The specifications below are the documents a working implementer or close reader actually needs to consult. The list is selective: only standards that are operative for current image-provenance practice are included. Each entry gives the canonical reference, a short description, and a note on relevance. Where applicable, links to authoritative sources are included; for ISO and other paywalled standards, the reference is precise enough to locate the document through the relevant organization.
C2PA core
- C2PA Technical Specification 2.4 — The current published version of the C2PA specification, defining manifest structure, assertion vocabulary, signing requirements, and binding mechanisms. Available at spec.c2pa.org. The most-consulted document in the stack and the entry point for any C2PA implementation work.
- C2PA Harms Modelling and Security Considerations — The companion documents to the spec describing the threats C2PA is designed against and the categories of harm it does and does not address. Essential reading for understanding what the specification is trying to do; cited heavily on the limitations page.
- C2PA Trust Model and Trust List — The trust-model section of the specification together with the C2PA conformance program's Trust List, covering the certificate model, trust list governance, and the criteria for CA inclusion. Essential for understanding the trust-list mechanics covered on the trust list page.
- C2PA User Experience Guidance for Implementers — The published guidance on consumer-facing display of credentials. Less prescriptive than the technical spec but useful for implementers building display surfaces.
Container and encoding
- ISO/IEC 19566-5 (JUMBF; current edition 2023) — The JPEG Universal Metadata Box Format, the container that holds C2PA manifests inside image files. The container is generic enough to be used for non-C2PA metadata; C2PA's adoption of it gave the format wider deployment than it had before.
- RFC 8949 (CBOR) — Concise Binary Object Representation, the binary encoding used for C2PA assertions and claims. Published as an Internet Standard by the IETF.
- RFC 9052 (COSE) — CBOR Object Signing and Encryption, the CBOR-native analogue of JOSE used for C2PA's signature encoding. The signature on each C2PA claim is a COSE_Sign1 structure.
- RFC 8152 — The original COSE specification, obsoleted by RFC 9052 and RFC 9053 but still cited in some implementations.
- RFC 8392 (CWT) — CBOR Web Token, occasionally relevant in C2PA contexts for identity assertions that follow the JWT pattern.
Cryptographic primitives
- RFC 5280 — Internet X.509 Public Key Infrastructure Certificate and CRL Profile. The X.509 certificate format used throughout C2PA's trust infrastructure.
- FIPS 180-4 — Secure Hash Standard. SHA-256, SHA-384, and SHA-512 are the hashes permitted by C2PA.
- FIPS 186-5 — Digital Signature Standard. ECDSA over P-256/P-384/P-521 curves used in C2PA signing.
- RFC 8017 (PKCS #1 v2.2) — RSA Cryptography Specifications. RSA-PSS with appropriate key sizes is a permitted C2PA signature algorithm alongside ECDSA.
- RFC 6960 (OCSP) — Online Certificate Status Protocol, used for revocation checking in C2PA's PKI inheritance.
Trust and reporting
- ISO/IEC 21617-1:2025 (JPEG Trust Part 1: Core foundation) — The JPEG Trust framework for establishing trust in media through tamper-evident trust records, trust profiles and trust reports. Aligned with and compatible with C2PA manifests.
- ISO/IEC 21617-2 and 21617-3 (drafts) — JPEG Trust Part 2 (Trust profiles and reports) and Part 3 (Media asset watermarking), both at committee-draft stage in development.
Image metadata
- Exif 3.0 (CIPA DC-008-2023) — Exchangeable Image File Format, the dominant camera-metadata standard. Maintained by the Camera & Imaging Products Association.
- ISO 16684-1:2019 (XMP) — Extensible Metadata Platform, Adobe's RDF/XML-based metadata standard, widely used in editorial pipelines.
- IPTC Photo Metadata Standard 2025.1 — The current version of the IPTC photo metadata standard (adding AI-generation properties such as AI System Used), maintained by the International Press Telecommunications Council. The newsroom-standard editorial-metadata format.
- IPTC Video Metadata Hub — The IPTC standards collection covering video metadata, increasingly relevant as video C2PA matures.
- ICC Profile Specification (ISO 15076-1) — International Color Consortium profile format, occasionally relevant in forensic analysis.
File formats and embeddings
- ISO/IEC 10918-1 (JPEG) — The base JPEG specification. C2PA manifests are embedded in JPEG files using the APP11 marker.
