The C2PA technical specification, version 2.4
Content Credentials is a published open specification, not a product claim. Version 2.4 is the current release and its own version history dates it to April 2026. It defines a manifest store serialized as JUMBF boxes, assertions in CBOR, a claim, and a claim signature in COSE, bound to the content by a hash.
The verdict
Verified
The document exists. The ledger fetched it at its publisher and quotes it.
Key facts
What the sources say
- Record ID
- CPS-2026-0001
- Kind
- Standard
- Jurisdiction
- Global
- Last verified
- Added
- The specification index at spec.c2pa.org redirects to the 2.4 specification, and requests for versions 2.5, 2.6 and 3.0 return HTTP 404.
- The version history dates release 2.4 to April 2026 and lists a new JSON serialization called crJSON plus repository receipt and environmental sustainability assertions.
- A C2PA Manifest carries an assertion store, a claim and a claim signature; the last manifest in the store is the active manifest.
- The specification never promises that a manifest proves truth; clause 14 decides only whether a signature validates and whether its signer is on a trust list.
Dimension by dimension
3 dimensions, each one stated, silent or open
Embeds a mark or manifest, Displays or verifies, What it requires. Stated means the document you can open below says it; silent means the ledger read the document and it does not.
- Embeds a mark or manifestStated
- It defines the manifest store itself, a JUMBF superbox labelled c2pa with type UUID 63327061-0011-0010-8000-00AA00389B71, embedded per format by Appendix A.C2PA Technical Specification 2.4, primary source, 15 September 2026.
- Displays or verifiesStated
- It defines validation states and status codes, and clause 16 sets out disclosure levels for how a consumer is shown provenance.C2PA Technical Specification 2.4, primary source, 15 September 2026.
- What it requiresStated
- It is a voluntary specification. It requires nothing of anyone until a law, a contract or a conformance programme points at it.C2PA Technical Specification 2.4, primary source, 15 September 2026.
What it changes
For a publisher, a platform or a newsroom
Read the version number before you quote a rule. A newsroom or platform policy that cites "the C2PA spec" without a version is citing a moving target, because 2.4 added serializations and assertions that 2.2 readers will not recognise. Pin the version in your policy, record the date you read it, and re read on each release, because the parsing your engineers build is written against one version of Appendix A and not against the idea of Content Credentials.
Sources
What this record was verified against
- C2PA Technical Specification 2.4Primary · 15 September 2026
- C2PA specifications indexPrimary · 15 September 2026
Related
Records that sit beside this one
Where a C2PA manifest actually sits in each file format
Global · verified 15 September 2026
PNG: "a chunk type of 'caBX' (as per PNG, 4.7.2)", recommended before the IDAT chunks.
The C2PA conformance programme, the trust list and the conforming products list
Global · verified 15 September 2026
The programme holds generator products, validator products and certification authorities to the specification, the Certificate Policy and the Security Requirements.
Content Credentials at ISO: ISO/CD 22144
Global · verified 15 September 2026
The ISO catalogue entry reads "ISO/CD 22144" with status "Under development" and stage "CD approved for registration as DIS [30.99]".
JUMBF, ISO/IEC 19566-5:2023, the box format under every manifest
Global · verified 15 September 2026
The catalogue entry reads "ISO/IEC 19566-5:2023, Information technologies, JPEG systems, Part 5: JPEG universal metadata box format (JUMBF)", status Published.
May the absence of Content Credentials be treated as suspicion?
Global · verified 15 September 2026
OpenAI states that if no metadata or watermark is detected "the tool will not make a definitive conclusion about whether the image was generated with OpenAI tools since provenance signals can in some cases be stripped".
Who answers for a manifest that is signed and false?
Global · verified 15 September 2026
The C2PA trust model is expressed as validation states: well formed, valid and trusted, each about signatures, certificates and lists rather than about the truth of an assertion.
Cite this record
Free to reuse under CC BY 4.0, with attribution. The record ID CPS-2026-0001 is permanent and is never reused.
- In a sentence
- According to the GAGE Content Provenance Checker (as of 15 September 2026), the c2pa technical specification, version 2.4.
- APA
- GAGE (Global Academy of Generative-AI Education). (2026). The C2PA technical specification, version 2.4. Content Provenance Checker. Retrieved 15 September 2026, from https://www.gage.academy/tools/content-provenance-checker/records/CPS-2026-0001-c2pa-technical-specification-2-4
- MLA
- "The C2PA technical specification, version 2.4." Content Provenance Checker, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/content-provenance-checker/records/CPS-2026-0001-c2pa-technical-specification-2-4.
- Chicago
- GAGE (Global Academy of Generative-AI Education). "The C2PA technical specification, version 2.4." Content Provenance Checker. Last modified 15 September 2026. https://www.gage.academy/tools/content-provenance-checker/records/CPS-2026-0001-c2pa-technical-specification-2-4.
- Permalink
- https://www.gage.academy/tools/content-provenance-checker/records/CPS-2026-0001-c2pa-technical-specification-2-4
Last updated . Every record re verified . The ledger is checked monthly, first Monday, and the same day for any C2PA specification release.
Back to the full ledger, or every record for Global and every standard record.
GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.