Check the certificate's integrity, issuer, subject, dates and current status at the point of use, then record whether it meets your specific purpose. Keeping those conclusions separate lets the next reviewer see what you established and what still needs confirmation.
Yesterday's successful check is useful history. It cannot answer a status question that arose today. A file can remain unchanged while the issuer withdraws the digital credential, or while a stated validity period ends.
Start with the decision you need to make
Write down what the certificate is being offered to support: course admission, a hiring requirement or another defined activity. Then identify the evidence and authority your process accepts for that purpose. This is a recommended review method, not a new regulatory obligation.
Our Pakistan pilot-licence article examines a particular enforcement case. The method here is broader: produce a dated, understandable record without assuming every certificate has the same legal effect or technical format.
Keep these checks separate
Use the following questions as a review worksheet. A failure or unanswered question should remain visible in the final record.
- Integrity and signature: does the available proof cover the exact file or credential being presented? Run the appropriate verifier; a printed signature image is not a cryptographic check.
- Issuer trust: who issued it, and why do you accept that organization for this purpose? A recognizable logo is not your evidence of authority.
- Person and document match: does the evidence relate to this applicant and this document version? Record how you established that link; possession of a file alone is insufficient.
- Dates: has any stated start date arrived, and has any stated end date passed? Preserve the time zone. An absent expiry date does not answer the separate status question.
- Current status: consult the applicable authoritative source for revocation, suspension or other relevant states. Record the response and its age, including any limitation.
- Acceptance: do the completed checks satisfy the requirements for the intended use? Name the decision maker and any outstanding action.
The W3C Verifiable Credentials Data Model v2.0 states: “Verifiability of a credential does not imply the truth of claims encoded therein.” Its trust model also leaves the verifier's choice of trusted issuers and purposes outside the standard.
Read the status, not just a green indicator
A technical example is W3C Bitstring Status List v1.0. It provides a compact way to publish credential states, including revocation and suspension. These are different status purposes; a result for one must not silently stand in for the other.
The specification includes this note: “Status information is about the verifiable credential”. Its example distinguishes a withdrawn digital credential from an educational degree that remains valid. Ask what was withdrawn and why before concluding that someone lost a qualification.
For a reviewer, the practical consequence is to preserve the source's actual wording. If it reports a suspension, retain its stated scope and effective dates where available. If it reports revocation, do not rename that result expiry. If it reports only one kind of status, record the others as unchecked where they matter.
This W3C example is not evidence that AeroCert implements suspension lists, nor that aviation certificates universally use W3C credentials. It explains a distinction your review process should be able to represent.
A response fetched now may still be old
Record both when you requested status and any publication, update or validity information attached to the response. A successful download is not proof that the underlying information changed at that moment.
The Bitstring Status List validity-period discussion sets no universal minimum or maximum list validity period. Apply the freshness requirements of the relevant scheme and your acceptance policy.
If the service is unavailable, save the attempt time, source and error. Keep yesterday's evidence as a historical result, label today's status unresolved, and use the applicable escalation route. An outage proves neither continuing validity nor revocation.
A fictional record a colleague can reuse
The following example is entirely hypothetical. Its people, identifiers, course and internal policy are invented to show how a reviewer keeps an unresolved check visible.
Alex is reviewing Sam's prerequisite certificate for admission to a laboratory refresher course. The fictional school's admission policy requires current issuer confirmation before completing admission. Yesterday's saved response said active; today's service cannot be reached.
- Review and purpose: DEMO-REVIEW-07, prerequisite review for laboratory refresher admission.
- Credential and subject: DEMO-CERT-42, issued by Fictional Example School to Sam Example. Exact credential file retained in the restricted review folder.
- Binding evidence: applicant identity matched through the school's existing identity-check process; credential identifier matched to the submitted file.
- Integrity and issuer: signature check succeeded for that file; issuer accepted under the fictional admission policy, version 1.
- Credential dates: stated validity from 1 January 2026 at 00:00 UTC to 31 December 2026 at 23:59 UTC; review time falls within that interval.
- Previous evidence: active response issued and retrieved on 6 September 2026 at 09:00 UTC. Historical evidence only for this review.
- Current attempt: issuer status portal, 7 September 2026 at 09:00 UTC, connection timed out. No current response or update time obtained.
- Separate conclusions: integrity confirmed; issuer accepted; subject matched; within stated dates; current status unresolved.
- Decision and next action: admission review pending under the fictional policy. Alex contacts the issuer through its established channel and records the response before completing the decision.
To reuse the record, replace the invented values and add the authoritative source address, evidence reference, verifier tool/version, reviewer and decision timestamp. Include the status response's validity information and the freshness rule actually applied. Keep only the personal information your process needs, with appropriate access and retention controls.
A later successful check should become a new dated entry. It should not overwrite the earlier outage or make it appear that confirmation was available sooner.
When a news alert prompts an individual check
Pakistan Observer coverage dated 29 August 2026 reported pilot-licence cancellations and suspensions, attributing them to a written Ministry of Defence answer to the National Assembly. That aggregate report does not establish whether a particular applicant's licence is presently usable. We have not independently recovered the underlying parliamentary answer; the publication date alone does not establish when individual decisions took effect.
Consider this wholly hypothetical internal review. All names, identifiers and the acceptance policy below are invented. This is an illustration, not legal advice or a universal requirement.
Mira Example at Fictional Cedar Air reviews applicant Rowan Sample for a first-officer vacancy on 8 September 2026 at 10:00 UTC, file DEMO-HIRE-18. Internal policy DEMO-HIRING v2 requires sufficient individual authority confirmation before marking the licence requirement satisfied. The alert triggers that check, without an automatic adverse conclusion.
Mira records licence DEMO-LIC-824, copy revision DEMO-COPY-2, and matches its holder details to Rowan through the company's established identity check, reference DEMO-ID-19. That binds the submitted copy to the applicant in this fictional record. Neither the copy nor the news establishes current authority recognition, suspension, cancellation or restrictions affecting the intended role.
At 10:15 UTC, Mira sends request DEMO-REQ-18 through the licensing authority's established verification channel, whose contact details the company has independently confirmed. She asks the authority to confirm the holder/licence match and current status for DEMO-LIC-824, including any restriction affecting first-officer duties. She requests the authoritative record reference and revision, issuing office, status-as-of time and time zone, effective dates and scope of any decision, and any stated response validity period. These are details to obtain, not an invented authority response.
At 11:00 UTC, the record reads: current status unresolved; licence-requirement decision pending under DEMO-HIRING v2. Named reviewer Mira Example will follow up through the same channel on 9 September and retain the reply with its receipt time and source authentication evidence. She will assess whether it answers the intended-use question before deciding. An unanswered request proves neither cancellation nor continuing validity.
This case describes no AeroCert connection to Pakistan status records. The W3C example above is not Pakistan licensing infrastructure.
Make the next check easier
Ask a colleague to read one completed record without opening your inbox. Can they identify the exact evidence, the status source, the unresolved questions and the reason for the decision? If not, improve the record before adding another green badge.
For the separate question of keeping evidence usable after changing suppliers, use our guide to verifying certificates without their platform. To assess AeroCert for your own workflow, see how verification works and discuss the checks your acceptance process needs.
Frequently asked questions
Does a valid digital signature mean a certificate is valid today?
No. Check the issuer, the person or document covered, validity dates and applicable current status, then decide whether the evidence meets the intended use. An intact signature alone does not settle those questions.
What should I record if the status service is unavailable?
Record the source, attempt time, error and last available evidence. Mark current status unresolved. Follow the applicable escalation process instead of treating yesterday's result as today's confirmation.
How fresh must a certificate status response be?
Use the applicable scheme and acceptance policy, together with the status response's validity and caching information. There is no universal interval in this guide. Retrieval time alone does not establish when the underlying status was updated.
Does revoking a digital credential cancel the underlying qualification?
Not necessarily. W3C distinguishes the digital credential from its backing qualification. Establish the issuer's reason and the relevant authority's position before drawing a conclusion about the qualification.
What if a source reports revocation but not suspension?
Record exactly which status was checked. A result showing no revocation does not answer a separate suspension question. If suspension matters for your decision, consult the applicable authoritative source or leave that check unresolved.
Make your certificates independently verifiable
AeroCert anchors SHA-256 certificate hashes on Avalanche and lets anyone verify them instantly by QR code, with no account, no backend call and no trust required.