Official-source catalog

Sources

Direct answer

K03 source records identify publisher, official location, exact edition or version, publication status, supported propositions, revalidation time, currentness limits, correction state, and supersession links.

Revalidated sources

CURRENT TECHNICAL STANDARD

PROV-O: The PROV Ontology

Vocabulary for representing provenance information.

W3C Recommendation 30 April 2013 · W3C Recommendation

CURRENT TECHNICAL STANDARD

Decentralized Identifiers (DIDs) v1.0

Technical standard relevant to identifier control and verification methods; it does not by itself establish legal identity.

DID Core v1.0 · W3C Recommendation

CURRENT TECHNICAL STANDARD

Verifiable Credentials Data Model v2.0

Data model for tamper-evident credentials and presentations; credential integrity is distinct from truth and authority.

Verifiable Credentials Data Model v2.0 · W3C Recommendation

CURRENT TECHNICAL STANDARD

JSON-LD 1.1

Linked-data serialization used for public knowledge records.

JSON-LD 1.1 · W3C Recommendation

CURRENT TECHNICAL STANDARD

Web Content Accessibility Guidelines (WCAG) 2.2

Accessibility requirements used as the public-interface target.

WCAG 2.2, W3C Recommendation 12 December 2024 · W3C Recommendation

CURRENT TECHNICAL STANDARD

Artificial Intelligence Risk Management Framework (AI RMF 1.0)

Risk-management reference for systems described by industry and government as AI. Version 1.0 remains the published framework but is under revision as of the 2026-08-14 research cutoff.

AI RMF 1.0 · Published voluntary framework; revision underway

CURRENT TECHNICAL STANDARD

NIST SP 800-218 Secure Software Development Framework Version 1.1

Final secure software development practices used for implementation and release controls. Version 1.2 remained an initial public draft at the research cutoff.

SP 800-218 SSDF Version 1.1; Version 1.2 initial public draft tracked separately · Version 1.1 final; Version 1.2 initial public draft

CURRENT TECHNICAL STANDARD

NIST SP 800-53 Rev. 5, Release 5.2.0 Security and Privacy Controls

Current 2025 minor release of the Rev. 5 control catalog used for assurance, access control, audit and resilience references.

SP 800-53 Rev. 5, Release 5.2.0 · Final control catalog with 2025 minor release

CURRENT TECHNICAL STANDARD

RFC 5280: Internet X.509 Public Key Infrastructure Certificate and CRL Profile

Certificate profile useful for understanding key-bound credentials and revocation.

RFC 5280 with update chain · Proposed Standard

SUPERSEDED

RFC 6962: Certificate Transparency

Experimental Certificate Transparency v1 protocol, now obsolete and superseded by RFC 9162; retained for historical comparison.

RFC 6962 · Experimental; obsolete

CURRENT TECHNICAL STANDARD

RFC 3161: Time-Stamp Protocol

Protocol relevant to evidence that a representation existed by a specified time.

RFC 3161 with RFC 5816 update · Proposed Standard

CURRENT TECHNICAL STANDARD

Supply-chain Levels for Software Artifacts (SLSA) Specification v1.2

Current approved software supply-chain integrity specification at the 2026-08-14 research cutoff, relevant to attributable releases and provenance.

SLSA v1.2 · Approved

CURRENT TECHNICAL STANDARD

in-toto Attestation Framework

Attestation framework for software supply-chain steps and evidence.

Current project framework · Open standard; CNCF graduated project

CURRENT TECHNICAL STANDARD

C2PA Technical Specification v2.4

Current content-provenance specification at the 2026-08-14 research cutoff; provenance assertions remain distinct from factual truth.

C2PA Technical Specification 2.4 · Published technical specification

OBSERVED DEPLOYMENT OR PRACTICE

Schema.org DefinedTerm

Public structured-data vocabulary for defined terms; the canonical page identifies the term as part of the development version and the new area.

Schema.org V30.0 · Public structured-data vocabulary release

CURRENT POLICY OR GUIDANCE

AI features and your website

Search guidance emphasizing ordinary foundational SEO; no markup guarantees citation or ranking.

