Skip to main content

Chapter 27 — Core Conformance and Certification Framework

Part III — Certification Schemes, Accreditation and Lifecycle Governance

Part III defines the formal trust architecture through which a valid Conformance Outcome may support a governed Certification Decision, an integrity-protected Certificate, continued surveillance, public verification and, where applicable, accreditation of the bodies that assess or certify.

Part I established:

  • the Core conformance boundary;
  • distinctions among validation, conformance, assurance, certification, accreditation, approval and Runtime Admission;
  • Conformance Subjects and Subject Snapshots;
  • Requirements, Controls, Criteria and Profiles;
  • evidence and Findings;
  • Conformance Outcomes;
  • assessment lifecycle foundations;
  • Certification Scheme foundations;
  • Runtime and Publication integration.

Part II established:

  • Conformance Assessment Programmes;
  • subject discovery;
  • authoritative inventories;
  • Scope Manifests;
  • Conformance Traceability Matrices;
  • evidence engineering;
  • Test Suites, Fixtures and Oracles;
  • automated and manual assessment;
  • sampling;
  • materiality;
  • Finding adjudication;
  • remediation;
  • Assessment Packages;
  • decision-support artefacts.

Part III governs the certification and accreditation lifecycle.

It defines:

  • Certification Programmes;
  • Scheme governance;
  • Scheme rulebooks;
  • Scheme profiles;
  • applications;
  • applicant declarations;
  • certification review;
  • Certification Decisions;
  • Certificate issuance;
  • Certificate Registries;
  • certification claims;
  • marks and badges;
  • surveillance;
  • continued conformance;
  • change notification;
  • scope extension and reduction;
  • suspension;
  • withdrawal;
  • expiration;
  • reinstatement;
  • recertification;
  • transfer;
  • Scheme transition;
  • Certification Bodies;
  • Conformity Assessment Bodies;
  • competence;
  • impartiality;
  • independence;
  • accreditation;
  • peer recognition;
  • assurance integration;
  • public verification;
  • complaints;
  • appeals;
  • disputes;
  • enforcement;
  • fraud prevention;
  • certification supply-chain integrity;
  • Part III provenance.

The governing principles are:

Certification SHALL be a separate, explicit and authorised decision based on a valid assessment. It SHALL not arise automatically from a passing test suite, Conformance Outcome, assurance conclusion, workflow completion or commercial contract.

Every Certification Decision SHALL bind to an exact Scheme version, exact certified subject, exact Subject Snapshot, exact Constitutional Baseline, exact scope, exact Assessment Package digest, exact conditions and exact validity period.

A Certificate SHALL be an immutable representation of the Certification Decision. Later suspension, scope reduction, withdrawal, expiration or reinstatement SHALL create new governed status records rather than rewrite the issued Certificate.

Certification SHALL remain bounded. It SHALL not imply universal legal compliance, universal ESG performance, absence of all defects, future conformance, accreditation, regulator approval or certification of excluded dependencies.

A certification mark SHALL be verifiable and status-aware. A static badge disconnected from the Certificate Registry SHALL not support a high-assurance public claim.

Continued certification SHALL depend on surveillance, change notification, incident treatment, evidence freshness and ongoing conformity with the applicable Scheme.

Certification Bodies SHALL demonstrate authority, competence, impartiality, independence, secure operations and decision integrity. Accreditation SHALL remain distinct from certification and SHALL itself be Scheme-bound and scope-bound.

Assurance, certification and accreditation SHALL reinforce trust without collapsing into one another. Each SHALL identify its exact subject matter, criteria, authority, scope, period and limitations.

Suspension and withdrawal SHALL propagate to public verification, certification marks, Runtime Admission dependencies, Publication claims, assurance references and tenant or white-label representations without erasing historical evidence.

Every certification path SHALL preserve Module lineage and Component lineage, together with tenant, white-label, Extension, Runtime, Publication and temporal lineage.

The Part III trust chain is:

Approved Certification Scheme

├── Scheme Rulebook
├── Conformance Profiles
├── Eligibility Rules
├── Assessment Requirements
├── Decision Rules
├── Surveillance Rules
├── Claim Rules
└── Appeal Rules


Certification Application


Valid Assessment and Assessment Package


Independent Certification Review


Certification Decision

├── Grant
├── Grant with Conditions
├── Restrict Scope
├── Defer
└── Reject


Certificate and Registry Record


Public Claim and Verification


Surveillance and Continued Conformance

├── Maintain
├── Condition
├── Reduce Scope
├── Suspend
├── Withdraw
├── Expire
└── Renew


Historical Verification and Archive

Part III SHALL remain independent of any one certification body, accreditation body, assessment platform, badge system, public-verification portal, signature technology, identity provider, registry technology, surveillance platform or commercial licensing model.


27.25. Certification Programme and Scheme Governance

A Certification Programme coordinates one or more Certification Schemes, certification applications, Certification Bodies, assessors, surveillance activities, public claims and lifecycle decisions.

A Certification Scheme defines the exact requirements, procedures and authority through which certification may be granted, maintained, reduced, suspended, withdrawn, renewed or transferred.


27.25.1. Certification Programme Identity

Every Certification Programme SHALL possess:

  • Certification Programme Identifier;
  • canonical name;
  • Programme Charter;
  • Programme owner;
  • constitutional sponsor;
  • Scheme inventory;
  • subject classes;
  • jurisdictions;
  • frameworks;
  • eligible applicants;
  • recognised Certification Bodies;
  • recognised assessment bodies;
  • accreditation requirements;
  • public-verification model;
  • risk profile;
  • lifecycle;
  • version;
  • provenance.

27.25.2. Certification Programme Types

Programme Types MAY include:

  • ZAYAZ Core Certification Programme;
  • Runtime Certification Programme;
  • Module Certification Programme;
  • Component Certification Programme;
  • Extension Certification Programme;
  • Tenant Certification Programme;
  • White-Label Certification Programme;
  • Organisation Certification Programme;
  • Publication-System Certification Programme;
  • Security Certification Programme;
  • Tenant-Isolation Certification Programme;
  • Migration Certification Programme;
  • Historical-Trust Certification Programme;
  • Certification-Body Recognition Programme.

27.25.3. Programme Charter

The Programme Charter SHALL define:

  • purpose;
  • authority;
  • constitutional basis;
  • intended trust claim;
  • subject classes;
  • Scheme governance;
  • Certification Body model;
  • accreditation model;
  • assessment model;
  • surveillance model;
  • public-claim model;
  • funding model;
  • conflicts-of-interest treatment;
  • appeals;
  • enforcement;
  • success criteria;
  • stop conditions;
  • provenance.

27.25.4. Scheme Identity

Every Certification Scheme SHALL possess:

  • Scheme Identifier;
  • canonical name;
  • Programme;
  • Scheme Owner;
  • Scheme Authority;
  • subject classes;
  • eligible applicants;
  • applicable Constitutional Baselines;
  • applicable Conformance Profiles;
  • jurisdictions;
  • frameworks;
  • business domains;
  • assessment requirements;
  • evidence requirements;
  • competence requirements;
  • impartiality requirements;
  • Certification Decision rules;
  • Certificate rules;
  • claim rules;
  • surveillance rules;
  • suspension and withdrawal rules;
  • recertification rules;
  • appeal rules;
  • lifecycle;
  • version;
  • provenance.

27.25.5. Scheme Rulebook

Every Scheme SHALL possess a Rulebook containing:

  • scope;
  • terminology;
  • authority;
  • eligibility;
  • application;
  • assessment;
  • review;
  • decision;
  • Certificate;
  • claims;
  • marks;
  • surveillance;
  • change notification;
  • conditions;
  • scope change;
  • suspension;
  • withdrawal;
  • expiration;
  • recertification;
  • transfer;
  • complaints;
  • appeals;
  • confidentiality;
  • public verification;
  • archive;
  • provenance.

27.25.6. Scheme Profile

A Scheme Profile SHALL bind:

  • Certification Scheme;
  • Conformance Profiles;
  • subject class;
  • Baseline;
  • jurisdiction;
  • framework;
  • assessment depth;
  • mandatory Criteria;
  • certification-blocking Findings;
  • evidence period;
  • surveillance;
  • validity;
  • provenance.

27.25.7. Scheme Requirement Classes

Scheme requirements MAY include:

  • subject-eligibility requirements;
  • applicant-eligibility requirements;
  • Conformance Profile requirements;
  • evidence requirements;
  • assessment-method requirements;
  • assessor-competence requirements;
  • independence requirements;
  • review requirements;
  • Certification Decision requirements;
  • public-claim requirements;
  • surveillance requirements;
  • incident-notification requirements;
  • record-retention requirements.

27.25.8. Certification Claim Model

The Scheme SHALL define the exact claim that certification supports.

The claim model SHALL identify:

  • claim text;
  • certified subject;
  • certified characteristics;
  • excluded characteristics;
  • Baseline;
  • scope;
  • period;
  • limitations;
  • required verification reference;
  • prohibited implications;
  • provenance.

27.25.9. Scheme Scope

Scheme scope SHALL identify:

  • subject types;
  • eligible versions;
  • Baselines;
  • jurisdictions;
  • tenant and white-label contexts;
  • Module and Component contexts;
  • Extension contexts;
  • Runtime contexts;
  • Publication contexts;
  • exclusions.

27.25.10. Scheme Boundary

The Scheme boundary SHALL define whether certification concerns:

  • design conformance;
  • implementation conformance;
  • operating effectiveness;
  • point-in-time state;
  • period-of-time state;
  • product or Package state;
  • Runtime state;
  • organisational processes;
  • tenant operation;
  • white-label operation;
  • Publication system;
  • historical reconstruction.

27.25.11. Scheme Validity Model

The validity model SHALL define:

  • issue time;
  • effective time;
  • validity period;
  • surveillance cadence;
  • change triggers;
  • incident triggers;
  • expiration;
  • renewal window;
  • grace period if any;
  • provenance.

27.25.12. Scheme Severity Policy

The severity policy SHALL define:

  • certification-blocking Findings;
  • conditionally acceptable Findings;
  • prohibited exceptions;
  • permitted temporary conditions;
  • scope-reduction rules;
  • suspension triggers;
  • withdrawal triggers.

27.25.13. Scheme Exception Policy

The Scheme SHALL identify:

  • exceptionable requirements;
  • non-exceptionable requirements;
  • exception authority;
  • maximum duration;
  • compensating Controls;
  • disclosure;
  • surveillance;
  • certification effect;
  • provenance.

27.25.14. Protected Certification Requirements

Protected requirements MAY include:

  • valid subject identity;
  • valid Baseline;
  • valid Certification Authority;
  • tenant isolation;
  • evidence integrity;
  • decision independence;
  • Certificate integrity;
  • claim accuracy;
  • public-verification integrity.

Protected requirements SHALL not be waived by commercial agreement.


27.25.15. Scheme Assessment Model

The assessment model SHALL define:

  • permitted assessment bodies;
  • first-, second- or third-party assessment;
  • assessment depth;
  • required Assessment Package;
  • sample rules;
  • Test Suites;
  • manual review;
  • independent review;
  • reassessment;
  • acceptance of external evidence.

27.25.16. Scheme Decision Model

The decision model SHALL define:

  • Certification Decision Authority;
  • reviewer independence;
  • quorum where applicable;
  • decision options;
  • conditions;
  • scope restrictions;
  • rationale requirements;
  • signatures;
  • appeals.

27.25.17. Scheme Surveillance Model

The surveillance model SHALL define:

  • surveillance frequency;
  • surveillance methods;
  • evidence requirements;
  • change notifications;
  • incident notifications;
  • unannounced assessment where permitted;
  • sampling;
  • remote or on-site activity;
  • public-status update;
  • provenance.

27.25.18. Scheme Publicity Model

The publicity model SHALL define:

  • public Certificate fields;
  • restricted fields;
  • public claim wording;
  • mark use;
  • verification endpoint;
  • suspension display;
  • withdrawal display;
  • historical status;
  • retention.

27.25.19. Scheme Ownership

The Scheme Owner SHALL be accountable for:

  • Rulebook;
  • Profile;
  • interpretation;
  • maintenance;
  • change control;
  • recognised bodies;
  • public verification;
  • appeals architecture;
  • lifecycle;
  • provenance.

Scheme ownership SHALL not grant unilateral certification decision authority unless explicitly assigned.


27.25.20. Scheme Interpretation

A formal Scheme Interpretation SHALL possess:

  • Interpretation Identifier;
  • Scheme version;
  • question;
  • authoritative text;
  • interpretation;
  • authority;
  • scope;
  • effective time;
  • affected applications;
  • affected Certificates;
  • provenance.

Interpretation SHALL not amend Scheme meaning.

A material meaning change SHALL follow Scheme change governance and, where Core meaning changes, Constitutional Evolution.


27.25.21. Scheme Guidance

Guidance MAY explain implementation or evidence expectations.

Guidance SHALL be identified as:

  • normative;
  • interpretive;
  • advisory;
  • illustrative.

Advisory guidance SHALL not create new mandatory requirements.


27.25.22. Scheme Change Proposal

Every material Scheme change SHALL identify:

  • current Scheme;
  • proposed version;
  • reason;
  • changed requirements;
  • changed Profiles;
  • changed eligibility;
  • changed assessment;
  • changed decision rules;
  • changed surveillance;
  • changed claims;
  • impact;
  • transition;
  • authority;
  • provenance.

27.25.23. Scheme Change Impact

Impact analysis SHALL cover:

  • active applications;
  • active assessments;
  • pending decisions;
  • active Certificates;
  • suspended Certificates;
  • certification marks;
  • public claims;
  • Certification Bodies;
  • assessors;
  • accreditation;
  • tenants;
  • white-label deployments;
  • Modules;
  • Components;
  • Extensions;
  • Runtime Admissions;
  • Publications.

27.25.24. Scheme Transition

A Scheme transition SHALL identify:

  • source Scheme version;
  • target Scheme version;
  • transition period;
  • grandfathering;
  • recertification;
  • surveillance;
  • Certificate treatment;
  • claim treatment;
  • public verification;
  • provenance.

27.25.25. Scheme Versioning

Released Scheme versions SHALL be immutable.

A new version SHALL preserve:

  • source version;
  • change history;
  • compatibility;
  • effective time;
  • transition;
  • provenance.

27.25.26. Scheme Lifecycle

Lifecycle states MAY include:

  • Draft;
  • Consultation;
  • Review;
  • Approved;
  • Active;
  • Active with Conditions;
  • Deprecated;
  • New-Application Prohibited;
  • Superseded;
  • Suspended;
  • Withdrawn;
  • Retired;
  • Historical Only.

27.25.27. Scheme Suspension

A Scheme MAY be suspended due to:

  • invalid authority;
  • defective requirements;
  • compromised decision process;
  • accreditation failure;
  • public-verification failure;
  • legal prohibition;
  • security compromise;
  • systemic misleading claims.

Scheme suspension SHALL identify treatment of active Certificates.


27.25.28. Scheme Withdrawal

Scheme withdrawal SHALL identify:

  • reason;
  • authority;
  • effective time;
  • active Certificate treatment;
  • surveillance treatment;
  • public claims;
  • replacement Scheme;
  • archive;
  • provenance.

27.25.29. Scheme Registry

The Scheme Registry SHALL preserve:

  • Scheme identities;
  • versions;
  • Rulebooks;
  • Profiles;
  • authorities;
  • recognised bodies;
  • interpretations;
  • guidance;
  • transitions;
  • lifecycle;
  • provenance.

27.25.30. Scheme Receipt

A Scheme Receipt SHOULD contain:

  • Scheme;
  • version;
  • Rulebook digest;
  • Profile inventory;
  • authority;
  • status;
  • effective time;
  • recognised bodies;
  • public-verification reference;
  • provenance.

27.25.31. Scheme Validation

HECATE SHALL validate:

  • Scheme identity;
  • authority;
  • Rulebook;
  • Profiles;
  • claim model;
  • severity;
  • exception policy;
  • assessment model;
  • decision model;
  • surveillance model;
  • lifecycle;
  • version;
  • provenance.

