SHP Certification Services
SHP certification services apply the Structured Hardening Project standard to supported certification targets.
The service does not define the standard.
The applicable SHP specifications, platform rules, threat model, control catalogue, verification rules, and certification governance determine what can be certified.
Current public service
The current public service described on this website is Fedora Tier 1 hardening and certification.
The service applies the Fedora Tier 1 requirements to an eligible device, evaluates the resulting state, and issues SHP certification only when the applicable certification requirements are satisfied.
What the service does
A certification engagement separates four activities:
- establishing the applicable certification target and scope
- applying the required hardening controls
- verifying the resulting device state
- issuing certification when the verification and certification requirements are satisfied
Hardening alone does not guarantee certification.
Certification follows the verification result and applicable decision rules.
Before hardening
The device and intended certification target must first be established.
The intake process is designed to collect only the information required to determine whether the requested engagement can proceed.
SHP does not require customer passwords, private keys, or unrelated client files as part of normal intake.
Verification
After hardening, the applicable controls are evaluated against observed device state.
Verification is structured and machine-readable.
Applicable Non-Negotiable Controls remain hard certification gates and cannot be waived merely to produce a desired certification result.
Certification
A successful service engagement can result in SHP certification only when the applicable certification requirements are satisfied.
Certification is device-bound, state-bound, specification-bound, and time-bounded.
It does not represent a permanent security status.
Bounded certification
Where the applicable specifications permit certification with defined exclusions, the result must be identified as:
Tier X — Bounded Certification
The included controls, excluded controls, and residual risk must remain explicit.
Bounded certification is not equivalent to full-tier certification and cannot be used to bypass an applicable Non-Negotiable Control.
What the service is not
SHP certification is not:
- general IT support
- a managed security service
- continuous monitoring
- incident response
- a guarantee against compromise
- permanent certification
The service establishes and evaluates a defined hardening state under the applicable SHP standard.
Service availability
Public availability may be narrower than the complete set of platforms, tiers, or certification classes defined within the SHP specification corpus.
A specification existing does not, by itself, mean that a corresponding certification service is currently offered.
Current service availability must be stated explicitly.