Current Search Central guidance · Official platform guidance

CURRENT LAW OR POLICY

European Union Artificial Intelligence Act information portal

European regulatory framework for systems legally categorized as AI. It became broadly applicable on 2026-08-02 with specified later dates and exceptions; it is not a legal-personhood regime for Machine Intelligence.

EU Artificial Intelligence Act implementation page, updated through 2026-08-14 research cutoff · Current law and official implementation guidance

CURRENT LAW OR POLICY

OECD AI Principles

Intergovernmental policy principles using the external term AI.

OECD AI Principles, May 2024 update · Intergovernmental policy principles

CURRENT TECHNICAL STANDARD

RFC 9162: Certificate Transparency Version 2.0

Experimental Certificate Transparency v2 protocol that obsoletes RFC 6962; useful as a design reference for append-only, publicly auditable logs.

RFC 9162 · Experimental; current successor to RFC 6962

RESEARCH FINDING

WCAG Evaluation Methodology (WCAG-EM) 2.0

Informative evaluation methodology for defining scope, exploring a product, selecting representative samples, evaluating them, and reporting findings; it does not add or replace WCAG requirements.

WCAG-EM 2.0 · W3C Group Note

CURRENT TECHNICAL STANDARD

Accessibility Conformance Testing (ACT) Rules Format 1.1

W3C Recommendation defining a common format for documenting automated and manual accessibility test rules; a test-rule format does not itself establish whole-site conformance.

ACT Rules Format 1.1 · W3C Recommendation

CURRENT LAW OR POLICY

Executive Order 14409 — Promoting Advanced Artificial Intelligence Innovation and Security

Official executive order directing public-private work to advance AI innovation and harden government and private-sector systems against external threats.

Executive Order 14409 · Presidential Executive Order

OBSERVED DEPLOYMENT OR PRACTICE

White House Launches GOLD EAGLE Initiative for Cybersecurity Vulnerability Coordination

Official announcement of a public-private vulnerability coordination model using frontier AI to identify, prioritize, and support remediation.

White House release, July 14, 2026 · Official release

CURRENT LAW OR POLICY

Expanding Capabilities to Combat Transnational Cyber-Enabled Crime

Official presidential memorandum directing an NCC program for vetted participating companies to conduct defined cyber surveillance and cyber effects operations against foreign CE-TCOs only under Federal Government control, supervision, legal authorities, written package approval, deconfliction, and critical-outcome limits. It is not a general private hack-back license.

Presidential Memorandum, August 12, 2026 · Presidential Memorandum

OBSERVED DEPLOYMENT OR PRACTICE

The Establishment of Project Manager Cyber Warfare

Official Army announcement confirming the merger of offensive and defensive cyber portfolios into Project Manager Cyber Warfare.

Army release, August 3, 2026 · Official first-party announcement

OBSERVED DEPLOYMENT OR PRACTICE

Cyber Warfare: The Best Offense Is a Powerful Defense

Official Army acquisition article describing full-spectrum cyber capability, critical-infrastructure defense, offensive-defensive integration, commercial collaboration, and agile fielding.

USAASC article, August 10, 2026 · Official first-party article

CURRENT LAW OR POLICY

10 CFR 73.54 — Protection of Digital Computer and Communication Systems and Networks

Nuclear cybersecurity requirements for protected digital systems and networks associated with safety, security, emergency preparedness, and supporting functions.

10 CFR 73.54, current eCFR · Federal regulation

CURRENT LAW OR POLICY

10 CFR 73.55 — Requirements for Physical Protection of Licensed Activities in Nuclear Power Reactors Against Radiological Sabotage

Physical protection requirements for operating nuclear power reactors, including detection, assessment, delay, response, training, and program performance.

10 CFR 73.55, current eCFR · Federal regulation

CURRENT LAW OR POLICY

Risk-Informed, Technology-Inclusive Regulatory Framework for Advanced Reactors — Final Rule

Final NRC rule creating an optional Part 53 framework and a technology-inclusive, performance-based security framework in 10 CFR Part 73. K05 replaces the earlier proposed-rule status; applicability still depends on the licensing path and facility election.