HECATE SHALL not establish Scheme authority through validation.


27.26. Certification Application, Eligibility and Contractual Boundary

A Certification Application initiates the formal certification process.

Application admission SHALL confirm eligibility and scope readiness.

It SHALL not imply conformance or certification.


27.26.1. Certification Application Identity

Every Certification Application SHALL possess:

  • Application Identifier;
  • Scheme;
  • Scheme version;
  • applicant;
  • certified-subject candidate;
  • subject version or Snapshot strategy;
  • requested scope;
  • requested claim;
  • Baseline;
  • Conformance Profiles;
  • jurisdictions;
  • tenants or white-label deployments;
  • Modules;
  • Components;
  • Extensions;
  • Runtime context;
  • Publication context;
  • declarations;
  • submission time;
  • lifecycle;
  • provenance.

27.26.2. Applicant Identity

Every applicant SHALL possess:

  • Applicant Identifier;
  • legal or organisational identity;
  • authority to apply;
  • relationship to subject;
  • tenant or white-label identity where applicable;
  • contact;
  • ownership;
  • conflicts;
  • sanctions or restrictions where applicable;
  • provenance.

27.26.3. Applicant Types

Applicant Types MAY include:

  • ZAYAZ Core custodian;
  • Module owner;
  • Component owner;
  • Extension publisher;
  • white-label operator;
  • tenant;
  • organisation;
  • integration provider;
  • Publication-system operator;
  • assurance provider;
  • Certification Body;
  • Conformity Assessment Body.

27.26.4. Authority to Apply

The applicant SHALL demonstrate authority to:

  • submit the subject;
  • provide evidence;
  • permit assessment;
  • receive Findings;
  • commit to remediation;
  • use certification claims;
  • notify changes;
  • accept surveillance;
  • permit public status disclosure where required.

27.26.5. Application Scope

The requested scope SHALL identify:

  • certified subject;
  • subject boundary;
  • included versions;
  • included environments;
  • tenant and white-label scope;
  • jurisdictions;
  • Modules;
  • Components;
  • Extensions;
  • external dependencies;
  • Publications;
  • exclusions;
  • claim language.

27.26.6. Application Declaration

The applicant SHALL declare as applicable:

  • subject identity is accurate;
  • known material changes are disclosed;
  • known material Findings are disclosed;
  • prior certification history is disclosed;
  • prior suspension or withdrawal is disclosed;
  • evidence is authentic;
  • conflicts are disclosed;
  • certification claims will follow Scheme rules;
  • surveillance obligations are accepted.

27.26.7. Known Non-Conformity Declaration

Known material non-conformities SHALL be disclosed.

Disclosure SHALL not automatically prohibit application unless the Scheme requires.

Concealment MAY trigger rejection, suspension or withdrawal.


27.26.8. Prior Certification Disclosure

The applicant SHALL disclose:

  • active Certificates;
  • expired Certificates;
  • suspended Certificates;
  • withdrawn Certificates;
  • rejected applications;
  • relevant external certifications;
  • unresolved appeals;
  • provenance.

27.26.9. Application Evidence

Application evidence MAY include:

  • legal identity;
  • subject ownership;
  • subject inventory;
  • Scope Manifest;
  • Baseline;
  • Profile;
  • existing Assessment Package;
  • external Certificates;
  • policies;
  • declarations;
  • competence records;
  • prior Findings;
  • provenance.

27.26.10. Application Admission Gate

The Gate SHALL evaluate:

  • valid Scheme;
  • valid applicant identity;
  • authority to apply;
  • eligible subject;
  • requested scope;
  • claim validity;
  • Baseline;
  • Profile availability;
  • assessment feasibility;
  • Certification Body competence;
  • conflicts;
  • sanctions or restrictions;
  • provenance.

27.26.11. Admission Outcomes

Outcomes MAY include:

  • Admitted;
  • Admitted with Scope Clarification;
  • Additional Information Required;
  • Deferred;
  • Rejected as Ineligible;
  • Referred to Another Scheme;
  • Conflict Review Required;
  • Indeterminate.

27.26.12. Application Rejection

Rejection SHALL identify:

  • reason;
  • Scheme rule;
  • missing or invalid condition;
  • appeal path;
  • resubmission conditions;
  • provenance.

27.26.13. Certification Agreement

A Certification Agreement MAY govern:

  • subject and scope;
  • Scheme;
  • assessment access;
  • evidence;
  • confidentiality;
  • surveillance;
  • change notification;
  • mark use;
  • public status;
  • fees;
  • complaints;
  • appeals;
  • suspension;
  • withdrawal;
  • records;
  • termination.

Commercial terms SHALL not alter certification criteria or decision independence.


27.26.14. Contractual Independence

The Certification Agreement SHALL state that:

  • payment does not guarantee certification;
  • commercial pressure does not alter Findings;
  • the applicant cannot direct the Certification Decision;
  • non-payment treatment shall not misrepresent conformance;
  • termination does not erase historical status.

27.26.15. Confidentiality Boundary

Confidentiality SHALL define:

  • protected application information;
  • assessor access;
  • Certification Body access;
  • accreditation access;
  • regulator access;
  • public fields;
  • incident disclosure;
  • appeal disclosure;
  • archive;
  • provenance.

27.26.16. Certification Fees

Fees MAY cover:

  • application;
  • assessment;
  • review;
  • surveillance;
  • travel;
  • verification services;
  • mark licensing.

Fees SHALL be transparent enough to assess conflicts.


27.26.17. Contingent Fee Prohibition

Certification fees SHOULD NOT depend on granting certification, outcome severity or suppression of Findings.


27.26.18. Application Change

A material application change SHALL identify:

  • changed applicant;
  • changed subject;
  • changed version;
  • changed scope;
  • changed Baseline;
  • changed Profile;
  • changed claim;
  • changed tenant population;
  • changed Modules or Components;
  • changed Extensions;
  • impact;
  • approval;
  • provenance.

27.26.19. Application Withdrawal

An applicant MAY withdraw an application.

Withdrawal SHALL preserve:

  • application;
  • reason where provided;
  • completed activities;
  • Findings;
  • evidence retention;
  • claim restrictions;
  • fees where applicable;
  • provenance.

A withdrawn application SHALL not be represented as rejection or certification.


27.26.20. Application Transfer

Application transfer to another Certification Body SHALL require:

  • Scheme permission;
  • applicant consent;
  • transferring body;
  • receiving body;
  • Assessment Package integrity;
  • unresolved Findings;
  • conflicts;
  • confidentiality;
  • authority;
  • provenance.

27.26.21. Application Lifecycle

Lifecycle states MAY include:

  • Draft;
  • Submitted;
  • Under Admission Review;
  • Admitted;
  • Additional Information Required;
  • Assessment Planned;
  • Assessment Active;
  • Certification Review;
  • Decision Pending;
  • Granted;
  • Rejected;
  • Deferred;
  • Withdrawn;
  • Transferred;
  • Closed;
  • Archived.

27.26.22. Application Registry

The Application Registry SHALL preserve:

  • applications;
  • applicants;
  • Schemes;
  • requested scopes;
  • declarations;
  • admission;
  • changes;
  • withdrawal;
  • transfer;
  • lifecycle;
  • provenance.

27.26.23. Application Receipt

A receipt SHOULD contain:

  • Application;
  • applicant;
  • Scheme;
  • requested subject and scope;
  • declarations;
  • admission outcome;
  • Certification Body;
  • time;
  • provenance.

27.26.24. Application Validation

HECATE SHALL validate:

  • Application identity;
  • Scheme;
  • applicant;
  • authority to apply;
  • subject identity;
  • requested scope;
  • declarations;
  • conflicts;
  • admission;
  • changes;
  • lifecycle;
  • provenance.

27.27. Certification Review and Decision

Certification Review is the governed evaluation of whether the assessment, subject, scope, Findings, exceptions, conditions and evidence satisfy the Certification Scheme.

The Certification Decision SHALL be made by valid authority independent of assessment execution where the Scheme requires.


27.27.1. Certification Review Package

Every Certification Review SHALL use a Certification Review Package containing:

  • Certification Application;
  • Scheme and version;
  • subject;
  • Subject Snapshot;
  • Baseline;
  • Profile;
  • Scope Manifest;
  • final Assessment Package;
  • Conformance Outcome;
  • Finding inventory;
  • exception inventory;
  • remediation state;
  • proposed conditions;
  • surveillance recommendation;
  • claim recommendation;
  • limitations;
  • provenance.

27.27.2. Review Identity

Every Certification Review SHALL possess:

  • Review Identifier;
  • Application;
  • Scheme;
  • Package digest;
  • reviewer;
  • reviewer authority;
  • reviewer competence;
  • independence;
  • review criteria;
  • start and completion time;
  • Findings;
  • recommendation;
  • provenance.

27.27.3. Review Independence

The reviewer SHALL not be the sole person who:

  • performed the assessment;
  • implemented the subject;
  • owns the assessed Module;
  • operates the assessed Component;
  • authored material evidence;
  • sells contingent certification services;
  • represents the applicant.

27.27.4. Review Competence

Review competence SHALL cover:

  • Scheme;
  • Conformance Profiles;
  • subject class;
  • Baseline;
  • assessment methods;
  • evidence;
  • Findings;
  • relevant jurisdiction;
  • certification decision rules.

27.27.5. Review Criteria

Certification Review SHALL evaluate:

  • applicant eligibility;
  • subject identity;
  • Scope Manifest;
  • Snapshot integrity;
  • Baseline validity;
  • Profile validity;
  • assessment authority;
  • assessor competence;
  • assessor independence;
  • assessment completeness;
  • CTM completeness;
  • evidence sufficiency;
  • sampling;
  • Findings;
  • exceptions;
  • remediation;
  • Outcome;
  • proposed claims;
  • surveillance readiness;
  • provenance.

27.27.6. Review Finding

A Review Finding SHALL identify:

  • review criterion;
  • observed state;
  • expected state;
  • affected assessment or application;
  • severity;
  • required action;
  • provenance.

27.27.7. Additional Assessment Request

The reviewer MAY require:

  • additional evidence;
  • additional Test;
  • expanded sample;
  • independent review;
  • clarification;
  • scope reduction;
  • remediation;
  • reassessment.

The request SHALL identify why it is necessary.


27.27.8. Certification Recommendation

Recommendation classes MAY include:

  • Recommend Grant;
  • Recommend Grant with Conditions;
  • Recommend Restricted Scope;
  • Recommend Deferral;
  • Recommend Additional Assessment;
  • Recommend Rejection;
  • Unable to Recommend.

A recommendation SHALL not itself grant certification.


27.27.9. Certification Decision Request

Every Decision Request SHALL contain:

  • Decision Request Identifier;
  • Application;
  • Scheme;
  • Review;
  • Review Package digest;
  • recommendation;
  • unresolved matters;
  • proposed scope;
  • proposed conditions;
  • proposed validity;
  • proposed surveillance;
  • provenance.

27.27.10. Certification Decision Authority

The Decision Authority SHALL possess:

  • valid Role;
  • Scheme scope;
  • subject-class scope;
  • jurisdictional scope;
  • competence;
  • independence;
  • active authority;
  • no disqualifying conflict;
  • provenance.

27.27.11. Decision Maker

A Decision Maker MAY be:

  • authorised individual;
  • certification committee;
  • multi-role panel;
  • automated objective decision Component where the Scheme explicitly permits;
  • authorised external Certification Body.

27.27.12. Automated Certification Decision

Automated certification MAY be permitted only where:

  • subject scope is narrow;
  • all Criteria are objective;
  • Scheme explicitly authorises automation;
  • Certification Authority is assigned to the decision service;
  • rules are deterministic and versioned;
  • no exception or unresolved Finding exists;
  • appeal remains available;
  • decision integrity is independently monitored.

An AI model SHALL not be the sole automated Certification Decision Maker.


27.27.13. Certification Committee

A committee SHALL preserve:

  • membership;
  • Roles;
  • competence;
  • independence;
  • conflicts;
  • quorum;
  • votes or concurrence;
  • dissent;
  • decision;
  • provenance.

27.27.14. Decision Preconditions

Preconditions SHALL include:

  • active Scheme;
  • admitted Application;
  • exact subject;
  • exact Snapshot;
  • valid Baseline;
  • valid Assessment Package;
  • acceptable Conformance Outcome;
  • review complete;
  • no unresolved certification-blocking Finding;
  • valid exceptions;
  • valid authority;
  • provenance complete.

27.27.15. Decision Classes

Decision Classes MAY include:

  • Grant Certification;
  • Grant with Conditions;
  • Grant Restricted Scope;
  • Defer;
  • Additional Assessment Required;
  • Reject;
  • Unable to Decide;
  • Application Withdrawn.

27.27.16. Grant Certification

Grant SHALL identify:

  • certified subject;
  • Snapshot or version;
  • Baseline;
  • scope;
  • certified characteristics;
  • conditions;
  • exclusions;
  • validity;
  • surveillance;
  • claims;
  • mark eligibility;
  • provenance.

27.27.17. Grant with Conditions

Every condition SHALL identify:

  • condition;
  • affected requirement;
  • owner;
  • due time;
  • interim state;
  • monitoring;
  • public disclosure;
  • failure consequence;
  • provenance.

27.27.18. Restricted Scope

A Restricted-Scope Decision SHALL identify:

  • requested scope;
  • certified scope;
  • excluded scope;
  • reason;
  • dependencies;
  • public-claim restriction;
  • surveillance;
  • provenance.

27.27.19. Deferral

Deferral SHALL identify:

  • unresolved matter;
  • required action;
  • owner;
  • deadline;
  • whether the assessment remains valid;
  • evidence freshness;
  • provenance.

27.27.20. Rejection

Rejection SHALL identify:

  • blocking requirement;
  • Findings;
  • evidence;
  • scope;
  • appeal;
  • reapplication conditions;
  • provenance.

27.27.21. Unable to Decide

Unable to Decide SHALL be used where authority, evidence, competence, conflict or procedure prevents a valid Decision.

It SHALL not be represented as rejection or certification.


27.27.22. Decision Rationale

Every Decision SHALL preserve:

  • Scheme criteria;
  • assessment basis;
  • material Findings;
  • exceptions;
  • conditions;
  • scope;
  • reasoning;
  • limitations;
  • provenance.

27.27.23. Decision Signature

The signature SHALL bind:

  • Decision Identifier;
  • Scheme and version;
  • Application;
  • subject;
  • Snapshot digest;
  • Baseline;
  • Assessment Package digest;
  • scope;
  • conditions;
  • validity;
  • decision maker;
  • authority;
  • time;
  • key;
  • provenance.

27.27.24. Multiple Signatures

A Scheme MAY require signatures from:

  • Decision Maker;
  • Certification Body;
  • technical reviewer;
  • independent reviewer;
  • Scheme Authority;
  • accreditation witness.

Each signature SHALL identify its scope.


27.27.25. Decision Notification

Notification SHALL identify:

  • Decision;
  • certified or rejected scope;
  • conditions;
  • validity;
  • surveillance;
  • claim rules;
  • appeal;
  • verification;
  • provenance reference.

27.27.26. Decision Correction

An administrative error MAY be corrected where meaning is unchanged.

A material decision error SHALL require:

  • renewed review;
  • new Certification Decision;
  • Certificate correction, suspension or withdrawal;
  • public-status update;
  • provenance.

27.27.27. Decision Supersession

A Decision MAY be superseded by:

  • scope extension;
  • scope reduction;
  • recertification;
  • transfer;
  • suspension;
  • withdrawal;
  • reinstatement;
  • corrected Decision.

The prior Decision SHALL remain historically preserved.


27.27.28. Certification Decision Registry

The Registry SHALL preserve:

  • Decision Requests;
  • reviews;
  • recommendations;
  • Decisions;
  • authorities;
  • signatures;
  • conditions;
  • corrections;
  • supersession;
  • provenance.

