Certification · v0.10.0
Assessment levels
APRF defines how results may be claimed. StackRail publishes the working draft and hosts a reference self-assessment UI—it does not currently operate an accredited third-party certification program.
Not ISO / NIST / SOC 2 certification
APRF gates and crosswalks do not substitute for peer-framework audits. Conformance statements must cite version, tier, profile, capability, and open blockers—never a single percentage badge.
self-attestation
Self-attestation
Organization publishes assessment results + evidence index against a pinned APRF version. No third-party validation.
third-party
Third-party assessment
Independent assessor verifies gate blockers and samples evidence. Intended for Tier 3 and regulated use.
For third-party assessors (draft)
- Pin the APRF SemVer under review and record criticality + profile/lenses.
- Verify each applicable mandatory check against its artifact and pass condition.
- Report blockers first; never average them into a readiness percentage.
- Sample evidence; require evidence refs for critical-severity pillars.
- Publish capability attained as the minimum across applicable pillars.
Formal assessor accreditation is out of scope until stewardship advances beyond working-draft. Propose changes via RFCs.