Final rule, 91 FR 15697, March 30, 2026 · FINAL RULE; facility-specific applicability required

OBSERVED DEPLOYMENT OR PRACTICE

Consequence-driven Cyber-informed Engineering

Official INL description of CCE as a critical-infrastructure methodology that assumes skilled adversaries can penetrate networks and uses a four-phase process to protect critical operations.

INL CCE program page · Official laboratory methodology description

CURRENT TECHNICAL STANDARD

NIST SP 800-82 Revision 3 — Guide to Operational Technology Security

Official guidance for securing operational technology while addressing performance, reliability, and safety requirements.

NIST SP 800-82 Rev. 3 · NIST Final Publication

CURRENT TECHNICAL STANDARD

NIST SP 800-207 — Zero Trust Architecture

Official zero-trust architecture guidance that removes implicit trust based on network location and focuses protection on resources, identities, and policy decisions.

NIST SP 800-207 · NIST Final Publication

CURRENT LAW OR POLICY

DoD Directive 3000.09 — Autonomy in Weapon Systems

Official policy for autonomous and semi-autonomous weapon systems. The directive expressly excludes autonomous or semi-autonomous cyberspace capabilities, unarmed platforms, and autonomous systems that are not weapon systems; its weapon-system V&V, testing, human-judgment, abort, and audit provisions must not be silently generalized into a cyber-defense compliance claim.

DoDD 3000.09, January 25, 2023 · Department of Defense Directive

OBSERVED DEPLOYMENT OR PRACTICE

Google and Kairos Power Advanced Nuclear Agreement

First-party announcement of an agreement intended to enable up to 500 MW of advanced nuclear power, with an initial reactor planned by 2030 and additional deployment through 2035.

Google announcement, October 14, 2024 · First-party corporate announcement

OBSERVED DEPLOYMENT OR PRACTICE

Constellation and Microsoft Crane Clean Energy Center Agreement

First-party announcement of a 20-year power purchase agreement intended to support restart of a nuclear unit and provide approximately 835 MW of carbon-free energy to the grid.

Constellation announcement, September 20, 2024 · First-party corporate announcement

OBSERVED DEPLOYMENT OR PRACTICE

Constellation and Meta Clinton Clean Energy Center Agreement

First-party announcement of a 20-year PPA for output of the Clinton Clean Energy Center supporting Meta operations and continued nuclear generation.

Constellation announcement, June 3, 2025 · First-party corporate announcement

CURRENT TECHNICAL STANDARD

Call for Comments on NIST SP 800-82 Revision 4

Official notice that NIST initiated revision of SP 800-82; the notice does not itself supersede Revision 3.

Revision-process notice, January 22, 2026 · PUBLIC COMMENT PROCESS; NOT A FINAL REVISION

CURRENT LAW OR POLICY

10 CFR Part 73 Subpart J — Security Requirements at Commercial Nuclear Plants

Current codified sections 73.100, 73.110, and 73.120. Selection and applicability depend on the Part 53 licensing path and facility election.

Current eCFR, reviewed 2026-08-15 · CODIFIED FEDERAL REGULATION

CURRENT LAW OR POLICY

Restricting Drones Near Critical Infrastructure Sites — Proposed Rule

Official May 2026 proposed rule for a petition process. A proposed restriction process does not itself grant a private facility authority to jam, spoof, seize, damage, or destroy an aircraft.

FAA proposed rule announcement, May 6, 2026 · PROPOSED RULE; NOT FINAL

CURRENT LAW OR POLICY

6 U.S.C. § 124n — Protection of Certain Facilities and Assets from Unmanned Aircraft

Federal statutory authorities for designated federal departments and covered missions; the statute is not a general delegation of counter-UAS mitigation authority to private facility owners.

Current preliminary U.S. Code text, reviewed 2026-08-15 · FEDERAL STATUTE

CURRENT LAW OR POLICY

47 U.S.C. § 333 — Willful or Malicious Interference

General federal prohibition on willful or malicious interference with authorized radio communications; system design must identify any separate statutory authority before proposing RF mitigation.