27.27.29. Decision Receipt

A receipt SHOULD contain:

  • Application;
  • Scheme;
  • subject;
  • Snapshot;
  • Assessment Package digest;
  • Review;
  • recommendation;
  • Decision;
  • scope;
  • conditions;
  • validity;
  • signatures;
  • provenance.

27.27.30. Decision Validation

HECATE SHALL validate:

  • Review Package;
  • reviewer competence;
  • reviewer independence;
  • Decision Request;
  • Decision Authority;
  • preconditions;
  • Decision;
  • rationale;
  • scope;
  • conditions;
  • signature;
  • Registry state;
  • provenance.

HECATE SHALL not convert a recommendation into certification without valid Decision Authority.


27.28. Certificate Issuance, Registry, Claims and Marks

A Certificate is the integrity-protected representation of a valid Certification Decision.

Certificate issuance SHALL reproduce the Decision exactly.

The Certificate SHALL not expand certified scope, duration, claim or authority.


27.28.1. Certificate Identity

Every Certificate SHALL possess:

  • Certificate Identifier;
  • Certification Scheme;
  • Scheme version;
  • Certification Decision;
  • certified subject;
  • Subject Snapshot or version;
  • Constitutional Baseline;
  • certified scope;
  • certified characteristics;
  • exclusions;
  • conditions;
  • status;
  • issue time;
  • effective time;
  • expiration;
  • Certification Body;
  • signatures;
  • verification reference;
  • provenance.

27.28.2. Certificate Classes

Certificate Classes MAY include:

  • Core Baseline Certificate;
  • Runtime Bundle Certificate;
  • Module Certificate;
  • Component Certificate;
  • Extension Certificate;
  • Tenant Certificate;
  • White-Label Certificate;
  • Organisation Certificate;
  • Publication-System Certificate;
  • Security Certificate;
  • Tenant-Isolation Certificate;
  • Migration Certificate;
  • Historical-Trust Certificate;
  • Certification-Body Certificate.

27.28.3. Certificate Manifest

Every high-assurance Certificate SHOULD possess a Certificate Manifest containing:

  • Certificate Identifier;
  • Scheme;
  • Decision digest;
  • subject identity;
  • Snapshot digest;
  • Baseline;
  • Scope Manifest digest;
  • certified characteristics;
  • conditions;
  • exclusions;
  • validity;
  • surveillance plan;
  • public claim;
  • status endpoint;
  • signatures;
  • provenance.

27.28.4. Certificate Issuance Request

Every issuance request SHALL contain:

  • Certification Decision;
  • exact certified scope;
  • exact claim;
  • exact validity;
  • conditions;
  • Certificate template or schema;
  • signature requirements;
  • Publication Profile;
  • issuer;
  • provenance.

27.28.5. Issuance Authority

Certificate issuance authority MAY be assigned to:

  • Certification Body;
  • Scheme Authority;
  • governed Certificate Issuance Component.

Issuance authority SHALL not grant Certification Decision Authority.


27.28.6. Certificate Issuance Gate

The Gate SHALL validate:

  • valid Decision;
  • Decision finality;
  • Decision signature;
  • exact subject;
  • exact Snapshot;
  • exact Baseline;
  • exact scope;
  • exact conditions;
  • exact validity;
  • issuer authority;
  • Certificate schema;
  • verification registration;
  • provenance.

27.28.7. Certificate Content Fidelity

Certificate issuance SHALL NOT:

  • broaden scope;
  • remove exclusions;
  • remove conditions;
  • change validity;
  • change subject identity;
  • omit Baseline;
  • imply accreditation not held;
  • imply regulator approval not held;
  • alter Scheme wording;
  • hide restrictions.

27.28.8. Certificate Format

Certificate formats MAY include:

  • signed structured data;
  • signed PDF;
  • verifiable credential;
  • machine-readable Registry record;
  • human-readable web record;
  • printed Certificate with verification reference.

The authoritative Certificate representation SHALL be identified.


27.28.9. Machine-Readable Certificate

A machine-readable Certificate SHOULD support:

  • subject resolution;
  • Scheme resolution;
  • status resolution;
  • signature verification;
  • validity evaluation;
  • scope inspection;
  • condition inspection;
  • supersession;
  • revocation;
  • provenance.

27.28.10. Human-Readable Certificate

The human-readable representation SHALL state clearly:

  • what is certified;
  • under which Scheme;
  • against which Baseline;
  • for which scope;
  • from which date;
  • until which date;
  • with which conditions;
  • with which exclusions;
  • how to verify status.

27.28.11. Certificate Signature

A Certificate Signature SHALL bind:

  • Certificate Identifier;
  • Certificate Manifest digest;
  • Certification Decision digest;
  • subject;
  • scope;
  • validity;
  • signer;
  • issuer authority;
  • time;
  • key;
  • provenance.

27.28.12. Certificate Root of Trust

The Scheme SHALL define:

  • trusted issuers;
  • trusted keys;
  • trust anchors;
  • key rotation;
  • revocation;
  • timestamping;
  • historical verification;
  • compromise treatment.

27.28.13. Certificate Status

Certificate status MAY include:

  • Pending Issuance;
  • Active;
  • Active with Conditions;
  • Restricted;
  • Surveillance Due;
  • Under Review;
  • Suspended;
  • Scope Reduced;
  • Expired;
  • Withdrawn;
  • Superseded;
  • Invalid;
  • Historical.

27.28.14. Immutable Certificate Principle

An issued Certificate SHALL remain immutable.

A status change SHALL create a status record linked to the Certificate.


27.28.15. Certificate Status Record

Every status record SHALL possess:

  • Status Record Identifier;
  • Certificate;
  • prior status;
  • new status;
  • reason;
  • authority;
  • effective time;
  • affected scope;
  • public treatment;
  • provenance.

27.28.16. Certificate Registry

The Certificate Registry SHALL preserve:

  • Certificate identities;
  • Scheme and version;
  • subjects;
  • Snapshot digests;
  • Baselines;
  • scopes;
  • conditions;
  • status;
  • validity;
  • Decision references;
  • Certification Body;
  • signatures;
  • status history;
  • provenance.

27.28.17. Public Certificate Registry

A public Registry MAY expose:

  • Certificate Identifier;
  • certified subject;
  • Scheme;
  • certified scope;
  • status;
  • issue time;
  • expiration;
  • conditions at permitted disclosure level;
  • Certification Body;
  • verification;
  • provenance summary.

27.28.18. Restricted Registry Fields

Restricted fields MAY include:

  • tenant-confidential scope;
  • detailed Findings;
  • security-sensitive conditions;
  • commercial terms;
  • privileged evidence;
  • personal data.

Restrictions SHALL not make the public claim misleading.


27.28.19. Certification Claim Object

Every formal certification claim SHALL possess:

  • Claim Identifier;
  • Certificate;
  • subject;
  • claim text;
  • scope;
  • audience;
  • channel;
  • language;
  • validity;
  • verification reference;
  • approval;
  • lifecycle;
  • provenance.

27.28.20. Claim Classes

Claim Classes MAY include:

  • Certificate Statement;
  • Product Claim;
  • Service Claim;
  • Module Claim;
  • Component Claim;
  • Extension Claim;
  • Tenant Claim;
  • White-Label Claim;
  • Organisation Claim;
  • Public Website Claim;
  • Procurement Claim;
  • Regulatory Submission Claim;
  • Publication Claim.

27.28.21. Claim Fidelity

A claim SHALL NOT exceed:

  • certified subject;
  • certified scope;
  • certified characteristics;
  • active validity;
  • permitted Scheme wording;
  • current Certificate status.

27.28.22. Prohibited Claim Implications

Claims SHALL not imply:

  • universal legal compliance;
  • universal ESG excellence;
  • environmental superiority;
  • future performance;
  • absence of incidents;
  • certification of the applicant's entire organisation where only a Component is certified;
  • certification of every tenant where only one tenant is certified;
  • accreditation where only certification exists;
  • regulator endorsement where none exists.

27.28.23. Conditional Claim

A claim based on conditional certification SHALL disclose material conditions according to the Scheme and CPF.


27.28.24. Restricted-Scope Claim

A Restricted-Scope Certificate SHALL not be presented as whole-system certification.


27.28.25. Certification Mark

Every certification mark SHALL possess:

  • Mark Identifier;
  • Scheme;
  • permitted Certificate classes;
  • visual or machine form;
  • usage rules;
  • minimum verification reference;
  • status dependency;
  • language rules;
  • modification rules;
  • withdrawal rules;
  • provenance.

27.28.26. Mark Licence

A mark licence SHALL identify:

  • licensee;
  • Certificate;
  • permitted uses;
  • territories;
  • channels;
  • start and end;
  • monitoring;
  • suspension;
  • termination;
  • provenance.

Mark licensing SHALL not alter certification scope.


27.28.27. Dynamic Mark

A dynamic mark SHOULD resolve current status from the Certificate Registry.

It MAY display:

  • active;
  • conditional;
  • suspended;
  • expired;
  • withdrawn;
  • verification unavailable.

27.28.28. Static Mark

A static mark SHALL include a durable verification reference.

It SHALL be removed or corrected where status changes according to Scheme rules.


27.28.29. Badge Misuse

Misuse MAY include:

  • mark used without Certificate;
  • mark used after expiration;
  • mark used during suspension;
  • mark used for unscoped products;
  • mark altered misleadingly;
  • verification link removed;
  • mark associated with a different legal entity;
  • mark implying accreditation.

27.28.30. Claim Approval

High-impact claims SHOULD require approval by:

  • certified-subject owner;
  • Certification Body or Scheme Authority where required;
  • Publication Authority;
  • legal or regulatory reviewer where required.

27.28.31. Claim Monitoring

Claim monitoring MAY include:

  • website scanning;
  • document review;
  • procurement-material review;
  • Publication review;
  • API review;
  • marketplace review;
  • tenant portal review;
  • white-label review;
  • public complaint intake.

27.28.32. Claim Correction

An inaccurate claim SHALL be:

  • corrected;
  • restricted;
  • withdrawn;
  • publicly clarified;
  • escalated

according to severity and Scheme rules.


27.28.33. Certificate Correction

An administrative Certificate error MAY be corrected through a governed correction record and reissued representation.

A material scope, subject, validity or Decision error SHALL require a new Certification Decision.


27.28.34. Certificate Supersession

A Certificate MAY be superseded due to:

  • recertification;
  • scope extension;
  • scope reduction;
  • Scheme transition;
  • subject-version change;
  • ownership transfer;
  • corrected Decision.

27.28.35. Certificate Verification Receipt

A verification receipt SHOULD contain:

  • Certificate Identifier;
  • Registry status;
  • subject;
  • Scheme;
  • scope;
  • validity;
  • signature state;
  • verification time;
  • supersession or withdrawal state;
  • provenance.

27.28.36. Certificate and Claim Validation

HECATE SHALL validate:

  • issuance request;
  • Decision binding;
  • Certificate Manifest;
  • content fidelity;
  • signature;
  • Registry record;
  • status;
  • claim scope;
  • mark eligibility;
  • verification reference;
  • correction;
  • supersession;
  • provenance.

27.29. Surveillance and Continued Certification

Certification SHALL remain valid only while the certified subject continues to satisfy the Scheme within the certified scope.

Surveillance SHALL provide proportionate evidence of continued conformance.


27.29.1. Surveillance Plan

Every Certificate requiring surveillance SHALL possess a Surveillance Plan containing:

  • Surveillance Plan Identifier;
  • Certificate;
  • Scheme;
  • certified subject;
  • certified scope;
  • Baseline;
  • Profile;
  • surveillance period;
  • surveillance methods;
  • evidence requirements;
  • sampling;
  • change-notification triggers;
  • incident-notification triggers;
  • assessor;
  • reviewer;
  • decision rules;
  • provenance.

27.29.2. Surveillance Types

Surveillance Types MAY include:

  • Continuous Surveillance;
  • Periodic Surveillance;
  • Annual Surveillance;
  • Risk-Based Surveillance;
  • Change-Triggered Surveillance;
  • Incident-Triggered Surveillance;
  • Complaint-Triggered Surveillance;
  • Unannounced Surveillance;
  • Remote Surveillance;
  • On-Site Surveillance;
  • Document-Only Surveillance;
  • Technical Continuous-Control Surveillance.

27.29.3. Surveillance Scope

Surveillance SHALL identify:

  • requirements monitored;
  • Controls monitored;
  • evidence refreshed;
  • subject versions;
  • environments;
  • tenants;
  • white-label deployments;
  • Modules;
  • Components;
  • Extensions;
  • Runtime state;
  • Publications;
  • certification claims.

27.29.4. Continued-Conformance Baseline

Surveillance SHALL determine whether the original Baseline and Profile remain applicable.

Where the Scheme transitions, the Surveillance Plan SHALL identify the target basis.


27.29.5. Change Notification Obligation

The certified party SHALL notify material change including:

  • legal identity;
  • ownership;
  • certified subject;
  • subject version;
  • Constitutional Baseline;
  • Runtime Bundle;
  • Runtime Manifest;
  • Module ownership;
  • Component version;
  • Extension Set;
  • tenant population;
  • white-label operator;
  • jurisdiction;
  • policy;
  • methodology;
  • model;
  • Agent Profile;
  • tool permission;
  • security architecture;
  • Publication process;
  • significant supplier.

27.29.6. Material Change Object

Every material change SHALL possess:

  • Change Notification Identifier;
  • Certificate;
  • changed subject;
  • prior state;
  • new state;
  • reason;
  • effective time;
  • affected scope;
  • self-assessed impact;
  • evidence;
  • submitter;
  • provenance.

27.29.7. Change Triage

Change triage SHALL classify:

  • no certification impact;
  • administrative update;
  • surveillance update;
  • partial reassessment;
  • full reassessment;
  • scope extension;
  • scope reduction;
  • suspension review;
  • recertification required;
  • Scheme transition required;
  • Indeterminate.

27.29.8. Incident Notification Obligation

The certified party SHALL notify material incidents affecting:

  • evidence integrity;
  • tenant isolation;
  • security;
  • certified capability;
  • certification claim;
  • Runtime Admission;
  • Publication;
  • key material;
  • regulatory status;
  • subject availability;
  • historical trust.

27.29.9. Incident Triage

Incident triage SHALL identify:

  • Certificate;
  • subject;
  • affected scope;
  • severity;
  • containment;
  • continued-certification impact;
  • reassessment;
  • public-status impact;
  • provenance.

27.29.10. Surveillance Assessment

A Surveillance Assessment SHALL possess:

  • Assessment Identifier;
  • Certificate;
  • subject Snapshot;
  • scope;
  • Profile;
  • methods;
  • evidence;
  • Findings;
  • change review;
  • incident review;
  • claim review;
  • recommendation;
  • provenance.

27.29.11. Surveillance Sampling

Sampling SHALL consider:

  • prior Findings;
  • prior conditions;
  • tenant variation;
  • Extension changes;
  • Module and Component changes;
  • incident history;
  • public claims;
  • high-risk operations;
  • prior sampling limitations.

27.29.12. Surveillance Finding

A Surveillance Finding SHALL identify:

  • Certificate;
  • affected requirement;
  • observed state;
  • prior assessed state;
  • evidence;
  • severity;
  • materiality;
  • scope;
  • certification effect;
  • provenance.

27.29.13. Condition Monitoring

Every certification condition SHALL have:

  • owner;
  • due time;
  • evidence;
  • monitoring;
  • completion criteria;
  • failure consequence;
  • status;
  • provenance.

27.29.14. Condition Closure

Condition closure SHALL require:

  • required action;
  • evidence;
  • validation;
  • Certification Body review;
  • status update;
  • provenance.

27.29.15. Surveillance Outcome

Outcome Classes MAY include:

  • Maintain Certification;
  • Maintain with Conditions;
  • Increase Surveillance;
  • Partial Reassessment Required;
  • Full Reassessment Required;
  • Reduce Scope;
  • Suspend;
  • Withdraw;
  • Unable to Conclude.

27.29.16. Maintain Certification

Maintenance SHALL require:

  • no unresolved blocking Finding;
  • conditions satisfied or validly continued;
  • evidence sufficient;
  • change notifications treated;
  • incidents treated;
  • claims accurate;
  • authority valid;
  • provenance complete.

27.29.17. Increased Surveillance

Increased surveillance SHALL identify:

  • reason;
  • scope;
  • frequency;
  • evidence;
  • duration;
  • exit criteria;
  • public disclosure where required;
  • provenance.

27.29.18. Continuous Certification State

A Continuous Certification State MAY include:

  • Current;
  • Current with Conditions;
  • At Risk;
  • Surveillance Overdue;
  • Reassessment Required;
  • Suspended;
  • Withdrawn;
  • Indeterminate.

27.29.19. Surveillance Overdue

Overdue surveillance SHALL trigger according to the Scheme:

  • warning;
  • claim restriction;
  • status change;
  • suspension;
  • expiration;
  • withdrawal.

27.29.20. Surveillance Independence

The Scheme SHALL define whether surveillance assessors and reviewers must be independent from:

  • certified-subject operation;
  • prior remediation;
  • prior assessment;
  • Certification Decision;
  • applicant consulting.

27.29.21. Unannounced Surveillance

Unannounced surveillance MAY be permitted where:

  • Scheme states it;
  • contractual and legal authority exists;
  • tenant and security boundaries are protected;
  • access is proportionate;
  • provenance is preserved.

27.29.22. Remote Surveillance

Remote surveillance SHALL identify limitations in:

  • observation;
  • evidence authenticity;
  • access;
  • tenant confidentiality;
  • physical Controls;
  • scope.

27.29.23. Continuous-Control Integration

Continuous Controls MAY feed surveillance where:

  • Control identity is known;
  • implementing Component is known;
  • evidence integrity is protected;
  • tenant context is preserved;
  • thresholds are governed;
  • automation failures are treated.

27.29.24. Certificate Drift

Certificate Drift exists where current subject state differs materially from certified state.

Drift SHALL identify:

  • certified Snapshot;
  • current Snapshot;
  • changed elements;
  • affected requirements;
  • affected Modules and Components;
  • affected tenants;
  • certification effect;
  • provenance.

27.29.25. Claim Drift

Claim Drift exists where public or private claims exceed current Certificate status or scope.


27.29.26. Surveillance Decision

Every Surveillance Decision SHALL possess:

  • Decision Identifier;
  • Certificate;
  • surveillance assessment;
  • Findings;
  • changes;
  • incidents;
  • decision;
  • conditions;
  • scope;
  • status effect;
  • authority;
  • time;
  • signature;
  • provenance.

27.29.27. Surveillance Notification

Notification SHALL identify:

  • Certificate;
  • surveillance outcome;
  • conditions;
  • required action;
  • status;
  • public claim effect;
  • next surveillance;
  • appeal;
  • provenance reference.

27.29.28. Surveillance Registry

The Registry SHALL preserve:

  • Plans;
  • assessments;
  • evidence;
  • Findings;
  • changes;
  • incidents;
  • Decisions;
  • conditions;
  • status effects;
  • provenance.

27.29.29. Surveillance Receipt

A receipt SHOULD contain:

  • Certificate;
  • Plan;
  • subject Snapshot;
  • methods;
  • evidence;
  • Findings;
  • changes;
  • incidents;
  • Decision;
  • status;
  • next action;
  • provenance.

27.29.30. Surveillance Validation

HECATE SHALL validate:

  • Plan;
  • scope;
  • evidence;
  • change notifications;
  • incident notifications;
  • Findings;
  • conditions;
  • Outcome;
  • Decision Authority;
  • status update;
  • provenance.

27.30. Scope Extension, Reduction, Suspension, Withdrawal and Expiration

Certification lifecycle controls SHALL ensure that current status accurately reflects current subject state, evidence, scope and Scheme validity.

Scope extension, scope reduction, suspension, withdrawal and expiration SHALL remain distinct.


27.30.1. Scope Extension Request

Every Scope Extension Request SHALL identify:

  • Certificate;
  • existing scope;
  • requested added scope;
  • added subjects;
  • added versions;
  • added tenants or white-label deployments;
  • added Modules;
  • added Components;
  • added Extensions;
  • added jurisdictions;
  • assessment need;
  • evidence;
  • provenance.

27.30.2. Scope Extension Assessment

Extension SHALL require assessment proportionate to:

  • added requirements;
  • shared Controls;
  • new dependencies;
  • tenant variation;
  • new Runtime state;
  • new Publication claims;
  • new risk;
  • prior Findings.

27.30.3. Scope Extension Decision

Decision Classes MAY include:

  • Grant Extension;
  • Grant Extension with Conditions;
  • Grant Partial Extension;
  • Additional Assessment Required;
  • Reject Extension;
  • Unable to Decide.

27.30.4. Scope Reduction

Scope may be reduced due to:

  • applicant request;
  • subject retirement;
  • non-conformity;
  • loss of support;
  • tenant exit;
  • white-label exit;
  • Module or Component change;
  • Extension withdrawal;
  • jurisdictional change;
  • Scheme transition.

27.30.5. Scope Reduction Object

Every Scope Reduction SHALL possess:

  • Reduction Identifier;
  • Certificate;
  • prior scope;
  • remaining scope;
  • removed scope;
  • reason;
  • authority;
  • effective time;
  • claim treatment;
  • Certificate status;
  • provenance.

27.30.6. Voluntary Reduction

Voluntary reduction SHALL not conceal known non-conformity.

Where non-conformity caused removal, the reason SHALL be recorded according to disclosure policy.


27.30.7. Certification Suspension

Suspension temporarily invalidates use of certification claims for defined scope while preserving the possibility of reinstatement.


27.30.8. Suspension Object

Every Suspension SHALL possess:

  • Suspension Identifier;
  • Certificate;
  • reason;
  • affected scope;
  • authority;
  • start time;
  • expected duration;
  • required actions;
  • permitted residual claims;
  • mark treatment;
  • Runtime treatment;
  • Publication treatment;
  • surveillance;
  • reinstatement criteria;
  • provenance.

27.30.9. Suspension Triggers

Triggers MAY include:

  • critical Finding;
  • overdue condition;
  • overdue surveillance;
  • evidence-integrity concern;
  • material subject change;
  • security incident;
  • tenant-isolation incident;
  • misleading claim;
  • mark misuse;
  • loss of Certification Body authority;
  • Scheme suspension;
  • applicant obstruction;
  • unresolved complaint;
  • invalid signature;
  • non-payment where Scheme lawfully permits.

27.30.10. Immediate Suspension

Immediate suspension MAY be required for:

  • active cross-tenant leakage;
  • falsified evidence;
  • compromised Certificate key;
  • invalid certification authority;
  • materially misleading public claim;
  • unlawful certified operation;
  • critical unresolved security risk.

27.30.11. Partial Suspension

Partial suspension SHALL identify exact affected scope.

Unaffected certified scope MAY remain active only where it remains coherent and non-misleading.


27.30.12. Suspension Notice

Notice SHALL identify:

  • Certificate;
  • scope;
  • reason at the authorised disclosure level;
  • start time;
  • required actions;
  • claim restrictions;
  • mark restrictions;
  • appeal;
  • verification reference.

27.30.13. Suspension Public Status

Public verification SHALL show suspension promptly according to Scheme requirements.


27.30.14. Suspension During Appeal

An appeal MAY or MAY NOT stay suspension according to Scheme rules and risk.

The stay treatment SHALL be explicit.


27.30.15. Suspension Remediation

Remediation SHALL identify:

  • triggering Finding;
  • actions;
  • owner;
  • deadline;
  • evidence;
  • reassessment;
  • surveillance;
  • provenance.

27.30.16. Reinstatement

Reinstatement SHALL require:

  • cause resolved;
  • remediation validated;
  • current Scheme;
  • current subject identity;
  • current scope;
  • evidence sufficient;
  • authority valid;
  • claim controls restored;
  • provenance complete.

27.30.17. Reinstatement Decision

Every Decision SHALL identify:

  • Suspension;
  • remediation;
  • reassessment;
  • scope;
  • conditions;
  • validity;
  • surveillance;
  • authority;
  • effective time;
  • provenance.

27.30.18. Certification Withdrawal

Withdrawal terminates certification for the affected scope.

It SHALL not erase the historical Certificate or Decision.


27.30.19. Withdrawal Object

Every Withdrawal SHALL possess:

  • Withdrawal Identifier;
  • Certificate;
  • reason;
  • affected scope;
  • authority;
  • effective time;
  • required claim cessation;
  • mark treatment;
  • public status;
  • Runtime treatment;
  • Publication treatment;
  • archive;
  • appeal;
  • provenance.

27.30.20. Withdrawal Triggers

Triggers MAY include:

  • persistent non-conformity;
  • unresolved suspension;
  • falsified evidence;
  • invalid Decision;
  • compromised authority;
  • intentional claim misuse;
  • subject no longer exists;
  • Scheme withdrawn;
  • applicant request;
  • Certification Body loss of authority;
  • refusal of surveillance;
  • failure to notify material change;
  • unlawful certified operation.

27.30.21. Voluntary Withdrawal

An applicant request SHALL identify:

  • reason where provided;
  • affected scope;
  • effective time;
  • active claims;
  • active contracts;
  • customer or tenant notification;
  • archive;
  • provenance.

Voluntary withdrawal SHALL not suppress prior material Findings.


27.30.22. Forced Withdrawal

Forced withdrawal SHALL require:

  • valid authority;
  • evidence;
  • Decision;
  • notice;
  • appeal path;
  • public-status update;
  • claim enforcement;
  • provenance.

27.30.23. Certificate Expiration

Expiration occurs when validity ends without renewal.

Expiration SHALL be distinct from suspension and withdrawal.


27.30.24. Expiration Treatment

At expiration:

  • status SHALL change;
  • new certification claims SHALL cease;
  • marks SHALL be treated according to Scheme;
  • public verification SHALL show expired status;
  • historical claims MAY remain verifiable;
  • Runtime or procurement dependencies SHALL reassess.

27.30.25. Grace Period

A grace period MAY permit administrative completion of renewal but SHALL define:

  • duration;
  • claim rules;
  • mark rules;
  • surveillance;
  • risk;
  • public status;
  • provenance.

A grace period SHALL not silently extend the Certificate.


27.30.26. Invalid Certificate

A Certificate MAY be classified Invalid where:

  • no valid Decision existed;
  • subject identity was false;
  • issuer lacked authority;
  • signature was forged;
  • Certificate was fabricated;
  • material issuance corruption occurred.

27.30.27. Historical Validity Classification

Lifecycle review SHALL distinguish:

  • valid until suspension;
  • valid until withdrawal;
  • invalid from issuance;
  • valid for limited scope;
  • unable to determine;
  • historically relied upon despite defect.

27.30.28. Affected-Claim Analysis

Lifecycle change SHALL identify affected:

  • websites;
  • contracts;
  • procurement records;
  • reports;
  • Publications;
  • APIs;
  • tenant portals;
  • white-label portals;
  • marketplaces;
  • regulatory submissions;
  • training materials.

27.30.29. Runtime Dependency Treatment

Where Runtime Admission depends on certification, status change SHALL trigger:

  • admission review;
  • continued-operation review;
  • hold;
  • migration;
  • fallback;
  • deactivation

according to Runtime policy.


27.30.30. Publication Treatment

Affected Publications SHALL be evaluated for:

  • correction;
  • qualification;
  • restatement;
  • supersession;
  • withdrawal;
  • no change.

27.30.31. Mark Enforcement

After suspension, withdrawal or expiration, the Scheme SHALL define:

  • removal deadline;
  • inventory of uses;
  • digital revocation;
  • marketplace correction;
  • tenant and white-label correction;
  • enforcement;
  • provenance.

27.30.32. Lifecycle Registry

The Certification Lifecycle Registry SHALL preserve:

  • extensions;
  • reductions;
  • suspensions;
  • reinstatements;
  • withdrawals;
  • expirations;
  • invalidity;
  • status history;
  • authority;
  • provenance.

27.30.33. Lifecycle Receipt

A receipt SHOULD contain:

  • Certificate;
  • lifecycle action;
  • prior and new status;
  • scope;
  • reason;
  • authority;
  • effective time;
  • claim treatment;
  • verification state;
  • provenance.

27.30.34. Lifecycle Validation

HECATE SHALL validate:

  • action identity;
  • Certificate;
  • authority;
  • trigger;
  • scope;
  • effective time;
  • notice;
  • claim and mark treatment;
  • Runtime and Publication treatment;
  • Registry state;
  • provenance.

27.31. Recertification, Transfer and Scheme Transition

Certification SHALL be renewed only through a governed recertification process sufficient to establish current conformance.

Certificate transfer and Scheme transition SHALL preserve decision independence, status truth and historical lineage.


27.31.1. Recertification Plan

Every recertification SHALL possess:

  • Recertification Plan Identifier;
  • current Certificate;
  • current subject;
  • new Subject Snapshot;
  • current Baseline;
  • target Baseline where different;
  • current Scheme;
  • target Scheme version;
  • Profiles;
  • prior Findings;
  • prior conditions;
  • change history;
  • surveillance history;
  • assessment scope;
  • decision schedule;
  • provenance.

27.31.2. Recertification Triggers

Triggers MAY include:

  • planned Certificate expiration;
  • Scheme requirement;
  • Baseline transition;
  • major subject version;
  • major Runtime change;
  • material Extension change;
  • ownership change;
  • prolonged suspension;
  • regulator direction;
  • certification-body transfer.

27.31.3. Recertification Scope

Recertification scope SHALL consider:

  • complete certified scope;
  • changed scope;
  • high-risk unchanged scope;
  • prior Findings;
  • systemic Controls;
  • tenant population;
  • white-label population;
  • Modules;
  • Components;
  • Extensions;
  • incidents;
  • Publications;
  • claim history.

27.31.4. Prior Evidence Reuse

Prior evidence MAY be reused only where:

  • subject remains unchanged;
  • requirement remains unchanged;
  • evidence remains fresh;
  • Scheme permits reuse;
  • no incident or drift invalidates it;
  • assessor documents reliance;
  • provenance remains complete.

27.31.5. Prior Finding Treatment

Recertification SHALL evaluate:

  • closed Findings;
  • recurring Findings;
  • accepted exceptions;
  • conditions;
  • overdue remediation;
  • systemic issues;
  • surveillance Findings;
  • complaints.

27.31.6. Recertification Assessment

The assessment SHALL follow current Scheme requirements.

Historical passing status SHALL not substitute for current evidence.


27.31.7. Recertification Decision

Decision Classes MAY include:

  • Renew;
  • Renew with Conditions;
  • Renew Restricted Scope;
  • Defer;
  • Additional Assessment Required;
  • Suspend;
  • Withdraw;
  • Reject Renewal;
  • Unable to Decide.

27.31.8. Renewal Certificate

Renewal SHALL produce a new Certificate linked to:

  • prior Certificate;
  • recertification assessment;
  • new Decision;
  • current Scheme;
  • current Baseline;
  • current scope;
  • new validity;
  • provenance.

27.31.9. Continuity of Claims

The Scheme SHALL define whether claims may continue during:

  • renewal review;
  • administrative issuance;
  • appeal;
  • temporary evidence delay.

Continuity SHALL not extend beyond authorised limits.


27.31.10. Certification Transfer

Transfer occurs where certification responsibility moves between Certification Bodies or legal entities without treating the original Decision as newly made by the recipient.


27.31.11. Transfer Object

Every Transfer SHALL possess:

  • Transfer Identifier;
  • Certificate;
  • transferring body;
  • receiving body;
  • applicant consent;
  • Scheme;
  • subject;
  • scope;
  • status;
  • assessment history;
  • Findings;
  • conditions;
  • surveillance;
  • accreditation state;
  • transfer time;
  • provenance.

