Digital certificates bind digital information to physical identities and provide non-repudiation and data integrity. Before you begin the IDES enrollment process, each entity should obtain one valid digital certificate issued by an approved certificate authority (CA). IDES stores your public key and related digital certificate.  IDES only recognizes and accepts digital certificates issued by IRS approved certificate authorities, listed below.

IRS public key

The IRS Public Key is a certificate that can be downloaded from the IDES Enrollment site. The public certificate should be included in the FATCA data packet (transmission archive) to the IRS.

Note: The public/private key pairs used for encryption for FATCA filings have an expiration date. The IRS Public Key for FATCA filing will expire soon. The IRS has a new key and will replace the existing key on November 1, 2024. After November 1, you will need to download the new IRS Public Key from IDES to file your FATCA Reports.

Certificate file format

Supported formats for the digital certificate are:

  • Distinguished Encoding Rules (DER) binary X.509
  • Privacy Enhanced eMail (PEM) ASCII (Base-64) encoded X.509

IDES will convert digital certificates received in DER format to Base64 for storage and retrieval.

Certificate authority Type of certificate
Sectigo (formerly Comodo) EV SSL

DigiCert

Standard SSL

EV SSL

Entrust

OV SSL Certificate Standard
EV SSL Certificate EV Multi-Domain

GoDaddy EV SSL

GlobalSign

EV SSL
OV SSL

IdenTrust

TrustID Server Standard SSL

FATCA Organization Certificate