Current preliminary U.S. Code text, reviewed 2026-08-15 · FEDERAL STATUTE

CURRENT TECHNICAL STANDARD

NERC Critical Infrastructure Protection Reliability Standards Catalog

Official catalog for current CIP reliability standards. Applicability depends on BES registration, asset categorization, effective dates, implementation plans, and jurisdiction-specific enforcement; this catalog is not a facility compliance determination.

Current catalog, reviewed 2026-08-15 · OFFICIAL RELIABILITY-STANDARDS CATALOG

CURRENT LAW OR POLICY

National Cyber Force — About Us

Official description of the NCF as a defence-intelligence partnership operating in and through cyberspace under UK and international law. It does not create authority for private independent cyber effects.

Official organizational page reviewed 2026-08-15 · OFFICIAL CURRENT ORGANIZATIONAL DESCRIPTION

CURRENT LAW OR POLICY

Government Cyber Security Strategy 2022 to 2030 — 2026 currentness notice

Official strategy page updated in January 2026 to direct readers to the Government Cyber Action Plan for the latest implementation details.

Strategy page updated 2026-01-06 · OFFICIAL STRATEGY WITH LATER ACTION-PLAN POINTER

CURRENT LAW OR POLICY

France COMCYBER — La lutte informatique offensive (LIO) — K06 current record

Official public description of military offensive cyber operations. It is a state military doctrine record, not a private-sector license or universal rule of international law.

Official COMCYBER page reviewed 2026-08-15 · OFFICIAL CURRENT MILITARY DOCTRINE DESCRIPTION

CURRENT LAW OR POLICY

France COMCYBER — La lutte informatique défensive (LID) — K06 current record

Official public description of defensive military cyber activity and permanent defensive posture.

Official COMCYBER page reviewed 2026-08-15 · OFFICIAL CURRENT MILITARY DOCTRINE DESCRIPTION

CURRENT LAW OR POLICY

Directive (EU) 2022/2555 — NIS 2 Directive

Official NIS 2 legal text. Entity scope, national transposition, sector classification, and enforcement remain jurisdiction- and organization-specific.

Directive (EU) 2022/2555 · EU DIRECTIVE

CURRENT LAW OR POLICY

Cyber Resilience Act — Implementation and reporting timeline

Official implementation timeline. At the K06 cutoff, the Act was in force; reporting obligations were scheduled for 2026-09-11 and main obligations for 2027-12-11.

Commission implementation page updated 2026-07-27 · EU REGULATION IN FORCE WITH PHASED APPLICATION

CURRENT LAW OR POLICY

Australian Signals Directorate — Offensive cyber

Official description of government-directed offshore offensive cyber activity. It expressly ties operations to Australian Government authorization and a legal framework.

Official ASD page reviewed 2026-08-15 · OFFICIAL CURRENT CAPABILITY DESCRIPTION

CURRENT LAW OR POLICY

2023–2030 Australian Cyber Security Strategy — Horizon 2

Official Horizon 2 page for 2026–2028, recording a current whole-of-nation cyber-resilience program. It does not by itself establish facility compliance or private operational authority.

Horizon 2 page updated 2026-07-13 · OFFICIAL CURRENT STRATEGY ACTION PLAN

CURRENT LAW OR POLICY

Republic of Korea NIS — Cyber and AI security publications

Official publication index showing current national cybersecurity white papers, annual reports, and AI/ML supply-chain guidance. The index does not by itself establish every proposition in third-party accounts of ROK doctrine.

Official publication index reviewed 2026-08-15 · OFFICIAL CURRENT PUBLICATION INDEX

CURRENT LAW OR POLICY

ROK position on application of international law in cyberspace — official publication listing

The official MOFA publication index identifies a 2025 national position. K06 did not obtain a stable exact English document URL through the bounded retrieval path, so substantive propositions remain partially reviewed.

Official MOFA listing observed 2026-08-15 · OFFICIAL LISTING; EXACT DOCUMENT RETRIEVAL PARTIAL

CURRENT LAW OR POLICY

Canada's National Cyber Security Strategy — Securing Canada's Digital Future

Official 2025 strategy backgrounder identifying whole-of-society engagement, agile leadership, protection, global leadership, and detection/disruption pillars.

