Skip to content
Versionv0.1 ALPHA 2

Certification requirements

Coming soon

The OSDF certification program is planned and not yet operational. There is no certification body, listing, or attestation process available today. This page describes the proposed requirements.

Certification lets organizations rely on a product's claimed profile. It combines automated conformance, security review, and a published attestation.

Requirements

  1. Pass the full test-vector corpus at the claimed profile, deterministically.
  2. Fail closed on every mandatory failure category - no partial rendering.
  3. Declare algorithms explicitly and reject unknown mandatory extensions.
  4. Document trust configuration - which roots, logs, and witnesses are used.
  5. Publish a security contact and follow coordinated disclosure.
  6. Reproducible build with a signed, transparency-logged release artifact.

Process

text
1. Self-test        osdf conformance run ./vectors2. Submit           signed attestation + build provenance3. Independent run  corpus re-run by the certification body4. Review           security questionnaire + design review5. List             published entry with profile + version

Maintaining certification

Certification is tied to a specific version. A new minor version requires a delta re-run; a major version requires full re-certification. Listings link to the signed conformance report so anyone can verify the claim.

Governance of the certification program is described in the foundation roadmap.

Spec status: working draft v0.4 · subject to change before v1.0.