27.31.12. Transfer Eligibility

Transfer SHALL require:

  • Scheme permission;
  • valid active or eligible status;
  • receiving-body authority;
  • receiving-body competence;
  • compatible accreditation scope;
  • intact Assessment Package;
  • no concealed critical Finding;
  • applicant consent;
  • provenance.

27.31.13. Transfer Review

The receiving body SHALL review:

  • Certificate validity;
  • Decision validity;
  • Assessment Package;
  • surveillance history;
  • complaints;
  • appeals;
  • Findings;
  • conditions;
  • status;
  • public claims;
  • provenance.

27.31.14. Transfer Decision

Transfer outcomes MAY include:

  • Accept Transfer;
  • Accept with Conditions;
  • Additional Assessment Required;
  • Reduce Scope;
  • Suspend Pending Assessment;
  • Reject Transfer;
  • Unable to Decide.

27.31.15. Transfer Certificate Treatment

The Scheme SHALL define whether transfer results in:

  • status record update;
  • reissued Certificate representation;
  • new Certificate;
  • new Decision;
  • recertification.

Historical issuer lineage SHALL remain preserved.


27.31.16. Applicant Ownership Change

A legal ownership change SHALL evaluate:

  • certified subject continuity;
  • management responsibility;
  • Control operation;
  • legal entity;
  • mark licence;
  • contractual obligations;
  • surveillance;
  • recertification need;
  • provenance.

27.31.17. Scheme Transition Profile

Every Scheme transition SHALL possess:

  • Transition Profile Identifier;
  • source Scheme;
  • target Scheme;
  • source Profiles;
  • target Profiles;
  • compatibility;
  • changed requirements;
  • changed assessment;
  • changed claims;
  • changed surveillance;
  • active Certificate treatment;
  • deadlines;
  • grandfathering;
  • provenance.

27.31.18. Scheme Compatibility

Compatibility MAY be:

  • Fully Compatible;
  • Compatible after Administrative Update;
  • Compatible after Surveillance;
  • Compatible after Partial Reassessment;
  • Compatible after Full Recertification;
  • Conditionally Compatible;
  • Historically Compatible Only;
  • Incompatible;
  • Indeterminate.

27.31.19. Certificate Grandfathering

Grandfathering SHALL identify:

  • eligible Certificates;
  • preserved status;
  • prohibited new claims;
  • transition period;
  • surveillance;
  • target Scheme;
  • expiration;
  • provenance.

27.31.20. Baseline Transition

Where the Constitutional Baseline changes, certification transition SHALL evaluate:

  • requirement changes;
  • Profile changes;
  • subject compatibility;
  • Runtime Bundle;
  • Module and Component changes;
  • Extension compatibility;
  • tenant impact;
  • Publication impact;
  • reassessment.

27.31.21. Extension Transition

Extension certification transition SHALL evaluate:

  • Extension Point;
  • Namespace;
  • Package version;
  • Core Baseline;
  • tenant adoption;
  • Runtime compatibility;
  • recompile;
  • revalidation;
  • migration;
  • provenance.

27.31.22. Module and Component Transition

Transition SHALL preserve:

  • prior Module and Component lineage;
  • target Module and Component lineage;
  • capability mapping;
  • contract changes;
  • ownership;
  • test evidence;
  • certification scope;
  • provenance.

27.31.23. Transition Deadline

Missed transition deadlines MAY trigger:

  • warning;
  • claim restriction;
  • increased surveillance;
  • suspension;
  • expiration;
  • withdrawal.

27.31.24. Scheme Retirement

Scheme retirement SHALL identify:

  • final application date;
  • final issuance date;
  • active Certificate treatment;
  • target Scheme;
  • transition;
  • archive;
  • public verification;
  • provenance.

27.31.25. Recertification and Transfer Registry

The Registry SHALL preserve:

  • Plans;
  • assessments;
  • Decisions;
  • renewals;
  • Transfers;
  • transition Profiles;
  • grandfathering;
  • retirement;
  • provenance.

27.31.26. Recertification Receipt

A receipt SHOULD contain:

  • prior Certificate;
  • new Snapshot;
  • current Scheme and Baseline;
  • assessment;
  • prior Findings;
  • Decision;
  • new Certificate;
  • continuity treatment;
  • provenance.

27.31.27. Transfer Receipt

A receipt SHOULD contain:

  • Certificate;
  • transferring body;
  • receiving body;
  • eligibility;
  • review;
  • Decision;
  • status treatment;
  • effective time;
  • provenance.

27.31.28. Recertification and Transition Validation

HECATE SHALL validate:

  • Plan;
  • current and target Scheme;
  • current and target Baseline;
  • evidence reuse;
  • prior Finding treatment;
  • Decision;
  • Transfer authority;
  • accreditation scope;
  • transition Profile;
  • grandfathering;
  • provenance.

27.32. Conformity Assessment Bodies, Certification Bodies and Accreditation

A Conformity Assessment Body, abbreviated CAB, performs one or more assessment activities.

A Certification Body, abbreviated CB, makes Certification Decisions and manages Certificates under one or more approved Schemes.

An Accreditation Body, abbreviated AB, assesses and recognises the competence and authority of CABs or CBs under an Accreditation Scheme.

These roles SHALL remain distinct unless a Scheme explicitly permits combination and the required independence safeguards are demonstrated.


27.32.1. Conformity Assessment Body Identity

Every CAB SHALL possess:

  • CAB Identifier;
  • legal identity;
  • organisational identity;
  • authorised activities;
  • subject classes;
  • Schemes;
  • jurisdictions;
  • competence scope;
  • assessor inventory;
  • independence model;
  • quality-management system;
  • security profile;
  • tenant-isolation profile;
  • insurance or liability profile where required;
  • lifecycle;
  • provenance.

27.32.2. Certification Body Identity

Every CB SHALL possess:

  • CB Identifier;
  • legal identity;
  • organisational identity;
  • recognised Schemes;
  • Certification Decision scope;
  • jurisdictional scope;
  • subject-class scope;
  • reviewer inventory;
  • Decision Maker inventory;
  • impartiality structure;
  • quality-management system;
  • security profile;
  • Certificate issuance infrastructure;
  • Registry integration;
  • lifecycle;
  • provenance.

27.32.3. Accreditation Body Identity

Every AB SHALL possess:

  • AB Identifier;
  • legal or institutional authority;
  • Accreditation Schemes;
  • jurisdictions;
  • recognised scope;
  • assessor competence;
  • impartiality;
  • governance;
  • public Registry;
  • peer-recognition relationships;
  • lifecycle;
  • provenance.

27.32.4. Body Role Classes

Body Role Classes MAY include:

  • Testing Body;
  • Inspection Body;
  • Validation Body;
  • Verification Body;
  • Audit Body;
  • Assurance Provider;
  • Certification Body;
  • Accreditation Body;
  • Scheme Owner;
  • Peer-Recognition Body.

27.32.5. Body Authority

Every Body SHALL identify authority for:

  • activities performed;
  • Schemes served;
  • subject classes;
  • jurisdictions;
  • decisions;
  • claims;
  • marks;
  • surveillance;
  • complaints;
  • appeals;
  • records.

Technical capability SHALL not create authority.


27.32.6. Organisational Governance

A CAB or CB SHALL possess governance defining:

  • accountable leadership;
  • operational management;
  • technical authority;
  • impartiality oversight;
  • certification decision authority;
  • complaints authority;
  • appeals authority;
  • security ownership;
  • data-protection ownership;
  • archive ownership.

27.32.7. Impartiality Committee

A Scheme or CB MAY require an Impartiality Committee.

The Committee SHALL preserve:

  • membership;
  • stakeholder balance;
  • conflicts;
  • mandate;
  • meetings;
  • findings;
  • recommendations;
  • dissent;
  • provenance.

27.32.8. Impartiality Risk Register

Risks MAY include:

  • self-review;
  • financial dependence;
  • commercial pressure;
  • consulting relationship;
  • shared ownership;
  • management participation;
  • assessor familiarity;
  • advocacy;
  • contingent fees;
  • applicant concentration;
  • Scheme-owner pressure;
  • regulator capture;
  • political pressure.

27.32.9. Impartiality Safeguards

Safeguards MAY include:

  • separation of teams;
  • independent review;
  • decision committee;
  • assessor rotation;
  • fee controls;
  • conflict disclosure;
  • external oversight;
  • peer review;
  • appeal independence;
  • audit;
  • public transparency.

27.32.10. Competence Framework

Every CAB and CB SHALL maintain a Competence Framework covering:

  • Scheme knowledge;
  • Constitutional Baselines;
  • Conformance Profiles;
  • subject classes;
  • assessment methods;
  • evidence;
  • sampling;
  • legal and regulatory context;
  • security;
  • tenant isolation;
  • Runtime architecture;
  • Modules;
  • Components;
  • Extensions;
  • Publications;
  • assurance and certification rules.

27.32.11. Role Competence

Competence SHALL be defined separately for:

  • application reviewer;
  • assessment planner;
  • test executor;
  • technical assessor;
  • domain assessor;
  • Lead Assessor;
  • certification reviewer;
  • Certification Decision Maker;
  • surveillance assessor;
  • complaint reviewer;
  • appeal decision maker;
  • accreditation assessor.

27.32.12. Competence Evidence

Evidence MAY include:

  • education;
  • qualification;
  • licence;
  • professional certification;
  • Scheme training;
  • supervised experience;
  • witnessed assessment;
  • calibration;
  • continuing professional development;
  • performance review;
  • peer review.

27.32.13. Competence Authorisation

Every authorised person SHALL possess:

  • Person Identifier;
  • Role;
  • competence scope;
  • Scheme scope;
  • subject scope;
  • jurisdictional scope;
  • authorising body;
  • start time;
  • expiration or review;
  • restrictions;
  • provenance.

27.32.14. Competence Monitoring

Monitoring SHOULD evaluate:

  • work quality;
  • Finding consistency;
  • decision quality;
  • complaints;
  • appeals;
  • calibration;
  • knowledge currency;
  • conflict compliance;
  • evidence handling;
  • security.

27.32.15. Witnessed Assessment

A witnessed assessment SHALL preserve:

  • assessed person;
  • witness;
  • subject;
  • Scheme;
  • criteria;
  • observed activities;
  • competence findings;
  • restrictions;
  • decision;
  • provenance.

27.32.16. Continuing Professional Development

Required development SHOULD address changes in:

  • Constitutional Baselines;
  • Scheme versions;
  • laws and regulations;
  • ESG frameworks;
  • assessment methods;
  • security threats;
  • AI and model risks;
  • Runtime architecture;
  • Extensions;
  • Publications.

27.32.17. Resource Adequacy

A Body SHALL demonstrate adequate:

  • qualified personnel;
  • technical infrastructure;
  • test environments;
  • evidence storage;
  • security;
  • tenant isolation;
  • Certificate issuance;
  • surveillance capacity;
  • complaints capacity;
  • archive capacity;
  • business continuity.

27.32.18. Outsourcing

Outsourced activities SHALL identify:

  • provider;
  • activity;
  • Scheme;
  • competence;
  • authority;
  • independence;
  • confidentiality;
  • tenant isolation;
  • oversight;
  • evidence;
  • liability;
  • provenance.

The CAB or CB SHALL retain accountability for outsourced work within its scope.


27.32.19. Subcontractor Registry

The Registry SHALL preserve:

  • subcontractors;
  • authorised activities;
  • Schemes;
  • competence;
  • conflicts;
  • contracts;
  • monitoring;
  • status;
  • provenance.

27.32.20. Confidentiality and Data Protection

Bodies SHALL govern:

  • applicant data;
  • tenant data;
  • white-label data;
  • personal data;
  • trade secrets;
  • privileged material;
  • security evidence;
  • regulator access;
  • public disclosure;
  • retention;
  • destruction.

27.32.21. Tenant-Isolation Capability

A CAB or CB handling multi-tenant evidence SHALL demonstrate isolation across:

  • storage;
  • access;
  • workflows;
  • logs;
  • search;
  • vector stores;
  • AI contexts;
  • exports;
  • backups;
  • archives;
  • reporting.

27.32.22. Security Capability

Security controls SHALL cover:

  • identity;
  • access;
  • privileged access;
  • keys;
  • signatures;
  • evidence integrity;
  • Certificate issuance;
  • Registry integrity;
  • incident response;
  • vendor risk;
  • business continuity.

27.32.23. Quality-Management System

A Body's quality-management system SHOULD govern:

  • document control;
  • records;
  • competence;
  • assessment procedures;
  • review;
  • decisions;
  • non-conformities;
  • corrective action;
  • internal audit;
  • management review;
  • complaints;
  • appeals;
  • continuous improvement.

27.32.24. Body Internal Audit

Internal audit SHALL evaluate:

  • Scheme conformity;
  • competence;
  • independence;
  • assessment quality;
  • Decision quality;
  • Certificate integrity;
  • surveillance;
  • complaints;
  • security;
  • tenant isolation;
  • records;
  • public claims.

27.32.25. Management Review

Management review SHOULD consider:

  • audit results;
  • complaints;
  • appeals;
  • accreditation findings;
  • assessor performance;
  • decision consistency;
  • Certificate status;
  • Scheme changes;
  • incidents;
  • risks;
  • improvement.

27.32.26. Body Non-Conformity

A Body non-conformity MAY concern:

  • invalid authority;
  • competence;
  • independence;
  • procedure;
  • evidence handling;
  • Decision integrity;
  • Certificate issuance;
  • Registry accuracy;
  • surveillance;
  • complaint handling;
  • public claims;
  • security;
  • tenant isolation.

27.32.27. Body Corrective Action

Corrective action SHALL identify:

  • Body Finding;
  • root cause;
  • affected assessments;
  • affected Decisions;
  • affected Certificates;
  • action;
  • validation;
  • public treatment;
  • provenance.

27.32.28. Accreditation Scheme

Every Accreditation Scheme SHALL possess:

  • Accreditation Scheme Identifier;
  • Scheme Owner;
  • Accreditation Authority;
  • body types;
  • competence criteria;
  • impartiality criteria;
  • assessment methods;
  • witness requirements;
  • decision rules;
  • accreditation scope;
  • validity;
  • surveillance;
  • suspension;
  • withdrawal;
  • appeals;
  • public claims;
  • lifecycle;
  • provenance.

27.32.29. Accreditation Application

An application SHALL identify:

  • applicant Body;
  • requested scope;
  • Schemes;
  • subject classes;
  • jurisdictions;
  • personnel;
  • procedures;
  • quality system;
  • security;
  • tenant-isolation capability;
  • prior accreditation;
  • provenance.

27.32.30. Accreditation Assessment

Assessment MAY include:

  • document review;
  • office assessment;
  • system assessment;
  • witnessed assessment;
  • personnel interviews;
  • sample assessment review;
  • Decision review;
  • Certificate review;
  • security testing;
  • Registry verification;
  • complaint review.

27.32.31. Accreditation Decision

Decision Classes MAY include:

  • Grant;
  • Grant with Conditions;
  • Restricted Scope;
  • Defer;
  • Reject;
  • Maintain;
  • Extend Scope;
  • Reduce Scope;
  • Suspend;
  • Withdraw;
  • Renew.

27.32.32. Accreditation Scope

Scope SHALL identify:

  • body;
  • body role;
  • Certification Schemes;
  • subject classes;
  • jurisdictions;
  • assessment methods;
  • limitations;
  • validity;
  • surveillance.

27.32.33. Accreditation Certificate

An Accreditation Certificate SHALL identify:

  • Body;
  • Accreditation Scheme;
  • Decision;
  • scope;
  • status;
  • issue time;
  • expiration;
  • conditions;
  • Accreditation Body;
  • signature;
  • verification;
  • provenance.

27.32.34. Accreditation Status

Status MAY include:

  • Active;
  • Active with Conditions;
  • Restricted;
  • Surveillance Due;
  • Suspended;
  • Expired;
  • Withdrawn;
  • Superseded;
  • Historical.

