trqp-assurance-hub

Assurance levels (AL1–AL4)

Back to Docs Index

Normative status: This is the canonical definition of Assurance Levels AL1–AL4 for the TRQP ecosystem.

This repository treats assurance levels as operational claims that MUST be backed by evidence artifacts. Higher levels require stronger evidence, stronger evaluation posture, and tighter lifecycle discipline.

Design principle: A higher AL is not “more paperwork”; it is a stronger, more falsifiable claim about system behavior and governance.

This guide is the canonical vocabulary for AL1–AL4 within the Assurance Hub. If upstream definitions (e.g., TRQP-TSPP) evolve, this hub SHOULD update via a versioned change with explicit migration notes.

Normative keywords

The key words MUST, MUST NOT, SHOULD, SHOULD NOT, and MAY are to be interpreted as described in RFC 2119.

Core terms

Assurance level definitions

AL1 — Baseline conformance and hygiene

At AL1, an operator MUST be able to produce machine-readable evidence showing protocol conformance and minimum deployment posture.

Minimum expectations:

AL2 — Evidence-bound self-attestation

At AL2, the operator MUST bind claims to evidence in a way that reduces provenance ambiguity.

Minimum expectations (in addition to AL1):

AL3 — Independently reviewed assurance

At AL3, claims MUST be reviewable by an independent assessor and MUST be supported by artifacts that enable audit-style checking.

Minimum expectations (in addition to AL2):

AL4 — High-consequence / continuously evidenced assurance

At AL4, the assurance claim MUST remain valid under change, and MUST be supported by operational evidence demonstrating ongoing control performance and lifecycle discipline.

Minimum expectations (in addition to AL3):