# Verification Models
Source: https://docs.chain.link/ccip/concepts/ccvs/verification-models

> For the complete documentation index, see [llms.txt](/llms.txt).

CCIP supports multiple Cross-Chain Verifier (CCV) models. Each model follows the same high-level pipeline (monitor source-chain events, wait for the required finality, produce a VerifierResult), but attestation mechanics differ.

For resolver contracts, version tags, and interface requirements shared across models, see [CCV Interfaces & Guarantees](/ccip/concepts/ccvs/interface-guarantees).

## CommitteeVerifier (Default)

The **CommitteeVerifier** is CCIP's default CCV, operated by the CCIP decentralized oracle network.

**Attestation flow:**

1. Offchain verifier nodes monitor `CCIPMessageSent` events filtered to their CCV's resolver contract.
2. Each node waits until the message meets its configured finality requirement (full finality by default, or a custom depth for faster-than-finality transfers).
3. Each node independently signs a hash over the CCV's version tag and the message ID (which commits to the full encoded message).
4. Signatures are sent to an **Aggregator**, which assembles a quorum result and exposes the combined VerifierResult via a read API.

**Reorg handling:** When a faster-than-finality message is reorged before full finality, the CommitteeVerifier quarantines affected messages and pauses new attestations until the source chain reaches finality. This reorg quarantine is specific to the default CommitteeVerifier. Third-party CCVs may not provide equivalent protection. See [Trust & Responsibility Model](/ccip/concepts/ccvs/trust-responsibility-model).

## CCTPVerifier

The **CCTPVerifier** integrates Circle's Cross-Chain Transfer Protocol (CCTP) attestation for USDC.

Instead of DON quorum signatures, the offchain verifier polls Circle's external attestation API, matches the response to the message using data from the `CCIPMessageSent` receipt, and serves the result via API for executors to retrieve.

Use this model when USDC transfers should carry Circle's native cross-chain attestation in addition to, or as part of, CCIP's verification stack.

## LombardVerifier

The **LombardVerifier** supports token-specific verification through Lombard's bridge and an external attestation service.

As with the CCTPVerifier, the offchain component polls an external API, matches attestations to messages, and publishes VerifierResults for execution. Configuration includes supported tokens, per-chain paths, and remote adapters.

Use this model for transfers of tokens that Lombard's bridge supports.

## Custom CCVs

CCVs are permissionless. Any party can deploy onchain resolver and implementation contracts plus the corresponding offchain verifier service, provided they conform to CCIP's interface specifications.

Custom CCVs are appropriate when:

- An institution requires its own verification committee or attestation source
- An application needs verification logic that the default models do not cover
- A token pool or receiver mandates a specific third-party verifier

Custom operators must implement both onchain contracts (outbound `forwardToVerifier` hook, inbound `verifyMessage`) and offchain infrastructure (event monitoring, attestation publishing). Failure to meet protocol specifications can stall or fail user transactions.

## Comparing Models

| Aspect             | CommitteeVerifier   | CCTP / Lombard     | Custom CCV         |
| :----------------- | :------------------ | :----------------- | :----------------- |
| Attestation source | DON node signatures | External API       | Operator-defined   |
| Aggregation        | Aggregator quorum   | Direct API serve   | Operator-defined   |
| Default for CCIP   | Yes                 | No                 | No                 |
| Reorg quarantine   | Built-in (FTF)      | Operator-dependent | Operator-dependent |

## Learn More

- [Cross-Chain Verifiers Overview](/ccip/concepts/ccvs/overview)
- [CCV Interfaces & Guarantees](/ccip/concepts/ccvs/interface-guarantees)
- [Architecture Overview](/ccip/concepts/architecture/overview): Verification stage in the message lifecycle

> **CAUTION: Disclaimer**
>
> Chainlink CCIP is an interoperability messaging protocol. Chainlink does not hold or transfer any assets. The
> performance and behaviour of applications using Chainlink CCIP may depend on coding, engineering, configuration, and
> other technical implementation choices made by developers, token issuers, Cross-Chain Verifiers, and other
> participants. Users remain responsible for evaluating, configuring, testing, deploying, operating, and maintaining
> their own applications and integrations, including assessing any applicable operational, security, technical, and
> legal or regulatory risks. Please review the [Chainlink Terms of Service](https://chain.link/terms) which provides
> important information and disclosures. By using Chainlink CCIP, you expressly acknowledge and agree to accept these
> terms. Cross-Chain Verifiers (CCVs) may be operated by third parties. The security, availability, governance, and
> operational profile of a CCV varies depending on the verifier selected. Users are solely responsible for evaluating
> any CCVs used in connection with their applications or integrations and determining whether they are appropriate for
> their intended use case. This code represents an example of using a Chainlink product or service. It is provided "AS
> IS" and "AS AVAILABLE" without warranties of any kind, has not been audited, and may omit checks or error handling.
> Each party intending to use this reference implementation must perform its own audits, security and code review, and
> testing before any production deployment and ensure the operation and performance of such code matches expectations.
> Neither Chainlink Labs, the Chainlink Foundation, nor Chainlink node operators are responsible for outcomes due to
> errors in this example or how it is deployed or operated. Use of the Chainlink Network is subject to the Chainlink
> Foundation Terms of Service, which provides important information and disclosures. By using this code, you acknowledge
> and agree to these terms.