27.32.35. Accreditation Surveillance

Surveillance SHALL assess continued:

  • competence;
  • impartiality;
  • decision integrity;
  • assessment quality;
  • quality system;
  • security;
  • tenant isolation;
  • complaint handling;
  • Certificate integrity.

27.32.36. Accreditation Suspension

Suspension MAY be triggered by:

  • competence failure;
  • impartiality failure;
  • invalid Decisions;
  • Certificate fraud;
  • security compromise;
  • tenant-data breach;
  • refusal of surveillance;
  • misleading accreditation claims;
  • unresolved critical findings.

27.32.37. Accreditation Withdrawal

Withdrawal SHALL identify affected:

  • Certification Schemes;
  • active Certificates;
  • pending applications;
  • surveillance;
  • public claims;
  • transfer needs;
  • regulatory notifications;
  • provenance.

27.32.38. Effect on Existing Certificates

Loss of CB accreditation SHALL not automatically define every existing Certificate as invalid.

The Scheme SHALL evaluate:

  • historical Decision validity;
  • current Body competence;
  • current surveillance;
  • transfer;
  • reassessment;
  • public disclosure;
  • risk.

27.32.39. Peer Recognition

Peer or multilateral recognition SHALL identify:

  • recognising bodies;
  • scope;
  • criteria;
  • jurisdictions;
  • limitations;
  • effective time;
  • withdrawal;
  • provenance.

Peer recognition SHALL not expand the underlying accreditation scope.


27.32.40. Accreditation Registry

The Registry SHALL preserve:

  • Accreditation Schemes;
  • applications;
  • assessments;
  • Decisions;
  • Certificates;
  • scopes;
  • status;
  • surveillance;
  • suspensions;
  • withdrawals;
  • provenance.

27.32.41. Body Recognition Registry

The Scheme SHOULD preserve a Registry of:

  • recognised CABs;
  • recognised CBs;
  • recognised ABs;
  • Scheme scopes;
  • jurisdictional scopes;
  • accreditation status;
  • restrictions;
  • provenance.

27.32.42. Body and Accreditation Receipt

A receipt SHOULD contain:

  • Body identity;
  • role;
  • Scheme scope;
  • competence;
  • independence;
  • accreditation;
  • status;
  • validity;
  • verification;
  • provenance.

27.32.43. Body and Accreditation Validation

HECATE SHALL validate:

  • Body identity;
  • authority;
  • governance;
  • competence records;
  • independence;
  • subcontractors;
  • security;
  • tenant isolation;
  • Accreditation Scheme;
  • assessment;
  • Decision;
  • scope;
  • status;
  • Registry state;
  • provenance.

HECATE SHALL not create accreditation authority or independently declare a Body competent beyond the approved assessment.


27.33. Assurance Integration and Multi-Level Trust Architecture

Assurance MAY provide an independent conclusion over subject matter relevant to certification.

Certification MAY rely on assurance evidence where the Scheme permits.

Assurance and certification SHALL remain distinct decisions.


27.33.1. Assurance Relationship Object

Every material assurance relationship SHALL possess:

  • Relationship Identifier;
  • Assurance Engagement;
  • assurance subject matter;
  • assurance criteria;
  • assurance conclusion;
  • Certification Scheme;
  • certification subject;
  • reliance scope;
  • reliance conditions;
  • validity;
  • limitations;
  • provenance.

27.33.2. Assurance Subject Matter

Assurance subject matter MAY include:

  • Conformance Outcome;
  • Assessment Package completeness;
  • evidence integrity;
  • Control design;
  • Control operating effectiveness;
  • tenant isolation;
  • security;
  • methodology;
  • computation;
  • Publication;
  • migration;
  • historical reconstruction;
  • certification process.

27.33.3. Assurance Criteria

Criteria SHALL identify:

  • constitutional requirements;
  • Conformance Profiles;
  • external standards;
  • legal or regulatory criteria;
  • Scheme rules;
  • evidence requirements;
  • period;
  • provenance.

27.33.4. Assurance Levels

Levels MAY include:

  • Internal Review;
  • Independent Review;
  • Agreed-Upon Procedures;
  • Limited Assurance;
  • Reasonable Assurance;
  • Continuous Assurance;
  • Other Governed Level.

The terminology SHALL align with the approved assurance profile.


27.33.5. Assurance Reliance

Certification reliance on assurance SHALL require:

  • provider identity;
  • provider competence;
  • provider independence;
  • exact subject matter;
  • exact scope;
  • exact criteria;
  • exact period;
  • valid conclusion;
  • evidence access or verification;
  • no material mismatch;
  • Scheme permission;
  • provenance.

27.33.6. Assurance Non-Substitution

An assurance conclusion SHALL not automatically:

  • grant certification;
  • establish Certification Authority;
  • waive certification-blocking Findings;
  • expand certified scope;
  • establish accreditation;
  • force Runtime Admission.

27.33.7. Certification Reliance on Assessment

Certification SHALL rely on a valid Conformance Outcome and Assessment Package according to the Scheme.

Assurance may increase confidence but SHALL not repair an invalid assessment basis silently.


27.33.8. Conformance, Assurance and Certification Stack

The trust stack SHALL preserve:

Authoritative Requirements


Conformance Assessment


Conformance Outcome

├── Assurance Engagement
│ └── Assurance Conclusion

└── Certification Review
└── Certification Decision
└── Certificate

27.33.9. Multi-Level Trust Profile

A Multi-Level Trust Profile MAY combine:

  • self-declaration;
  • automated validation;
  • independent assessment;
  • limited assurance;
  • reasonable assurance;
  • certification;
  • accreditation;
  • continuous surveillance.

Each layer SHALL remain separately identifiable.


27.33.10. Trust Level Object

Every Trust Level SHALL identify:

  • level;
  • subject;
  • criteria;
  • assessor;
  • independence;
  • evidence;
  • period;
  • Outcome;
  • limitations;
  • verification;
  • provenance.

27.33.11. Trust-Level Claim

A claim SHALL state the exact trust level.

Terms such as “verified,” “assured” and “certified” SHALL not be used interchangeably.


27.33.12. Assurance Provider Recognition

A Scheme MAY recognise assurance providers based on:

  • competence;
  • independence;
  • methodology;
  • accreditation or registration;
  • jurisdiction;
  • quality controls;
  • security;
  • tenant isolation;
  • public accountability.

27.33.13. Assurance Evidence Mapping

The CTM SHALL identify which certification requirements rely on:

  • direct assessment evidence;
  • assurance evidence;
  • external Certificate;
  • common Control;
  • applicant declaration;
  • continuous monitoring.

27.33.14. Assurance Qualification

A qualified, modified, adverse or disclaimer conclusion SHALL be evaluated for certification effect.

It SHALL not be represented as unqualified assurance.


27.33.15. Assurance Expiration

Expired or superseded assurance SHALL not remain current certification evidence silently.


27.33.16. Assurance Change Notification

Material changes to an assurance conclusion SHALL propagate to:

  • Certification Review;
  • Certificate surveillance;
  • Runtime dependencies;
  • Publication claims;
  • public verification;
  • provenance.

27.33.17. Assurance Withdrawal

Withdrawal SHALL identify:

  • engagement;
  • subject matter;
  • conclusion;
  • reason;
  • affected Certificate;
  • affected claim;
  • reassessment;
  • public treatment;
  • provenance.

27.33.18. Continuous Assurance Integration

Continuous assurance MAY consume:

  • control telemetry;
  • Runtime Manifests;
  • evidence freshness;
  • incident state;
  • change notifications;
  • tenant-isolation monitoring;
  • Certificate status.

Automation SHALL preserve authority boundaries.


27.33.19. Shared Assurance Evidence

Shared evidence SHALL preserve:

  • source;
  • scope;
  • tenants;
  • white-label deployments;
  • Modules;
  • Components;
  • validity;
  • restrictions;
  • provenance.

27.33.20. Assurance Conflict

Where assurance and conformance results conflict, the conflict SHALL preserve:

  • subjects;
  • scopes;
  • periods;
  • criteria;
  • evidence;
  • conclusions;
  • authority;
  • resolution;
  • certification effect;
  • provenance.

27.33.21. Trust Aggregation Prohibition

Multiple low-assurance artefacts SHALL not automatically equal high assurance or certification.

Aggregation rules SHALL be explicitly governed.


27.33.22. Assurance Registry Integration

The Certification Registry SHOULD link:

  • assurance provider;
  • engagement;
  • conclusion;
  • scope;
  • validity;
  • relied-upon Certificate;
  • status;
  • provenance.

27.33.23. Assurance Receipt

A receipt SHOULD contain:

  • assurance relationship;
  • subject matter;
  • criteria;
  • conclusion;
  • reliance;
  • conditions;
  • validity;
  • affected Certificate;
  • provenance.

27.33.24. Assurance Integration Validation

HECATE SHALL validate:

  • relationship identity;
  • subject and scope;
  • provider;
  • competence;
  • independence metadata;
  • criteria;
  • conclusion;
  • validity;
  • reliance conditions;
  • certification effect;
  • provenance.

HECATE SHALL not issue the assurance conclusion unless separately assigned within a valid assurance process.


27.34. Public Verification, Publication and Anti-Misrepresentation Controls

Certification status SHALL be independently verifiable at the time a claim is evaluated.

Public verification SHALL present current status without erasing historical status.

All public certification communications SHALL comply with the Constitutional Publication Framework.


27.34.1. Public Verification Service

Every public verification service SHALL possess:

  • Service Identifier;
  • owner;
  • Schemes served;
  • Certificate Registries served;
  • trust anchors;
  • status sources;
  • update frequency;
  • availability objective;
  • security profile;
  • privacy profile;
  • archive model;
  • lifecycle;
  • provenance.

27.34.2. Verification Query

A query MAY use:

  • Certificate Identifier;
  • subject identifier;
  • legal entity;
  • Scheme;
  • mark identifier;
  • verification token;
  • QR code;
  • signed credential;
  • public URL;
  • digest.

27.34.3. Verification Response

Every response SHOULD identify:

  • Certificate;
  • Scheme;
  • subject;
  • certified scope;
  • status;
  • issue time;
  • effective time;
  • expiration;
  • conditions at permitted disclosure level;
  • Certification Body;
  • accreditation status where applicable;
  • supersession;
  • verification time;
  • signature state;
  • provenance summary.

27.34.4. Verification Status Classes

Status Classes MAY include:

  • Valid and Active;
  • Valid with Conditions;
  • Valid for Restricted Scope;
  • Surveillance Due;
  • Suspended;
  • Expired;
  • Withdrawn;
  • Superseded;
  • Invalid;
  • Historical;
  • Unknown;
  • Unable to Verify.

Unknown and Unable to Verify SHALL not be represented as valid.


27.34.5. Historical Verification

Historical verification SHALL identify Certificate status at a specified time.

Current withdrawal SHALL not erase evidence that the Certificate was previously active where historically valid.


27.34.6. Signature Verification

Verification SHALL evaluate:

  • Certificate signature;
  • issuer;
  • trust anchor;
  • signing time;
  • key validity;
  • revocation;
  • Manifest digest;
  • Decision digest;
  • archive evidence.

27.34.7. Revocation Status

A verification service SHALL expose relevant revocation or invalidity state promptly.


27.34.8. Verification Availability

Availability requirements SHOULD reflect reliance risk.

Fallback MAY include:

  • signed offline verification artefact;
  • replicated Registry;
  • archived status list;
  • regulator endpoint;
  • Certification Body endpoint.

27.34.9. Verification Integrity

Controls SHALL protect against:

  • status tampering;
  • Registry substitution;
  • DNS or domain compromise;
  • QR-code substitution;
  • fake verification pages;
  • stale caches;
  • signature downgrade;
  • cross-tenant information leakage.

27.34.10. Verification Privacy

Public verification SHALL minimise:

  • personal data;
  • tenant-confidential data;
  • security-sensitive data;
  • unnecessary commercial information.

Sufficient scope information SHALL remain available to prevent misleading claims.


27.34.11. Publication Profile

Every public Certificate or certification claim SHALL use a Publication Profile defining:

  • audience;
  • disclosure;
  • language;
  • format;
  • verification;
  • correction;
  • status updates;
  • archive;
  • provenance.

27.34.12. Public Certificate Publication

A public Certificate Publication MAY contain:

  • human-readable Certificate;
  • machine-readable Certificate;
  • status;
  • scope;
  • conditions;
  • mark;
  • verification;
  • Scheme summary;
  • limitations.

27.34.13. Public Claim Approval

Public claims SHALL require:

  • valid Certificate;
  • active status;
  • claim fidelity;
  • permitted mark;
  • correct subject;
  • correct scope;
  • Publication Authority;
  • verification reference.

27.34.14. White-Label Public Claims

White-label claims SHALL distinguish:

  • operator certification;
  • platform certification;
  • tenant certification;
  • Module certification;
  • Component certification;
  • Extension certification;
  • organisation certification.

One SHALL not imply another.


27.34.15. Tenant Public Claims

A tenant SHALL not claim certification of:

  • all tenants;
  • the white-label operator;
  • the whole ZAYAZ platform;
  • excluded Modules;
  • excluded Components;
  • excluded Publications

unless included in scope.


27.34.16. Supply-Chain Claims

A certified dependency SHALL not make the dependent product certified automatically.

Claims SHALL distinguish:

  • certified dependency;
  • assessed integration;
  • certified composite system;
  • inherited Control;
  • excluded dependency.

27.34.17. Comparative Claims

A certification claim SHALL not imply superiority over non-certified subjects unless a separate governed comparison supports it.


27.34.18. Environmental or ESG Claims

Certification concerning conformance SHALL not be represented as proof of superior environmental or social performance unless the Scheme explicitly certifies that characteristic.


27.34.19. Regulator-Ready Claims

Terms such as “regulator-ready” SHALL identify:

  • Scheme;
  • jurisdiction;
  • scope;
  • requirements;
  • limitations;
  • validity;
  • verification.

27.34.20. Anti-Greenwashing Control

The claim system SHALL detect or prevent:

  • scope inflation;
  • expired certification use;
  • selective disclosure;
  • omission of material conditions;
  • certification-to-performance conflation;
  • unsupported environmental benefit;
  • misleading mark placement;
  • unverified claims.

27.34.21. Claim Monitoring Agent

An agent MAY assist in detecting public-claim misuse.

It SHALL preserve:

  • observed claim;
  • source;
  • Certificate;
  • comparison;
  • confidence;
  • evidence;
  • human review;
  • provenance.

It SHALL not issue enforcement decisions autonomously.


27.34.22. Misrepresentation Finding

A Finding SHALL identify:

  • claim;
  • claimant;
  • Certificate;
  • observed wording;
  • permitted wording;
  • scope mismatch;
  • status mismatch;
  • audience;
  • severity;
  • corrective action;
  • provenance.

27.34.23. Claim Correction Notice

A correction notice SHALL identify:

  • incorrect claim;
  • correction;
  • effective time;
  • affected channels;
  • verification;
  • authority;
  • provenance.

27.34.24. Claim Withdrawal

Withdrawal SHALL identify:

  • claim;
  • reason;
  • channels;
  • removal deadline;
  • verification update;
  • monitoring;
  • provenance.

27.34.25. Public Suspension Notice

A suspension notice SHOULD identify:

  • Certificate;
  • affected scope;
  • suspension status;
  • effective time;
  • permitted public explanation;
  • next review where publishable;
  • verification.

27.34.26. Public Withdrawal Notice

A withdrawal notice SHOULD identify:

  • Certificate;
  • scope;
  • withdrawal;
  • effective time;
  • replacement where applicable;
  • historical verification;
  • claim cessation.

27.34.27. Public Correction and Restatement

A public certification record SHALL be corrected or restated where:

  • subject was wrong;
  • scope was wrong;
  • status was wrong;
  • validity was wrong;
  • conditions were omitted;
  • Certification Body was wrong;
  • accreditation was misrepresented.