2025 National Cyber Security Strategy · OFFICIAL CURRENT NATIONAL STRATEGY

CURRENT LAW OR POLICY

Articles on Responsibility of States for Internationally Wrongful Acts

Official ILC text addressing attribution, direction and control, breach, and circumstances precluding wrongfulness. It is not a cyber-specific treaty and does not resolve all disputed cyber applications.

2001 draft articles annexed to UN General Assembly resolution 56/83 · AUTHORITATIVE ILC DRAFT ARTICLES COMMENDED TO STATES; NOT A CYBER-SPECIFIC CONVENTION

CURRENT LAW OR POLICY

Cyber operations and harmful information

Official ICRC position resource emphasizing protection of civilians, civilian infrastructure, and civilian data under international humanitarian law during armed conflict.

Official topic page reviewed 2026-08-15 · OFFICIAL ICRC LEGAL AND POLICY POSITION

CURRENT LAW OR POLICY

Responsible Cyber Power in Practice

Official public description of the National Cyber Force approach to accountable, precise, and calibrated cyber operations under UK authority.

Publication dated 4 April 2023 · OFFICIAL CURRENT PUBLIC DOCTRINE; operational details remain classified

CURRENT LAW OR POLICY

National Cyber Strategy 2022

Official strategy describing the United Kingdom's objective to remain a leading responsible and democratic cyber power able to protect and promote national interests in and through cyberspace.

National Cyber Strategy 2022 · OFFICIAL NATIONAL STRATEGY

CURRENT LAW OR POLICY

La lutte informatique défensive (LID)

Official French military description of defensive cyber operations and protection of ministry systems and missions.

Current COMCYBER public doctrine page · OFFICIAL MILITARY DOCTRINE PAGE

CURRENT LAW OR POLICY

La lutte informatique offensive (LIO)

Official French military description of offensive cyber operations as a military mission under state command; it is not private-sector authority.

Current COMCYBER public doctrine page · OFFICIAL MILITARY DOCTRINE PAGE

CURRENT LAW OR POLICY

EU Policy on Cyber Defence

Official EU policy overview calling for full-spectrum cyber-defence capability, closer civilian-military coordination, private-sector cooperation, crisis management, and reduced strategic dependencies.

Current European Commission policy overview · OFFICIAL EU POLICY OVERVIEW

CURRENT LAW OR POLICY

Action Plan on Cybersecurity and Artificial Intelligence

Official 2026 action-plan record addressing risks and opportunities of advanced AI in cybersecurity; it supplements rather than silently replaces existing EU legal instruments.

European Commission action plan, 7 July 2026 · OFFICIAL ACTION PLAN

CURRENT LAW OR POLICY

2023–2030 Australian Cyber Security Strategy

Official national strategy organized around six cyber shields, including protected critical infrastructure, sovereign capability, threat sharing and blocking, and regional resilience.

2023–2030 strategy · OFFICIAL NATIONAL STRATEGY

CURRENT LAW OR POLICY

Republic of Korea National Cybersecurity Strategy 2024

Official national-strategy record emphasizing proactive cyber defence, international cooperation, critical-infrastructure resilience, emerging-technology advantage, and integrated response capability.

National Cybersecurity Strategy, February 2024 · OFFICIAL NATIONAL STRATEGY

OBSERVED DEPLOYMENT OR PRACTICE

Korea's 2024 National Cybersecurity White Paper

Officially published multi-agency white paper describing Korea's national cybersecurity framework, threat trends, and sector activities.

2024 National Cybersecurity White Paper · OFFICIAL MULTI-AGENCY WHITE PAPER

CURRENT LAW OR POLICY

Canada's National Cyber Security Strategy: Securing Canada's Digital Future

Official 2025 strategy organized around whole-of-society engagement, agile leadership, protection partnerships, global leadership, and detection and disruption of cyber threat actors.

PS4-239/2025E-PDF · OFFICIAL NATIONAL STRATEGY

OBSERVED DEPLOYMENT OR PRACTICE

National Cyber Threat Assessment 2025–2026

Official threat assessment identifying persistent cybercrime, ransomware risk to critical infrastructure, and increasingly disruptive state-sponsored activity.

