Structured Hardening Project

Certification

The meaning, lifecycle, trust boundaries, expiry, revocation, and cryptographic governance of SHP certification.

SHP Certification

SHP certification is a bounded, cryptographically verifiable statement about an evaluated system state.

It is not a permanent declaration that a device is secure.

It is not a guarantee that compromise cannot occur.

It is not created merely by running SHP verification tooling.

What certification binds

An SHP certification is bound to the context in which the certification decision was made.

Certification is:

  • device-bound
  • state-bound
  • specification-bound
  • time-bounded

The certification therefore has meaning only within its stated platform, tier or certification class, evaluated state, specification versions, scope, and validity period.

Certification lifecycle

An active certification has a finite validity period.

When that period ends, the certification becomes:

Expired — Not Certified

Expiry does not imply that the device was compromised.

It means that the previous certification is no longer an active certification of the current device state.

A certification can also become:

Revoked — Not Certified

Revocation and expiry are distinct events.

State change and drift

Certification is state-bound.

Material change can cause the certified state and the current state to diverge.

Where the applicable drift rules invalidate certification, the device must be re-verified before a new certification can represent its current state.

Certification is therefore never described as permanent or “set and forget”.

Full and bounded certification

Where all requirements for full-tier certification are satisfied, certification may represent the full applicable tier.

Where the specifications permit certification with defined exclusions, it must be labelled:

Tier X — Bounded Certification

A bounded certification must identify its included controls, excluded controls, and residual risk.

It must never imply equivalence with full-tier certification.

A missing or failed applicable Non-Negotiable Control cannot be hidden by bounded certification.

Signing authority

SHP certification exists only when issued under SHP-controlled certification authority.

The trust architecture is hierarchical.

At a high level:

SHP Root → Platform Intermediate → Operational Certification Signing Authority

The SHP root does not sign individual certificates directly.

Platform separation is part of the trust model.

Client self-signing does not constitute SHP certification.

Machine-readable certification artefact

The machine-readable certification manifest is the authoritative object covered by the applicable certification signature.

Human-readable certificates or representations are derived views and must not silently change the meaning of the signed machine-readable artefact.

Independent verification should establish the authenticity and applicable trust chain of the certification artefact.

Public verification

A public verification service may provide certification status without exposing client identity.

Public identifiers must not be sequential or predictably reveal certification volume or client relationships.

The public service supplements the cryptographic artefact.

It does not replace independent cryptographic verification.

What certification does not mean

SHP certification does not mean:

  • that compromise is impossible
  • that every conceivable threat is covered
  • that certification survives arbitrary state change
  • that an expired certificate remains active
  • that a revoked certificate remains valid
  • that one platform’s certification is equivalent to another’s
  • that independently generated signatures create SHP certification
  • that SHP provides continuous monitoring or incident response

Certification must always be interpreted within its defined bounds.

Verification and certification

Verification evaluates observed state.

Certification applies the governed certification rules and SHP signing authority to an eligible verification result.

They are connected, but they are not the same operation.

Read about Verification · Browse Specifications