSON Canonicalization Scheme)** before signature generation and verification; the ECDSA signature is the raw **r‖s** form <sup>[4][4], [6][6]</sup>. (ICAO Doc 9303 also defines a compact CBOR/byte serialization of the seal for constrained variants.)

**Trust framework.** VDS-NC reuses the **eMRTD PKI**: a **Barcode Signer Certificate (BSC)** is issued under the country's **CSCA** (Country Signing Certificate Authority). A verifier needs only the **issuing state's root (CSCA) certificate** to validate the seal's integrity; the signer certificate can be carried inline in the seal <sup>[3][3]</sup>.

**Carrier.** The encoded seal is the payload for a **[QR Code](https://docs.barcoder.ai/docs/standards/qr-code)** or **[Data Matrix](https://docs.barcoder.ai/docs/standards/data-matrix)** <sup>[6][6]</sup>.

## Use cases

- **Travel-related public-health proofs** — verifiable COVID-19 vaccination and test certificates for international travel <sup>[1][1]</sup>.
- **eMRTD-family travel documents** — VDS/VDS-NC profiles cover visas, residence permits, emergency travel documents, arrival/visa attestations, and other supplementary travel documents <sup>[4][4]</sup>.
- **Offline border verification** — because the signer certificate can be embedded and only the country CSCA root is required, inspection works without live connectivity, suited to border posts <sup>[3][3]</sup>.
- **Add-on to paper documents** — a printed seal extends a paper certificate with tamper-evident, machine-verifiable data <sup>[2][2]</sup>.

## Implementations

- **Kotlin generator/parser** — [tsenger/vdstools][7] — 13★, last active 2026. Parses and generates VDS and VDS-NC seals across profiles (vaccination, test, residence permit, emergency travel, visa, arrival attestation), supports ES256/ES384, and outputs barcode-agnostic bytes for QR or Data Matrix <sup>[4][4]</sup>.
- **Android reader** — [australian-passport-office/vds-nc-reader-library-android][8] — Kotlin, reads and evaluates VDS-NC per ICAO Doc 9303 in Android apps <sup>[3][3]</sup>.
- **JVM verifier** — `kurzdigital/vds-jvm` parses and verifies VDS / VDS-NC seals <sup>[6][6]</sup>.
- **EU tooling** — the EU Publications Office published a **VDS Reader** for inspecting ICAO seals <sup>[6][6]</sup>.
- **ICAO iPACK** — official implementation package and training for state authorities deploying issuance/inspection <sup>[1][1], [5][5]</sup>.

## Comparison

| | **ICAO VDS-NC** | **[EU DCC](https://docs.barcoder.ai/docs/standards/eu-dcc)** | **[SMART Health Cards](https://docs.barcoder.ai/docs/standards/smart-health-cards)** | **[DIVOC](https://docs.barcoder.ai/docs/standards/divoc)** |
|---|---|---|---|---|
| Data model | signed **JSON** seal (hdr/msg/sig); CBOR variant in Doc 9303 | CWT / CBOR + COSE | W3C VC as JWS over FHIR | W3C VC (JSON-LD) |
| Encoding | canonical JSON (RFC 8785) in QR/Data Matrix | Base45 + ZLIB, `HC1:` | numeric `shc:/`, Deflate | JSON-LD in QR |
| Signature | **ES256 / ES384**, raw r‖s | ES256 / PS256 | ES256 | issuer-controlled |
| Trust | **eMRTD CSCA / BSC PKI**, offline-capable | EU Gateway CSCA/DSC PKI | issuer JWKS + VCI directory | per-country keys |
| Governance | **ICAO (UN agency)** | EU eHealth Network → WHO | VCI consortium / HL7 | eGov Foundation (India) |
| Scope | travel docs + health proofs | health proofs | health/clinical credentials | health campaigns |

VDS-NC is distinguished by its **roots in the ePassport (eMRTD) trust ecosystem**: it reuses the same CSCA PKI that already binds ICAO member states, so verification needs only an issuing country's existing root certificate and can run **fully offline** at a border. Where EU DCC built a new EU Gateway and SHC uses web-published keys, VDS-NC leans on infrastructure governments already operate for passports <sup>[3][3], [4][4]</sup>.

## Fun facts

**It rides on ePassport infrastructure.** Because VDS-NC reuses the **eMRTD CSCA PKI**, any state that already issues ePassports has most of the trust machinery to issue and verify VDS-NC seals — verification can require nothing more than the issuing country's root certificate <sup>[3][3]</sup>.

**ICAO published a dedicated EU-DCC interoperability guide.** Recognizing that two parallel health-proof formats existed at borders, ICAO issued a *Guide for Handling ICAO VDS-NC Health Proofs and the EU DCC* so inspectors could process both <sup>[2][2]</sup>.

## Status

VDS-NC is a published ICAO standard within the Doc 9303 / MRTD family and remains in use for travel documents beyond the pandemic (visas, residence permits, emergency travel documents) <sup>[4][4]</sup>. Its **public-health-proof profile** saw heavy pandemic-era uptake and now sits alongside the wound-down EU DCC and SMART Health Cards as a post-pandemic credential format; the underlying VDS/VDS-NC mechanism and its eMRTD trust model continue as part of ICAO's machine-readable travel-document toolkit, with tooling actively maintained (e.g. `tsenger/vdstools`, last active 2026) <sup>[4][4], [7][7]</sup>.

## Sources

[1]: https://www.icao.int/sites/default/files/TRIP/Publications/Guidance-for-Visible-Digital-Seals-VDS-NC-for-Travel-Related-Public-Health-Proofs.pdf
[2]: https://www.icao.int/sites/default/files/TRIP/Publications/Guide-Handling-ICAO-VDS-NC-Health-Proofs-and-EU-DCC-V1.0.pdf
[3]: https://github.com/australian-passport-office/vds-nc-reader-library-android
[4]: https://github.com/tsenger/vdstools
[5]: https://www.icao.int/secretariat/CapacityDevelopmentImplementation/Pages/VDS-NC-iPACK.aspx
[6]: https://github.com/kurzdigital/vds-jvm
[7]: https://github.com/tsenger/vdstools
[8]: https://github.com/australian-passport-office/vds-nc-reader-library-android

1. [Guidance for Visible Digital Seals (VDS-NC) for Travel-Related Public Health Proofs — ICAO][1]
2. [Guide for Handling ICAO VDS-NC Health Proofs and the EU DCC — ICAO][2]
3. [vds-nc-reader-library-android (Doc 9303, eMRTD trust) — Australian Passport Office][3]
4. [vdstools — VDS/VDS-NC structure, profiles, ES256/ES384 — tsenger][4]
5. [Visible Digital Seals iPACK — ICAO][5]
6. [vds-jvm — parse and verify VDS/VDS-NC — kurzdigital][6]

## Deployments

_No country reports mention this standard by name._

## Regions / aggregations not mapped to a single country

- Universal