2025–2026 assessment · OFFICIAL NATIONAL THREAT ASSESSMENT

CURRENT LAW OR POLICY

Report of the Group of Governmental Experts on Advancing Responsible State Behaviour in Cyberspace

UN-mandated consensus report addressing responsible state behaviour, international law, norms, confidence-building, capacity-building, and cyber risk.

A/76/135, 14 July 2021 · UNITED NATIONS CONSENSUS REPORT; not a treaty or complete code

CURRENT LAW OR POLICY

International Humanitarian Law and Cyber Operations During Armed Conflicts

ICRC position paper explaining that IHL applies to and limits cyber operations during armed conflict, with particular concern for civilian harm and infrastructure.

ICRC position paper, 28 November 2019 · OFFICIAL ICRC LEGAL POSITION; not itself binding state law

CURRENT LAW OR POLICY

10 CFR Part 53 — Risk-Informed, Technology-Inclusive Regulatory Framework for Advanced Reactors

Official final-rule notice establishing an optional technology-inclusive framework for licensing future commercial nuclear plants. Applicability to a named facility requires licensing counsel and NRC process evidence.

Final rule, 2026 · OFFICIAL FINAL RULE NOTICE

CURRENT LAW OR POLICY

NRC Regulatory Guide 5.71 Revision 1 — Cyber Security Programs for Nuclear Power Reactors

Official regulatory guide describing an NRC-accepted method for meeting nuclear-reactor cyber-security requirements. A guide is not a facility license, finding, or universal certification.

Revision 1 · OFFICIAL REGULATORY GUIDE

CURRENT TECHNICAL STANDARD

DOE Cyber-Informed Engineering

Official DOE method page describing integration of cyber-security considerations into engineering conception, design, development, and operation, with priority on worst-consequence pathways.

Official program page reviewed 2026-08-15 · OFFICIAL PROGRAM GUIDANCE

CURRENT TECHNICAL STANDARD

NIST SP 800-82 Revision 3 — K07 Official Review Record

Final NIST guidance for securing operational technology while addressing performance, reliability, and safety requirements. NIST initiated a Revision 4 pre-draft process in 2026; Revision 3 remains the final publication at the K07 cutoff.

Revision 3 · FINAL; REVISION 4 PRE-DRAFT PROCESS OPENED 2026

RESEARCH FINDING

NIST SP 800-82 Revision 4 — Pre-Draft Call for Comments

Official pre-draft revision notice. It is evidence that revision work is underway, not a final control baseline or replacement for Revision 3.

Pre-draft call for comments · PRE-DRAFT; NOT FINAL

CURRENT TECHNICAL STANDARD

NIST SP 800-161 Revision 1 Update 1 — Cybersecurity Supply Chain Risk Management Practices

Final NIST C-SCRM guidance for identifying, assessing, and mitigating supply-chain risk across organizational levels and system life cycles.

Revision 1 Update 1 · FINAL

CURRENT TECHNICAL STANDARD

NIST SP 1326 — Cybersecurity Supply Chain Risk Management Due Diligence Assessment Quick-Start Guide

Final quick-start guide for minimum reasonable supplier and product research supporting acquisition and existing-system decisions; it supplements rather than replaces SP 800-161 Revision 1.

Final · FINAL

CURRENT TECHNICAL STANDARD

NIST IR 8356 — Security and Trust Considerations for Digital Twin Technology

Final NIST report on digital-twin characteristics, expected uses, cyber-security challenges, and trust considerations. It does not certify a twin as faithful to a real facility.

NIST IR 8356 · FINAL

CURRENT TECHNICAL STANDARD

NIST SP 800-218A — Secure Software Development Practices for Generative AI and Dual-Use Foundation Models

Final SSDF community profile adding model-development practices and tasks for producers and acquirers of AI systems. Use with SP 800-218, not as a standalone certification.

Final · FINAL

CURRENT LAW OR POLICY

Federal Acquisition Regulation 37.602 — Performance Work Statement

Current FAR text requiring performance work statements, to the maximum extent practicable, to describe required results and enable assessment against measurable performance standards.

