trqp-assurance-hub

Revocation and renewal

Certification is only credible when it is time-bound and revocable.

CTR-ACB defines baseline expectations for renewal cadence and revocation signaling. Ecosystems can tighten these rules.

Validity windows

A Certification Attestation includes a validity window (not_before, not_after).

Recommended defaults:

Renewal

Renewal SHOULD:

Revocation

Revocation MUST be supported at AL4, and SHOULD be supported from AL3 upward.

A revocation event SHOULD:

CTR-ACB does not mandate a transport for revocation notices; it requires that revocation is discoverable and actionable for relying parties at the target tier.

See: docs/guides/revocation-semantics.md.