- ISO/IEC 23008-12 (HEIF) — High Efficiency Image File Format. C2PA manifests embed in a top-level
uuidbox containing the JUMBF manifest store, as in other ISOBMFF-based formats. - ISO/IEC 14496-12 (ISOBMFF) — ISO Base Media File Format, the container behind MP4 and the structural basis for HEIF. Relevant for video C2PA.
- ISO/IEC 21320-1 (Document Container File) — The ZIP-based container standard relevant for ZIP-packaged document formats that C2PA supports.
- ISO 32000-2 (PDF 2.0) — The current PDF specification. C2PA manifests embed in PDFs as embedded (associated) files.
Watermarking and fingerprinting (informative references)
- Cox, Kilian, Leighton, and Shamoon, "Secure Spread Spectrum Watermarking for Multimedia" (IEEE Transactions on Image Processing, 1997) — The seminal frequency-domain watermarking paper, foundation of much of the classical watermarking literature.
- Fernandez, Couairon, et al., "The Stable Signature: Rooting Watermarks in Latent Diffusion Models" (ICCV 2023) — The Meta paper introducing the Stable Signature scheme. Open-published, with reference implementation.
- Google DeepMind, "SynthID: Tools for watermarking and identifying AI-generated content" (2023, with ongoing technical updates) — Google's published material on SynthID. Less complete than the academic papers above; details remain partially proprietary.
- Saberi, Sadasivan, et al., "Robustness of AI-Image Detectors: Fundamental Limits and Practical Attacks" (ICLR 2024) — The widely-cited paper on adversarial attacks against AI-image detectors and watermarks. Essential for understanding watermark robustness claims.
- Zhao, Zhang, et al., "Invisible Image Watermarks Are Provably Removable Using Generative AI" (NeurIPS 2024) — Formalization of the regeneration attack against watermarks.
Detection and forensics (informative references)
- Farid, "Photo Forensics" (MIT Press, 2016) — The standard textbook on classical image forensics. Farid's continued lab publications at Berkeley update many of the techniques for modern contexts.
- Wang, Wang, et al., "CNN-generated images are surprisingly easy to spot" (CVPR 2020) — The foundational paper showing that a classifier trained on one GAN generalizes to images from other CNN generators.
- Cozzolino, Poggi, et al., "Raising the Bar of AI-generated Image Detection with CLIP" (CVPR Workshops 2024) — A study of cross-generator generalization, the central weakness of AI-image detectors.
- An, Ding, et al., "WAVES: Benchmarking the Robustness of Image Watermarks" (ICML 2024) — Companion benchmark for watermark robustness across schemes.
Policy and regulation
- Regulation (EU) 2024/1689 (EU AI Act) — The full text of the EU AI Act. Article 50 contains the provenance-relevant marking obligations. Official journal of the European Union.
- EU AI Office Guidance and Codes of Practice — The European Commission's published guidance on AI Act implementation, including the voluntary Code of Practice on marking and labelling AI-generated content (June 2026). Continues to be elaborated through 2026 and beyond.
- California SB 942 (AI Transparency Act, 2024), as amended by AB 853 (2025) — Full text available through the California Legislative Information system.
- TAKE IT DOWN Act (2025, federal; Public Law 119-12) — Full text via Congress.gov. Federal statute on non-consensual intimate imagery including deepfakes.
- NIST AI Risk Management Framework (AI 100-1) and NIST AI 100-4 — The federal AI risk framework and NIST's report on reducing risks posed by synthetic content, which surveys provenance, watermarking and detection.
Adjacent standards
- W3C Verifiable Credentials Data Model 2.0 — A general framework for cryptographically verifiable credentials. Architecturally related to C2PA, occasionally proposed as an alternative or complement.
- W3C Decentralized Identifiers (DIDs) v1.0 — A standard for identifier schemes that do not require central registries. Has been proposed as an alternative trust model for C2PA-style signing.
- Sigstore (specifications and implementation) — Open-source signing infrastructure for software supply chain. Architecturally similar to C2PA in some respects, particularly the ephemeral-signing pattern.
Note
This index is selective rather than exhaustive. Standards that are relevant in narrow contexts (specific national metadata standards, single-vendor proprietary formats, niche watermarking schemes) are omitted to keep the list focused on what a working implementer or close reader will actually consult. The further reading page provides the corresponding bibliography for non-specification sources.