27.34.28. Verification Audit Log

The service SHOULD preserve:

  • query type;
  • Certificate;
  • response status;
  • time;
  • service version;
  • errors;
  • security events;
  • provenance.

Privacy-preserving aggregation MAY be used for public analytics.


27.34.29. Verification Metrics

Metrics MAY include:

  • verification volume;
  • failed verification;
  • unknown Certificate lookup;
  • stale status;
  • mark misuse;
  • correction time;
  • withdrawal propagation time;
  • service availability.

Metrics SHALL not create certification authority.


27.34.30. EcoWorld Publication Integration

EcoWorld MAY publish approved:

  • certification explanations;
  • Scheme summaries;
  • public Certificate records;
  • Academy material;
  • mark-use guidance;
  • verification interfaces;
  • suspension or withdrawal notices.

EcoWorld SHALL consume governed CPF Releases and current Certificate Registry status.


27.34.31. Public Lookup Integration

E-C-O Number or related public lookup services MAY expose certification status where:

  • identity mapping is governed;
  • scope is clear;
  • status is current;
  • Certificate verification is available;
  • privacy is preserved;
  • provenance is complete.

27.34.32. Public Verification Receipt

A receipt SHOULD contain:

  • query;
  • Certificate;
  • Registry state;
  • signature state;
  • status;
  • scope;
  • verification time;
  • service;
  • provenance.

27.34.33. Verification and Publication Validation

HECATE SHALL validate:

  • service identity;
  • Registry source;
  • Certificate binding;
  • status;
  • signature;
  • scope;
  • Publication Profile;
  • claim fidelity;
  • mark use;
  • correction;
  • withdrawal;
  • provenance.

27.35. Complaints, Appeals, Disputes and Certification Enforcement

Certification systems SHALL provide governed mechanisms for complaints, appeals, disputes, corrective action and enforcement.

Complaints and appeals SHALL be handled by competent and sufficiently independent authority.


27.35.1. Complaint Object

Every material Complaint SHALL possess:

  • Complaint Identifier;
  • complainant;
  • respondent;
  • Certificate, Body, Scheme or claim concerned;
  • complaint type;
  • allegations;
  • evidence;
  • affected scope;
  • confidentiality;
  • urgency;
  • lifecycle;
  • decision;
  • provenance.

27.35.2. Complaint Types

Types MAY include:

  • assessment conduct complaint;
  • assessor competence complaint;
  • assessor independence complaint;
  • Certification Decision complaint;
  • Certificate claim complaint;
  • mark misuse complaint;
  • surveillance complaint;
  • Certification Body complaint;
  • Accreditation Body complaint;
  • tenant-confidentiality complaint;
  • security complaint;
  • discrimination or accessibility complaint;
  • public-verification complaint.

27.35.3. Complaint Standing

A complaint MAY be submitted by:

  • applicant;
  • certified party;
  • tenant;
  • white-label operator;
  • organisation;
  • employee;
  • assessor;
  • Scheme Owner;
  • regulator;
  • assurance provider;
  • customer;
  • supplier;
  • public-interest actor;
  • member of the public where Scheme permits.

27.35.4. Complaint Intake

Intake SHALL identify:

  • subject;
  • standing where required;
  • urgency;
  • evidence;
  • confidentiality;
  • conflict;
  • responsible authority;
  • interim action;
  • provenance.

27.35.5. Complaint Admission

Admission outcomes MAY include:

  • Admitted;
  • Additional Information Required;
  • Referred;
  • Duplicated;
  • Rejected as Out of Scope;
  • Closed as Unsubstantiated;
  • Emergency Escalation;
  • Indeterminate.

27.35.6. Complaint Investigation

Investigation SHALL preserve:

  • issue;
  • criteria;
  • evidence;
  • interviews;
  • records;
  • conflicts;
  • findings;
  • affected Certificates;
  • affected claims;
  • confidentiality;
  • provenance.

27.35.7. Complaint Independence

The person or body deciding a complaint SHALL not be materially responsible for the complained-of activity where independence is required.


27.35.8. Complaint Outcome

Outcomes MAY include:

  • Upheld;
  • Partially Upheld;
  • Rejected;
  • Additional Assessment Required;
  • Corrective Action Required;
  • Scope Reduction Required;
  • Suspension Review Required;
  • Withdrawal Review Required;
  • Accreditation Review Required;
  • Unable to Conclude.

27.35.9. Complaint Remedy

Remedies MAY include:

  • explanation;
  • apology;
  • evidence correction;
  • Finding correction;
  • reassessment;
  • renewed review;
  • new Certification Decision;
  • claim correction;
  • mark removal;
  • surveillance increase;
  • suspension;
  • withdrawal;
  • assessor retraining;
  • Body corrective action;
  • Scheme correction.

27.35.10. Appeal Object

Every Appeal SHALL possess:

  • Appeal Identifier;
  • appealed Decision;
  • appellant;
  • grounds;
  • evidence;
  • requested remedy;
  • Appeal Authority;
  • stay request;
  • lifecycle;
  • Decision;
  • provenance.

27.35.11. Appealable Decisions

Appealable Decisions MAY include:

  • application rejection;
  • adverse Finding adjudication;
  • Certification rejection;
  • restricted scope;
  • condition;
  • suspension;
  • withdrawal;
  • transfer rejection;
  • accreditation Decision;
  • complaint Decision;
  • claim-enforcement Decision.

27.35.12. Appeal Grounds

Grounds MAY include:

  • procedural error;
  • authority error;
  • competence error;
  • independence failure;
  • factual error;
  • omitted evidence;
  • incorrect requirement interpretation;
  • disproportionate remedy;
  • inconsistent Scheme application;
  • new material evidence;
  • conflict of interest.

27.35.13. Appeal Authority

The Appeal Authority SHALL possess:

  • valid authority;
  • Scheme competence;
  • subject competence;
  • independence;
  • no disqualifying conflict;
  • access to records;
  • provenance.

27.35.14. Appeal Stay

A stay MAY affect:

  • Certification Decision;
  • Certificate issuance;
  • suspension;
  • withdrawal;
  • mark use;
  • public status;
  • transfer;
  • accreditation.

Risk-critical suspension MAY remain in force during appeal.


27.35.15. Appeal Review

Review SHALL preserve:

  • appealed record;
  • grounds;
  • evidence;
  • parties' submissions;
  • procedure;
  • findings;
  • decision;
  • dissent;
  • provenance.

27.35.16. Appeal Decision

The Appeal Authority MAY:

  • affirm;
  • modify;
  • reverse;
  • remand;
  • require reassessment;
  • require renewed Certification Review;
  • require new Decision;
  • dismiss;
  • declare inability to conclude.

27.35.17. Certification Dispute

A dispute MAY concern:

  • subject identity;
  • scope;
  • Scheme interpretation;
  • Requirement applicability;
  • evidence ownership;
  • Certificate ownership;
  • transfer;
  • mark licence;
  • public claim;
  • Body authority;
  • accreditation recognition;
  • historical status.

27.35.18. Dispute Resolution

Resolution MAY use:

  • formal review;
  • mediation;
  • expert determination;
  • arbitration where permitted;
  • regulatory referral;
  • court or tribunal;
  • Scheme Authority interpretation.

External decisions SHALL be integrated without rewriting historical records.


27.35.19. Whistleblower Report

A protected report MAY concern:

  • falsified evidence;
  • assessor coercion;
  • Finding suppression;
  • contingent certification;
  • mark fraud;
  • tenant leakage;
  • invalid Certificate issuance;
  • accreditation fraud.

Protection SHALL include confidentiality and anti-retaliation controls where applicable.


27.35.20. Emergency Complaint

An emergency complaint MAY trigger:

  • evidence preservation;
  • Certificate hold;
  • suspension;
  • claim hold;
  • mark hold;
  • public warning;
  • security response;
  • regulator notification.

27.35.21. Certification Enforcement Action

Enforcement actions MAY include:

  • warning;
  • correction order;
  • mark-removal order;
  • increased surveillance;
  • scope reduction;
  • suspension;
  • withdrawal;
  • Body recognition suspension;
  • accreditation referral;
  • public notice;
  • legal or regulatory referral.

27.35.22. Enforcement Authority

Every action SHALL identify:

  • authority;
  • subject;
  • Scheme rule;
  • evidence;
  • scope;
  • proportionality;
  • effective time;
  • appeal;
  • provenance.

27.35.23. Proportionality

Enforcement SHALL consider:

  • severity;
  • intent;
  • duration;
  • population;
  • tenant impact;
  • public impact;
  • recurrence;
  • remediation;
  • cooperation;
  • risk.

Zero-tolerance matters MAY require immediate action.


27.35.24. Fraud Investigation

Fraud investigation MAY address:

  • fabricated Certificate;
  • forged signature;
  • falsified evidence;
  • false applicant identity;
  • hidden non-conformity;
  • fake accreditation;
  • badge misuse;
  • Registry tampering;
  • assessor bribery;
  • duplicate Certificate identifiers.

27.35.25. Affected-Certificate Analysis

A Body-level complaint or fraud finding SHALL evaluate:

  • affected assessments;
  • affected Decisions;
  • affected Certificates;
  • affected Schemes;
  • affected tenants;
  • affected Publications;
  • reassessment;
  • suspension;
  • transfer;
  • public notice.

27.35.26. Complaint and Appeal Timelines

The Scheme SHOULD define:

  • acknowledgement;
  • admission;
  • investigation;
  • response;
  • Decision;
  • appeal window;
  • escalation;
  • delay notice.

Urgency SHALL be proportionate to risk.


27.35.27. Complaint Confidentiality

Confidentiality SHALL protect legitimate interests without concealing material public or tenant risk.


27.35.28. Public Complaint Outcome

A public outcome MAY identify:

  • issue;
  • authority;
  • result;
  • remedy;
  • Certificate effect;
  • effective time;
  • verification reference.

It SHALL comply with the CPF.


27.35.29. Complaint and Appeal Registry

The Registry SHALL preserve:

  • Complaints;
  • Appeals;
  • standing;
  • evidence;
  • interim measures;
  • Decisions;
  • remedies;
  • status;
  • finality;
  • provenance.

27.35.30. Complaint Receipt

A receipt SHOULD contain:

  • Complaint;
  • admission;
  • authority;
  • investigation;
  • Outcome;
  • remedy;
  • Certificate effect;
  • provenance.

27.35.31. Appeal Receipt

A receipt SHOULD contain:

  • Appeal;
  • appealed Decision;
  • stay;
  • Review;
  • Appeal Decision;
  • remedy;
  • finality;
  • provenance.

27.35.32. Complaint, Appeal and Enforcement Validation

HECATE SHALL validate:

  • identity;
  • subject;
  • authority;
  • independence;
  • lifecycle;
  • evidence;
  • interim measures;
  • Decision;
  • remedy;
  • Certificate effect;
  • Registry state;
  • provenance.

HECATE SHALL not adjudicate contested merits autonomously where human or institutional judgement is required.


27.36. Certification Security, Supply-Chain Integrity and Part III Conformance

The certification trust chain SHALL be protected against identity fraud, evidence tampering, decision tampering, Certificate forgery, Registry compromise, mark misuse, status delay, tenant leakage and historical erasure.


27.36.1. Certification Security Model

Every Certification Programme SHOULD possess a security model covering:

  • applicant identity;
  • subject identity;
  • assessor identity;
  • reviewer identity;
  • Decision Maker identity;
  • Body identity;
  • accreditation identity;
  • evidence integrity;
  • Assessment Package integrity;
  • Decision integrity;
  • Certificate issuance;
  • signing keys;
  • Certificate Registry;
  • public verification;
  • marks;
  • surveillance;
  • archive;
  • incident response.

27.36.2. Trust Boundaries

Trust boundaries SHALL identify:

  • applicant systems;
  • CAB systems;
  • CB systems;
  • AB systems;
  • Scheme systems;
  • evidence systems;
  • Certificate issuance systems;
  • public-verification systems;
  • tenant boundaries;
  • white-label boundaries;
  • external providers;
  • signing infrastructure.

27.36.3. Certification Supply Chain

The supply chain SHALL preserve:

Requirement and Scheme Source


Conformance Profiles and Test Artefacts


Assessment Execution


Evidence and Assessment Package


Certification Review


Certification Decision


Certificate Issuance


Certificate Registry


Public Claim and Verification


Surveillance and Lifecycle Status

27.36.4. Supply-Chain Object

Every material supply-chain stage SHOULD identify:

  • stage;
  • artefact;
  • owner;
  • implementing Module;
  • implementing Component;
  • version;
  • digest;
  • signature;
  • time;
  • tenant scope;
  • provenance.

27.36.5. Applicant Identity Assurance

Identity assurance SHALL evaluate:

  • legal identity;
  • domain ownership;
  • authorised representative;
  • tenant or white-label relationship;
  • beneficial ownership where required;
  • sanctions or restrictions where applicable;
  • credential security;
  • provenance.

27.36.6. Subject Identity Assurance

Subject identity SHALL be protected against:

  • substitution;
  • version ambiguity;
  • Snapshot mismatch;
  • scope ambiguity;
  • counterfeit Package;
  • wrong tenant;
  • wrong Module;
  • wrong Component;
  • wrong Extension;
  • wrong Runtime environment.

27.36.7. Assessment Package Integrity

Integrity SHALL use as appropriate:

  • Package Manifest;
  • artefact-root digest;
  • trusted timestamp;
  • signatures;
  • immutable storage;
  • access logging;
  • archive replication;
  • provenance.

27.36.8. Decision Integrity

Certification Decisions SHALL be protected against:

  • unauthorised modification;
  • reviewer substitution;
  • authority expiration;
  • signature forgery;
  • condition removal;
  • scope inflation;
  • validity extension;
  • hidden dissent;
  • Registry mismatch.

27.36.9. Issuance Security

Certificate issuance SHALL protect:

  • templates;
  • schemas;
  • Decision binding;
  • signing keys;
  • Certificate identifiers;
  • issuance credentials;
  • Registry write access;
  • duplicate issuance;
  • audit logs.

27.36.10. Identifier Uniqueness

Certificate, Decision, Application, Body and Accreditation identifiers SHALL be globally unique within their governed Namespace.

Reuse for incompatible identity SHALL be prohibited.


27.36.11. Signing-Key Governance

Key governance SHALL define:

  • key owner;
  • purpose;
  • algorithm;
  • issuance;
  • storage;
  • access;
  • rotation;
  • backup;
  • recovery;
  • revocation;
  • destruction;
  • historical verification;
  • provenance.

27.36.12. Key Compromise

Compromise SHALL trigger:

  • containment;
  • key revocation;
  • affected-Certificate analysis;
  • re-signing or reissuance;
  • Registry update;
  • public notice where required;
  • assurance review;
  • incident record;
  • provenance.

27.36.13. Registry Security

Registry controls SHALL protect:

  • Certificate records;
  • status records;
  • Decision links;
  • subject links;
  • signatures;
  • public APIs;
  • administrator access;
  • replication;
  • backup;
  • tamper detection;
  • availability.

27.36.14. Status Propagation

Suspension, withdrawal, expiration, invalidity and supersession SHALL propagate to:

  • Certificate Registry;
  • public verification;
  • marks;
  • applicant portals;
  • tenant portals;
  • white-label portals;
  • Runtime dependencies;
  • Publication systems;
  • assurance references;
  • accreditation records where relevant.

27.36.15. Propagation Objective

The Scheme SHOULD define maximum propagation times according to risk.


27.36.16. Stale Status

A stale-status incident exists where a verification surface presents outdated Certificate state beyond the permitted interval.


27.36.17. Counterfeit Certificate Detection

Detection MAY use:

  • Registry lookup;
  • signature verification;
  • identifier validation;
  • template analysis;
  • issuer validation;
  • domain validation;
  • mark validation;
  • anomaly detection;
  • public reporting.

27.36.18. Duplicate Identifier Detection

Duplicate or conflicting Certificate identifiers SHALL trigger immediate investigation.


