There is no technical reason it couldn't be decentralized. It's a file handed to you by a trusted issuer, like (not American, so guessing:) the dmv. From that point on it should all be local processing to generate the child certs. It doesn't need to phone home until the credentials expire.
Again, the implementation is the problem
ETA: Also, phone "home" here is wrong. The app should be a completely independent, 3rd party entity, not built or owned by the dmv (in this scenario) in any way. I believe in Estonia there's a bunch of different options for the 3rd parties, and they're heavily vetted and certified, but still independent from the state (who issue the certs).