trqp-assurance-hub

Candidate Trust Registry Assurance & Certification Baseline

This package defines a Candidate Trust Registry Assurance & Certification Baseline (CTR-ACB).

It is not a certification authority, and it does not modify TRQP transport semantics. It is a transport-neutral, implementation-neutral baseline for how a trust registry (and its operators) can be assessed and certified using machine-readable artifacts.

The baseline builds on the existing assurance artifacts in this repository:

What this enables

CTR-ACB provides the foundations for an eventual trust registry software certification program by defining:

Different ecosystems can operationalize this baseline in different ways (self-attestation, industry peer review, accredited assessor), while still producing interoperable artifacts.

Non-goals

CTR-ACB does not:

Where to start

  1. Read the tier model: assurance-tier-model.md
  2. Understand controls: control-framework.md
  3. Follow the evaluation flow: evaluation-procedure.md
  4. Review the attestation artifact: certification-attestation.md