27.36.19. Mark Security

Marks SHOULD protect against:

  • unauthorised copying;
  • subject substitution;
  • link substitution;
  • stale status;
  • visual alteration;
  • phishing;
  • counterfeit verification pages.

27.36.20. Verification-Domain Security

Public verification domains SHALL use governed:

  • domain ownership;
  • certificates;
  • DNS controls;
  • monitoring;
  • incident response;
  • redirects;
  • archive;
  • provenance.

27.36.21. AI Fraud Detection

AI MAY assist with:

  • counterfeit detection;
  • claim scanning;
  • anomaly detection;
  • duplicate identifier detection;
  • status inconsistency;
  • evidence anomaly detection.

AI output SHALL be reviewed before enforcement.


27.36.22. Certification Incident

Every material Certification Incident SHALL possess:

  • Incident Identifier;
  • affected Scheme;
  • affected Body;
  • affected Certificates;
  • affected tenants;
  • affected claims;
  • incident type;
  • severity;
  • detection time;
  • containment;
  • investigation;
  • recovery;
  • provenance.

27.36.23. Incident Types

Types MAY include:

  • Applicant Identity Fraud;
  • Subject Substitution;
  • Evidence Tampering;
  • Assessment Package Tampering;
  • Invalid Certification Decision;
  • Certificate Forgery;
  • Signing-Key Compromise;
  • Registry Compromise;
  • Verification-Service Compromise;
  • Mark Misuse;
  • Status Propagation Failure;
  • Tenant-Data Exposure;
  • Accreditation Fraud;
  • Assessor Bribery or Coercion.

27.36.24. Certification Incident Response

Response SHALL include as applicable:

  • containment;
  • evidence preservation;
  • Certificate hold;
  • suspension;
  • withdrawal;
  • key revocation;
  • Registry correction;
  • public notice;
  • tenant notification;
  • regulator notification;
  • affected-outcome analysis;
  • recovery;
  • retrospective.

27.36.25. Business Continuity

The certification system SHOULD support continuity for:

  • application records;
  • Assessment Packages;
  • Decisions;
  • Certificate issuance;
  • Registry status;
  • public verification;
  • surveillance;
  • complaints;
  • archives.

Continuity SHALL not bypass authority or integrity controls.


27.36.26. Disaster Recovery

Recovery testing SHOULD verify:

  • Registry restoration;
  • status history;
  • signature verification;
  • Decision links;
  • Certificate Manifests;
  • Body and accreditation records;
  • public verification;
  • tenant isolation;
  • provenance.

27.36.27. Certification Archive

The archive SHALL preserve:

  • Schemes;
  • Rulebooks;
  • Profiles;
  • applications;
  • agreements;
  • Assessment Packages;
  • Reviews;
  • Decisions;
  • Certificates;
  • status records;
  • surveillance;
  • claims;
  • marks;
  • complaints;
  • appeals;
  • Bodies;
  • accreditation;
  • incidents;
  • provenance.

27.36.28. Historical Certification Verification

Historical verification SHALL identify:

  • Scheme version;
  • certified subject;
  • Snapshot;
  • Baseline;
  • scope;
  • Certificate status at target time;
  • Certification Body authority at target time;
  • accreditation status at target time;
  • later suspension, withdrawal or invalidity;
  • provenance.

27.36.29. Certification Replay

Replay MAY reconstruct:

  • application admission;
  • assessment basis;
  • Certification Review;
  • Decision preconditions;
  • Decision;
  • Certificate issuance;
  • status changes;
  • public verification.

Replay SHALL not issue a new Certification Decision.


27.36.30. Part III Provenance

Part III provenance SHALL connect:

  • Certification Programme;
  • Scheme;
  • Rulebook;
  • Scheme Profile;
  • Scheme interpretation;
  • applicant;
  • Application;
  • Certification Agreement;
  • admission;
  • Assessment Package;
  • Certification Review;
  • recommendation;
  • Certification Decision;
  • signatures;
  • Certificate;
  • Certificate Manifest;
  • Registry;
  • claim;
  • mark;
  • surveillance;
  • change notification;
  • incident notification;
  • scope extension;
  • scope reduction;
  • suspension;
  • reinstatement;
  • withdrawal;
  • expiration;
  • recertification;
  • transfer;
  • Scheme transition;
  • CAB;
  • CB;
  • AB;
  • accreditation;
  • assurance relationship;
  • public verification;
  • complaint;
  • appeal;
  • enforcement;
  • security incident;
  • archive;
  • Module lineage;
  • Component lineage;
  • tenant lineage;
  • white-label lineage;
  • Extension lineage;
  • Runtime lineage;
  • Publication lineage;
  • temporal lineage.

27.36.31. Part III Provenance Graph

Certification Programme and Scheme


Certification Application and Admission


Assessment Package


Certification Review


Certification Decision


Certificate, Registry, Claim and Mark


Surveillance and Change Notification

├── Maintain
├── Extend Scope
├── Reduce Scope
├── Suspend
├── Reinstate
├── Withdraw
├── Expire
└── Recertify


Certification Body and Accreditation Governance


Assurance Integration


Public Verification, Complaint, Appeal and Enforcement


Security, Archive and Historical Verification

27.36.32. Bitemporal Certification Lineage

Every material certification object SHALL preserve as applicable:

  • subject valid time;
  • Scheme effective time;
  • Application time;
  • assessment time;
  • Decision time;
  • Certificate issue time;
  • Certificate effective time;
  • surveillance time;
  • status valid time;
  • status transaction time;
  • withdrawal time;
  • archive time.

27.36.33. Certification Integrity Receipt

A high-assurance receipt SHOULD contain:

  • Scheme and version;
  • subject;
  • Snapshot digest;
  • Baseline;
  • Assessment Package digest;
  • Certification Review;
  • Decision digest;
  • Certificate Manifest digest;
  • Certificate status;
  • CB authority;
  • accreditation status;
  • verification state;
  • Module and Component lineage;
  • provenance completeness;
  • verification time.

27.36.34. Certification Metrics

Metrics MAY include:

  • application admission rate;
  • certification grant rate;
  • conditional grant rate;
  • restricted-scope rate;
  • Decision turnaround;
  • Certificate issuance time;
  • surveillance completion;
  • suspension rate;
  • withdrawal rate;
  • recurrence rate;
  • claim-misuse rate;
  • status-propagation time;
  • complaint rate;
  • appeal-overturn rate;
  • Body Finding rate;
  • accreditation suspension rate;
  • counterfeit detection rate;
  • verification availability.

Metrics SHALL not determine certification authority or correctness independently.


27.36.35. Pergamum Pulse Integration

Pergamum Pulse MAY derive intelligence including:

  • Scheme fragmentation;
  • certification concentration;
  • Certification Body concentration;
  • assessor bottlenecks;
  • decision-consistency risk;
  • conditional-certification backlog;
  • surveillance overdue risk;
  • Certificate drift;
  • claim-misuse concentration;
  • suspension recurrence;
  • withdrawal propagation risk;
  • recertification congestion;
  • accreditation-scope gaps;
  • Body impartiality risk;
  • tenant certification divergence;
  • white-label certification divergence;
  • Extension certification clusters;
  • Module-level certification risk;
  • Component-level certification risk;
  • verification-integrity risk;
  • counterfeit risk.

Pergamum Pulse SHALL preserve:

  • Scheme lineage;
  • Application lineage;
  • Assessment Package lineage;
  • Decision lineage;
  • Certificate lineage;
  • Registry lineage;
  • surveillance lineage;
  • Body lineage;
  • accreditation lineage;
  • assurance lineage;
  • complaint and appeal lineage;
  • Module lineage;
  • Component lineage;
  • tenant lineage;
  • white-label lineage;
  • Extension lineage;
  • Runtime lineage;
  • Publication lineage;
  • temporal validity;
  • provenance.

Derived intelligence SHALL remain Intelligence Layer assertions until governed activation.


27.36.36. Part III Conformance Suite

The Constitutional Compiler Framework SHOULD generate fixtures including:

  • valid Certification Programme;
  • valid Scheme Rulebook;
  • Scheme claim exceeding subject scope;
  • non-exceptionable requirement waived commercially;
  • valid Scheme transition;
  • active Certificate under withdrawn Scheme;
  • valid Certification Application;
  • applicant lacking authority to apply;
  • concealed known non-conformity;
  • contingent certification fee;
  • valid Certification Review;
  • reviewer self-review conflict;
  • invalid Decision Authority;
  • certification recommendation treated incorrectly as Decision;
  • valid conditional Certification Decision;
  • restricted-scope Decision;
  • Unable-to-Decide outcome;
  • valid Certificate Manifest;
  • Certificate scope broader than Decision;
  • altered issued Certificate;
  • valid certification mark;
  • static mark without verification;
  • mark used during suspension;
  • valid Surveillance Plan;
  • unreported material Runtime change;
  • tenant-isolation incident notification;
  • overdue surveillance;
  • valid scope extension;
  • voluntary scope reduction concealing non-conformity;
  • immediate partial suspension;
  • valid reinstatement;
  • forced withdrawal;
  • expired Certificate with active public claim;
  • invalid fabricated Certificate;
  • valid Recertification Plan;
  • invalid prior-evidence reuse;
  • Certification Body transfer;
  • Scheme transition requiring full recertification;
  • valid CAB competence record;
  • orphan assessor authorisation;
  • impartiality conflict;
  • subcontracted assessment without oversight;
  • valid Accreditation Scheme;
  • accreditation scope inflation;
  • suspended CB with active issuance;
  • valid assurance reliance;
  • qualified assurance treated incorrectly as unqualified;
  • low-assurance aggregation treated as certification;
  • valid public verification response;
  • stale Certificate status;
  • white-label claim scope inflation;
  • anti-greenwashing Finding;
  • valid complaint;
  • appeal with stay;
  • whistleblower evidence of Finding suppression;
  • counterfeit Certificate incident;
  • signing-key compromise;
  • Registry recovery;
  • complete Part III provenance.

Part III Conformance

An implementation conforms to Part III of the Core Conformance and Certification Framework where it:

  1. governs certification through explicit Certification Programmes and versioned Schemes;
  2. preserves Scheme Rulebooks, Profiles, claim models, severity policies, exception policies, surveillance rules and appeal rules;
  3. prevents Scheme guidance from silently creating new mandatory requirements;
  4. impact-analyses Scheme changes across applications, assessments, Certificates, Bodies, tenants, Extensions, Runtime Admissions and Publications;
  5. keeps released Scheme versions immutable;
  6. binds every Application to an exact applicant, subject, scope, Baseline, Profile, Scheme version and requested claim;
  7. verifies applicant authority to submit the subject and use certification claims;
  8. requires disclosure of known material non-conformity and prior certification history;
  9. prevents payment or commercial agreement from guaranteeing certification or altering criteria;
  10. preserves application admission as distinct from conformance and certification;
  11. performs independent Certification Review where the Scheme requires;
  12. binds Certification Review to an exact final Assessment Package digest;
  13. separates certification recommendation from Certification Decision;
  14. assigns Certification Decision authority by Scheme, subject class, jurisdiction, competence and independence;
  15. prohibits an AI model from acting as the sole Certification Decision Maker;
  16. permits automated certification only for narrowly defined objective scope under explicit authority and deterministic rules;
  17. binds every Certification Decision to exact subject, Snapshot, Baseline, scope, conditions, validity and Assessment Package;
  18. preserves rejected, deferred and Unable-to-Decide outcomes without misrepresenting them as certification;
  19. issues Certificates that reproduce the Certification Decision exactly;
  20. keeps issued Certificates immutable and represents later status changes through linked status records;
  21. protects Certificate identifiers, Manifests, signatures and Registry state;
  22. prevents Certificate claims from exceeding certified scope, characteristics, status or validity;
  23. distinguishes product, service, Module, Component, Extension, tenant, white-label, organisation and Publication certification;
  24. prevents certification from implying universal legal compliance, universal ESG excellence, regulator endorsement or certification of excluded dependencies;
  25. requires certification marks to be Scheme-bound, Certificate-bound, status-aware and verifiable;
  26. governs mark licensing, monitoring, correction and withdrawal;
  27. maintains surveillance proportionate to subject risk and Scheme requirements;
  28. requires material change and incident notification;
  29. detects Certificate Drift and Claim Drift;
  30. preserves surveillance assessment and Decision as distinct from the original Certification Decision;
  31. governs scope extension and scope reduction through explicit assessment and Decision;
  32. distinguishes suspension, withdrawal, expiration, invalidity and supersession;
  33. propagates status changes to Registries, public verification, marks, Runtime dependencies and Publications;
  34. requires validated remediation and current evidence before reinstatement;
  35. preserves historical Certificate validity without erasing later suspension or withdrawal;
  36. governs recertification using current Scheme, Baseline, Snapshot, evidence and Finding history;
  37. prevents historical certification from substituting for current evidence;
  38. governs certification transfer through receiving-body competence, authority, accreditation scope and Package integrity;
  39. governs Scheme transitions, compatibility, grandfathering and Certificate treatment;
  40. distinguishes CAB, CB, AB, assurance provider, Scheme Owner and peer-recognition roles;
  41. requires Bodies to demonstrate authority, competence, impartiality, quality governance, security and tenant isolation;
  42. governs assessor and Decision Maker competence through explicit authorisation and monitoring;
  43. governs outsourcing without transferring accountability;
  44. represents accreditation as a separate, Scheme-bound and scope-bound recognition;
  45. prevents accreditation from expanding Certification Scheme scope;
  46. evaluates existing Certificates when CB accreditation is suspended or withdrawn rather than applying an unexplained blanket assumption;
  47. integrates assurance without allowing assurance to substitute for certification or repair an invalid assessment silently;
  48. identifies exact trust levels and prevents “validated,” “verified,” “assured,” “certified” and “accredited” from being used interchangeably;
  49. provides public verification of current and historical Certificate status;
  50. prevents Unknown or Unable-to-Verify states from being represented as valid;
  51. governs white-label, tenant, supply-chain, comparative, environmental and regulator-ready claims precisely;
  52. detects and corrects misleading certification and anti-greenwashing claims;
  53. provides governed complaints, appeals, disputes, whistleblower channels and enforcement;
  54. preserves sufficient independence in complaint and appeal decisions;
  55. protects the full certification supply chain from identity fraud, evidence tampering, Decision tampering, Certificate forgery, Registry compromise and mark misuse;
  56. governs signing keys, key compromise, status propagation, business continuity and disaster recovery;
  57. preserves historical Certification Body and accreditation status at the relevant time;
  58. preserves both Module and Component lineage;
  59. integrates Pergamum Pulse without granting it Scheme, certification, accreditation, enforcement or appeal authority;
  60. preserves complete bitemporal Part III provenance and provides conformance fixtures across the certification lifecycle.

Part III Foundational Principle

Certification is a governed trust decision, not a decorative output of testing or assessment.

Every certification claim SHALL originate from an approved Scheme, an eligible applicant, an exact subject and Snapshot, a valid Assessment Package, an independent Certification Review where required, and a Certification Decision made by competent and authorised authority. The resulting Certificate SHALL reproduce that Decision exactly and remain immutable throughout its historical life.

Continued certification SHALL depend on surveillance, change notification, incident treatment, evidence freshness and accurate public claims. Scope extension, scope reduction, suspension, withdrawal, expiration, reinstatement, recertification and transfer SHALL remain distinct and independently verifiable.

Certification Bodies and Conformity Assessment Bodies SHALL demonstrate competence, impartiality, secure evidence handling and tenant isolation. Accreditation Bodies may recognise their competence under exact Accreditation Schemes. Assurance may support trust. None of these roles may impersonate another or expand the scope of the underlying evidence.

By making certification Scheme-bound, Decision-separated, Certificate-immutable, surveillance-driven, status-transparent, Body-accountable, accreditation-scoped, claim-honest, fraud-resistant and historically verifiable, ZAYAZ can provide regulator-grade certification without allowing badges, automation, commercial pressure or institutional reputation to outrun the evidence.




GitHub RepoRequest for Change (RFC)