CTR-ACB aligns certification tiers to the repository’s assurance levels (AL1–AL4).
The intent is to preserve a single mental model: higher AL = stronger evidence + stronger evaluation.
| Tier | Evaluation posture | Typical assessor | Evidence strength |
|---|---|---|---|
| AL1 | Self-declared posture | Operator | Low (structured, but minimal) |
| AL2 | Self-attested with evidence | Operator + peer review optional | Medium (evidence bundles + manifests) |
| AL3 | Independently reviewed | Independent assessor | High (control satisfaction + lifecycle + integrity) |
| AL4 | High consequence / regulated | Accredited assessor / multi-party | Highest (strong provenance + revocation discipline) |
Across tiers, the baseline tightens:
CTR-ACB intentionally does not define accreditation. It does define minimum behaviors: