Structured Hardening Project

Services

Certification services delivered under the Structured Hardening Project standard.

SHP Certification Services

SHP certification services apply the Structured Hardening Project standard to supported certification targets.

The service does not define the standard.

The applicable SHP specifications, platform rules, threat model, control catalogue, verification rules, and certification governance determine what can be certified.

Current public service

The current public service described on this website is Fedora Tier 1 hardening and certification.

The service applies the Fedora Tier 1 requirements to an eligible device, evaluates the resulting state, and issues SHP certification only when the applicable certification requirements are satisfied.

Explore the Fedora Platform

What the service does

A certification engagement separates four activities:

  1. establishing the applicable certification target and scope
  2. applying the required hardening controls
  3. verifying the resulting device state
  4. issuing certification when the verification and certification requirements are satisfied

Hardening alone does not guarantee certification.

Certification follows the verification result and applicable decision rules.

Before hardening

The device and intended certification target must first be established.

The intake process is designed to collect only the information required to determine whether the requested engagement can proceed.

SHP does not require customer passwords, private keys, or unrelated client files as part of normal intake.

Secure Intake

Verification

After hardening, the applicable controls are evaluated against observed device state.

Verification is structured and machine-readable.

Applicable Non-Negotiable Controls remain hard certification gates and cannot be waived merely to produce a desired certification result.

How Verification Works

Certification

A successful service engagement can result in SHP certification only when the applicable certification requirements are satisfied.

Certification is device-bound, state-bound, specification-bound, and time-bounded.

It does not represent a permanent security status.

What SHP Certification Means

Bounded certification

Where the applicable specifications permit certification with defined exclusions, the result must be identified as:

Tier X — Bounded Certification

The included controls, excluded controls, and residual risk must remain explicit.

Bounded certification is not equivalent to full-tier certification and cannot be used to bypass an applicable Non-Negotiable Control.

What the service is not

SHP certification is not:

  • general IT support
  • a managed security service
  • continuous monitoring
  • incident response
  • a guarantee against compromise
  • permanent certification

The service establishes and evaluates a defined hardening state under the applicable SHP standard.

Service availability

Public availability may be narrower than the complete set of platforms, tiers, or certification classes defined within the SHP specification corpus.

A specification existing does not, by itself, mean that a corresponding certification service is currently offered.

Current service availability must be stated explicitly.

Contact SHP