The W3C Security Interest Group has published the first drafts of the following Group Notes:

"Threat Modeling Guide" which describes when, why, and how to perform threat modeling during the development of a specification at W3C; and "Threat Model for Decentralized Credentials" which is the live "meta" Threat Model related to Decentralized Credentials.

w3.org/news/2026/group-note-dr

diagram of "Layer 3: "Credentials" and precisely the Credential-Presentation Phase " with "Governance and Trust Framework" at top; "website", "wallet" levels with arrows between "Issuer", "Holder" and "Website" , "agents" and "at bottom "Verifiable Data Registry"
0

If you have a fediverse account, you can quote this note from your own instance. Search https://w3c.social/users/w3c/statuses/115978512846979543 on your instance and quote it. (Note that quoting is not supported in Mastodon.)