← APRF overview

Certification · v0.10.0

Assessment levels

APRF defines how results may be claimed. StackRail publishes the working draft and hosts a reference self-assessment UI—it does not currently operate an accredited third-party certification program.

Not ISO / NIST / SOC 2 certification

APRF gates and crosswalks do not substitute for peer-framework audits. Conformance statements must cite version, tier, profile, capability, and open blockers—never a single percentage badge.

For third-party assessors (draft)

  1. Pin the APRF SemVer under review and record criticality + profile/lenses.
  2. Verify each applicable mandatory check against its artifact and pass condition.
  3. Report blockers first; never average them into a readiness percentage.
  4. Sample evidence; require evidence refs for critical-severity pillars.
  5. Publish capability attained as the minimum across applicable pillars.

Formal assessor accreditation is out of scope until stewardship advances beyond working-draft. Propose changes via RFCs.