The C2PA standard has moved off the page and into shipping hardware. Cameras, smartphones, and camcorders now sign images at the moment of capture, creating a record of provenance that starts at the sensor. For photographers and organizations building authenticity workflows, it helps to know which devices support this and what camera-level signing does and does not accomplish.
This guide covers every device currently shipping with C2PA support, what that support entails, and how it fits into a broader verification workflow. We update this page as new devices and firmware releases are announced. To read the credentials one of these cameras has embedded in an image, test the photo in our free C2PA inspector, use the browser-based AI photo checker, or follow the step-by-step guide to checking a photo's Content Credentials. If you need to judge an image that has no credentials at all, start with how to tell if a photo is AI-generated.
What Camera-Level C2PA Actually Does
When a camera with C2PA support captures an image, it generates a manifest and embeds it in the file before the image ever leaves the device. This manifest typically includes the identity of the signing device (a certificate tied to the camera's hardware), a timestamp of when the capture occurred, and basic metadata about the capture conditions.
The manifest is cryptographically signed, meaning any subsequent modification to the file (cropping, color correction, re-saving) will break the signature unless the editing software is itself C2PA-aware and adds its own manifest entry to the chain. Software like Adobe Photoshop and Lightroom can read and extend C2PA chains, recording what changes were made and by which tool.
The practical result is that someone receiving a C2PA-signed image can verify that it came from a specific device at a specific time. If the chain is intact, they can also see what edits were applied downstream.
Leica
Leica was the first camera manufacturer to ship C2PA support in a production model.
The Leica M11-P, released in late 2023, was the first camera in the world to embed C2PA content credentials at capture. It signs every image with a manifest tied to Leica's certificate authority, recording the camera serial number, capture timestamp, and lens information. The feature is enabled by default and requires no additional configuration.
The Leica M11-D, released in 2024, became Leica's second camera with fully integrated Content Credentials. It uses the same dedicated hardware as the M11-P; signing is switched on in the menu under Sign Content.
The Leica SL3-S, released in January 2025, followed, extending C2PA support to Leica's mirrorless system camera line. Notably, the earlier Leica SL3 does not support C2PA because it lacks the dedicated hardware encryption chip required for on-device signing. The SL3-S was designed from the ground up with this capability.
For the M11-P, C2PA signing is enabled by default. On the M11-D and SL3-S, content credentials can be activated in the camera settings. Leica has not brought the feature to the M11, Q3, or SL3 by firmware, since its implementation depends on a hardware chip those models lack.
Nikon
Nikon's rollout is the clearest illustration of why camera signing needs a verification layer around it.
In February 2025, Nikon and AFP completed a certification test using a prototype Nikon camera, showing that C2PA credentials could survive a wire service's editorial pipeline from capture to publication when every tool in the chain supports the standard.
Nikon then added C2PA to the Nikon Z6III in firmware version 2.00, released on August 27, 2025. Within about a week, a researcher showed that the camera's multiple-exposure mode could be used to make it sign a manipulated image it had not really captured, and the forged file still passed the standard verification tools. Nikon suspended its Authenticity Service and invalidated every certificate the program had issued, so Z6III credentials from that period no longer verify. As of mid-2026 the service has not returned. We cover the episode and its lesson in why a camera signature isn't proof.
The cryptography was never the problem. The signatures were valid, and the exploit worked by feeding the signer manipulated content rather than by breaking the signature. That is why a signed image still benefits from independent verification of the content behind it.
Sony
Sony has pursued C2PA across both its still photography and professional video product lines. The PXW-Z300 camcorder was the first video camera in the world to support C2PA content credentials, launching Sony's "camera authenticity solution" for broadcast and documentary workflows.
Sony initially shipped C2PA support on five cameras: the Alpha 1 II, Alpha 9 III, FX3, FX30, and the PXW-Z300. Four additional models received support through firmware updates: the Alpha 7R V, Alpha 7 IV, Alpha 1, and Alpha 7S III. Two 2026-generation bodies have since joined the supported list: the Alpha 7 V, released in December 2025, and the Alpha 7R VI, released in June 2026. That brings the total to eleven cameras spanning Sony's professional video and hybrid mirrorless lines.
In late 2025 Sony also became the first manufacturer to sign video with C2PA on production cameras. Firmware released in November 2025 added movie signatures to the Alpha 7R V and Alpha 7 IV, and the May 2026 update for the Alpha 7 V extended the same capability there.
One practical caveat: signing on Sony bodies runs through the Camera Authenticity Solution, which requires a license that Sony currently offers to newsrooms and agencies rather than to individual photographers. Owning a supported body is not by itself enough to produce signed files.
Canon
Canon joined the Content Authenticity Initiative and has shipped C2PA support on two professional bodies so far. In July 2025, Canon released firmware bringing content credentials to the EOS R1 and EOS R5 Mark II. That firmware round updated nine EOS cameras in total, but the content credentials feature itself reached only those two models. As of August 2026, no other Canon body signs at capture; models like the EOS R3 and EOS R6 Mark II received the July 2025 updates without the C2PA component.
Canon has indicated that support will reach more bodies over time, with its professional and advanced amateur lines first, as the editorial and agency workflows these cameras serve adopt C2PA across the full chain.
