Standard v1.0

Reproducible evidence across the full supply chain.

The standard contains 184 versioned controls. Mandatory gates prevent certification regardless of weighted score. Active tests require verified ownership, explicit consent, a declared scope, and a bounded testing window.

01 / 18 checks

Protocols & transport

TLS, HTTP behavior, DNS, redirects, compression, caching, cookies.

02 / 24 checks

Pages & crawl surface

Routes, sitemaps, robots, canonicals, hreflang, feeds, broken paths.

03 / 31 checks

OWASP & vulnerability

Headers, exposure, dependencies, DAST, secrets, supply-chain integrity.

04 / 16 checks

Trust & well-known

security.txt, change-password, policies, ownership, disclosures, contacts.

05 / 22 checks

APIs & contracts

OpenAPI, schemas, compatibility, errors, idempotency, rate limits, webhooks.

06 / 19 checks

Legibility & access

WCAG, semantics, contrast, language, keyboard, responsive rendering.

07 / 14 checks

Agents & discovery

MCP, llms.txt, structured data, agent permissions, human escalation.

08 / 40 checks

Operations & evidence

CI, provenance, SBOM, observability, incident readiness, retention.

Tier rules

0–59

Observed

Inventory and evidence captured

60–79

Ready

Mandatory public controls pass

80–94

Verified

Supply chain and ownership verified

95–100

Assured

Active testing and reviewer attestation