Certification requirements
Coming soon
The OSDF certification program is planned and not yet operational. There is no certification body, listing, or attestation process available today. This page describes the proposed requirements.
Certification lets organizations rely on a product's claimed profile. It combines automated conformance, security review, and a published attestation.
Requirements
- Pass the full test-vector corpus at the claimed profile, deterministically.
- Fail closed on every mandatory failure category - no partial rendering.
- Declare algorithms explicitly and reject unknown mandatory extensions.
- Document trust configuration - which roots, logs, and witnesses are used.
- Publish a security contact and follow coordinated disclosure.
- Reproducible build with a signed, transparency-logged release artifact.
Process
text
1. Self-test → osdf conformance run ./vectors2. Submit → signed attestation + build provenance3. Independent run → corpus re-run by the certification body4. Review → security questionnaire + design review5. List → published entry with profile + versionMaintaining certification
Certification is tied to a specific version. A new minor version requires a delta re-run; a major version requires full re-certification. Listings link to the signed conformance report so anyone can verify the claim.
Governance of the certification program is described in the foundation roadmap.