In May 2026 Canon went a step beyond firmware and launched the Authenticity Imaging System, a service for news organizations that manages photographer certificates centrally and adds trusted timestamps after capture, starting with the EOS R1 and EOS R5 Mark II in Europe, the Middle East, and Africa.
Announced but Not Shipping: Fujifilm and Panasonic
Two more manufacturers have committed to C2PA publicly without shipping it yet, which matters for anyone deciding whether to wait for a firmware update.
Fujifilm joined the C2PA and the Content Authenticity Initiative in May 2024 and said it would bring content credentials to its X and GFX lines by firmware, naming the X-T50 and GFX100S II in the announcement. As of August 2026, no Fujifilm camera signs at capture. Some third-party compatibility lists mark these models as supported; that is the announcement being mistaken for a release.
Panasonic is likewise a Content Authenticity Initiative member, and its Lumix firmware updates through 2026 have not included C2PA on any body, the S1R II included.
No other manufacturer has shipped capture-time C2PA in a production camera as of this writing. If your brand is not listed on this page, its cameras do not sign photos today.
Google Pixel
Google brought C2PA to smartphones with the Pixel 10 series, launched in August 2025: hardware-backed signing at C2PA Assurance Level 2, applied by default to every photo from the Pixel Camera app. It remains the only phone that signs real captures, since Samsung's Galaxy implementation marks only AI-edited images and the iPhone ships no C2PA at all. The full phone picture, including what iPhone photographers can do about the gap, is in our smartphone C2PA overview.
What Camera-Level C2PA Does Not Do
Camera-level signing closes a real gap, but it has clear boundaries.
A camera-level C2PA manifest proves that a specific device captured an image at a specific time. It does not prove that the content of the image has not been manipulated after capture. If a photographer exports the RAW file, edits it in non-C2PA-aware software, and exports a JPEG, the camera's original C2PA signature applies to the RAW file, not to the edited JPEG. The chain of custody is broken at the point where a non-compliant tool touches the file.
Camera-level signing also does not verify that the scene being photographed is itself authentic. A C2PA-signed photo of a printed image, a screen, or a staged scene carries valid credentials that accurately record the capture event, but say nothing about whether the subject matter is genuine. Recapture attacks, where someone photographs a manipulated image displayed on a screen, produce files with legitimate camera signatures.
These limitations are not flaws in the C2PA standard. The standard is designed to record claims about provenance, not to validate the semantic truth of content. The distinction becomes important when you build workflows that need authenticity rather than provenance alone.
The Role of Post-Capture Verification
For workflows that require both provenance and content verification, camera-level C2PA is best understood as one layer in a broader system.
Lumethic's verification adds the analytical layer that camera signing alone does not provide. When a photographer submits both a JPEG and its original RAW file, Lumethic runs eight independent forensic checks: sensor authenticity, EXIF consistency, structural similarity, perceptual hashing, histogram analysis, face detection, RAW integrity, and recapture detection. These checks verify that the JPEG is a legitimate derivative of the camera RAW, that no synthetic content has been introduced, and that the image was not recaptured from a screen or print.
If the image already carries a camera-level C2PA manifest, Lumethic preserves it as an ingredient in its own C2PA signing, maintaining the full chain of custody. The result is an image with both hardware-level provenance from the camera and analytical verification from Lumethic. For photojournalism, legal evidence, and insurance documentation, this combination gives you about the most defensible assurance of authenticity currently available.
For photographers whose cameras do not yet support C2PA, Lumethic provides the same verification and signing workflow independently. You do not need a C2PA-enabled camera to benefit from forensic verification and content credentials. Any camera that shoots RAW is compatible with Lumethic's verification process.
Frequently Asked Questions
Do I need to buy a new camera to use content credentials? No. Lumethic can verify and sign images from any camera that shoots RAW. Camera-level C2PA support adds an additional layer of provenance at capture, but it is not a prerequisite for creating content credentials on your images.
Which cameras have C2PA enabled by default? Leica's M11-P has C2PA enabled by default. The Leica M11-D and SL3-S support C2PA but require activation in the camera settings. Other manufacturers generally require firmware updates, manual activation, or in Sony's case a Camera Authenticity Solution license. The earlier Leica SL3 does not support C2PA.
Will more cameras support C2PA in the future? The trend is clearly in that direction. The Content Authenticity Initiative now has over 6,000 members, and all major camera manufacturers have either shipped C2PA features or announced plans to do so. As the software ecosystem (editors, CMSes, social platforms) adds C2PA support, the incentive for camera manufacturers to embed signing at capture grows.
Does C2PA survive editing in Lightroom or Photoshop? Yes. Adobe's Creative Cloud applications are C2PA-aware and will extend the manifest chain, recording what edits were applied and by which tool. The Lumethic Lightroom plugin adds forensic verification to this workflow, creating a verified and signed image during your normal Lightroom export.
What about video? Sony's PXW-Z300 was the first video camera to support C2PA, and eight additional Sony cameras (spanning both video and hybrid mirrorless bodies) have since received support. Video provenance is a newer area, but the same principles apply: the camera signs the file at capture, and downstream tools must be C2PA-aware to maintain the chain.
Related Articles
- What is C2PA? Understanding the Content Authenticity Standard
- Verify, Then Sign: A High-Trust Approach to C2PA Implementation
- Photo Verification in Adobe Lightroom: Plugin Guide
This page was last updated on July 8, 2026. If you know of a device we've missed, let us know.





