The International Civil Aviation Organization (ICAO) TRIP-ICBWG (International Capacity Building Working Group) has announced mandatory updates to electronic Machine Readable Travel Documents, deprecating Basic Access Control in favour of Password Authenticated Connection Establishment (PACE).
Due to BAC’s vulnerability to eavesdropping and data disclosure, ICAO’s Annex 9 standards now require member states to implement PACE capability by 1 January 2027 and cease issuing BAC-only credentials by 1 January 2028. All legacy BAC documents must be removed from circulation by 2038. Additionally, ICAO plans to phase out 3DES algorithms, requiring states to select AES-based PACE ciphersuites.
The update is primarily for eMRTD issuers and border authorities operating inspection systems such as electronic gates.
The ICAO Technical Advisory Group to the Traveller Identification Programme (TAG/TRIP) and the ICAO Facilitation Panel (FALP) determined that BAC is becoming increasingly vulnerable to eavesdropping and unauthorised disclosure of the personal information held on the eMRTD chip. As a result, TAG/TRIP has identified PACE as the alternative. PACE was designed to overcome the limitations of BAC, which uses symmetric cryptography. PACE employs asymmetric cryptography to establish stronger protection against eavesdropping.
eMRTD issuing authorities are required to implement PACE by 1 January 20271 and stop issuing documents with BAC by 1 January 2028. In addition, countries shall ensure that all eMRTDs supporting BAC are removed from circulation by 1 January 2038, irrespective of the validity period. There is a one year transition period where issuing authorities can include both BAC and PACE on the chip.
Until BAC is removed from circulation in 2038, borders will need to ensure their inspection systems continue to support both PACE and BAC.
The decision to standardise these changes in Annex 9 makes their implementation an obligation for all eMRTD-issuing ICAO member states. These mandatory changes affect both the document issuance and the border verification sides of the travel continuum.
In the near future, there are likely to be changes to the suite of cryptographic algorithms deemed secure enough to use for eMRTD authentication. TAG/TRIP has decided to deprecate the usage of the 3DES algorithm in the near future. Therefore, States should only choose PACE ciphersuites using the AES algorithm when migrating to PACE.
1eMRTDs supporting PACE only are already being issued by Member States and have been in circulation for several years without interoperability issues at borders.
The FALP endorsed the following implementation deadlines for states relating to this change (for both issuance and border verification) which are outlined in the following Annex 9 standards:
• 3.13.1 Contracting States issuing eMRTDs shall implement Password Authenticated Connection Establishment (PACE) as of 1 January 2027.
• 3.13.2 Contracting States issuing eMRTDs shall no longer issue eMRTDs with Basic Access Control (BAC) as of 1 January 2028.
• 3.13.3 Contracting States issuing eMRTDs shall ensure that all eMRTDs with BAC are out of circulation by 1 January 2038.
ICAO Doc 9303 Part 11: Security Mechanisms for Machine Readable Travel Documents outlines technical specifications for accessing an eMRTD’s contactless integrated-circuit chip, including PACE. https://www.icao.int/sites/default/files/publications/DocSeries/9303_p11_cons_en.pdf
For the Identity Week community, this shift represents a vital technical roadmap change:
– Border & Verification Tech Providers: Inspection systems and e-Gates must support dual-protocol (BAC/PACE) checks seamlessly through 2038 without slowing traveller throughput.
– Document & Chip Manufacturers: Issuing authorities and suppliers must align chip software and key management with AES-backed PACE standards ahead of the 2027/2028 deadlines.















