Structured Hardening Standard

Hardening you can verify

The Structured Hardening Project (SHP) is a technical standard for defining, applying, verifying, and certifying bounded security postures.

SYSTEM / 01

A defined hardening lifecycle

SHP replaces informal collections of security tweaks with a structured model.

  1. 01 Threat Model
  2. 02 Controls
  3. 03 Hardening
  4. 04 Evidence
  5. 05 Verification
  6. 06 Certification

CONTROL MODEL / 02

A hardening standard, not a collection of tweaks

SHP starts by defining what a system is being protected against.

Platform-specific threat models establish the adversaries, attack classes, assumptions, exclusions, and operational boundaries relevant to a certification target.

Controls are then defined against that scope.

Controls that cannot be verified do not provide a sufficient basis for SHP certification.

Explore the SHP Standard
VALID CONTROL REQUIRED FIELDS
WHAT
what it does
APPLY
how it is applied
VERIFY
how it is verified
RECOVER
how it can be recovered or rolled back

VERIFICATION / 03

Verification is part of the design

SEPARATE OPERATIONS

Hardening and verification are separate operations.

OBSERVED STATE
VERIFICATION
STRUCTURED OUTPUT
DECISION

SHP verification is designed to produce deterministic, structured, machine-readable results from observed system state.

Certification decisions are derived from verification output rather than informal judgement.

How Verification Works

CERTIFICATION / 04

Certification has boundaries

CERTIFICATION PROPERTIES BOUNDARY MODEL
DEVICE
BOUND
it applies to the evaluated device
STATE
BOUND
material state changes can invalidate it
SPECIFICATION
BOUND
its meaning depends on the applicable specification versions
TIME
BOUNDED
certification expires
AUTHENTICITY
VERIFIABLE
authenticity is bound to SHP-controlled signing authority

A certification can therefore be independently examined without treating a badge or document as sufficient evidence by itself.

Understand SHP Certification

BOUNDARIES / 05

Platform and tier integrity

PLATFORM BOUNDARY

Platform-specific by design

Hardening controls are not assumed to transfer safely between operating systems, device classes, or network platforms.

Each supported SHP platform requires its own defined scope, threat model, controls, verification behaviour, and certification rules.

No cross-platform certification equivalence is implied.

Explore Platforms

TIER BOUNDARY

Tier integrity

SHP tiers represent defined security postures under platform-specific rules.

They are not marketing labels.

Non-Negotiable Controls act as hard certification gates. Where bounded certification is permitted, its exclusions and residual risk must remain explicit and it must never be represented as equivalent to full-tier certification.

Understand the Tier Model

AUTHORITY / 06

Open verification, governed certification

OPEN

Verification

Verification logic must be open, deterministic, versioned, reproducible, and capable of producing structured machine-readable output.

Verification
GOVERNED

Certification

Certification is different.

Only certification issued under the SHP trust architecture constitutes SHP certification. Client self-signing or independent execution of verification tooling does not create an SHP certificate.

Certification

AUTHORITY / 07

The specifications are part of the product

SHP is governed through versioned technical documents defining its architecture, mathematics, platform boundaries, threat models, controls, evidence, verification, and certification behaviour.

PUBLIC WEBSITE The public website explains SHP.
APPLICABLE SPECIFICATIONS The applicable specifications define it.
Browse Specifications