FAC 2026 current text reviewed 2026-08-15 · CURRENT FEDERAL ACQUISITION REGULATION

CURRENT LAW OR POLICY

Federal Acquisition Regulation Part 46 — Quality Assurance

Current FAR quality-assurance provisions addressing inspection, contractor quality control, nonconformance, acceptance, critical items, and surveillance plans.

FAC 2026 current text reviewed 2026-08-15 · CURRENT FEDERAL ACQUISITION REGULATION

CURRENT TECHNICAL STANDARD

NTIA — The Minimum Elements for a Software Bill of Materials

Official minimum-element report covering baseline component data, automation support, and practices for software transparency. An SBOM is inventory evidence, not proof of absence of vulnerabilities or compromise.

July 12, 2021 report · OFFICIAL GUIDANCE

CURRENT TECHNICAL STANDARD

CISA Hardware Bill of Materials Framework for Supply Chain Risk Management

Official framework providing repeatable component naming, attribute, and format concepts for hardware supply-chain transparency. HBOM completeness and applicability remain product- and contract-specific.

September 2023 framework · OFFICIAL FRAMEWORK

RESEARCH FINDING

NIST AI RMF Profile on Trustworthy AI in Critical Infrastructure — Concept Note

Official 2026 concept note for a critical-infrastructure AI RMF profile. It is development evidence, not a final profile or certification baseline.

Concept note · CONCEPT NOTE; PROFILE UNDER DEVELOPMENT

CURRENT TECHNICAL STANDARD

Unicode 17.0 Runic Code Chart

Official character chart for the Runic block U+16A0–U+16FF. Encoding a character does not assign a modern project meaning or guarantee domain-registration support.

Unicode 17.0 · OFFICIAL CHARACTER CODE CHART

CURRENT TECHNICAL STANDARD

Unicode Standard Annex #15 — Unicode Normalization Forms

Normative Unicode normalization specification. NFC consistency supports stable comparison, but normalization does not create semantic equivalence between different characters.

Unicode 17.0.0, Revision 57 · UNICODE STANDARD ANNEX

CURRENT TECHNICAL STANDARD

RFC 3492 — Punycode: A Bootstring Encoding of Unicode for IDNA

Defines Punycode, the ASCII-compatible encoding used by IDNA. It does not determine registry policy, registration availability, DNS delegation, TLS issuance, or hosting status.

RFC 3492 · PROPOSED STANDARD; UPDATED BY RFC 5891

CURRENT TECHNICAL STANDARD

RFC 5890 — IDNA Definitions and Document Framework

Defines IDNA terminology including U-labels and A-labels. Protocol validity remains distinct from registry, registrar, delegation, resolution, certificate, and hosting states.

RFC 5890 · PROPOSED STANDARD

CURRENT TECHNICAL STANDARD

RFC 5891 — Internationalized Domain Names in Applications: Protocol

Defines IDNA2008 registration and lookup protocol without changing DNS itself. It is for domain names, not free text.

RFC 5891 · PROPOSED STANDARD

CURRENT TECHNICAL STANDARD

RFC 5646 — Tags for Identifying Languages

Defines BCP 47 language tags. A script subtag must describe the actual language and script of content rather than serving as a search-engine hint.

RFC 5646 / BCP 47 · BEST CURRENT PRACTICE

CURRENT TECHNICAL STANDARD

FIPS 203 — Module-Lattice-Based Key-Encapsulation Mechanism Standard

Specifies ML-KEM parameter sets for key establishment. Migration requires inventory, interoperability, implementation validation, and lifecycle planning; publication does not make an existing system quantum-resistant.

FIPS 203 · FINAL

CURRENT TECHNICAL STANDARD

FIPS 204 — Module-Lattice-Based Digital Signature Standard

Specifies ML-DSA digital signatures. Algorithm adoption does not prove signer authority, factual truth, implementation correctness, or migration completion.

FIPS 204 · FINAL

CURRENT TECHNICAL STANDARD

FIPS 205 — Stateless Hash-Based Digital Signature Standard

Specifies SLH-DSA. It is one migration option with distinct signature-size and performance tradeoffs that must be evaluated for the named use.

FIPS 205 · FINAL

Source authority boundary

Official publication supports provenance and bounded propositions. It does not automatically prove factual truth, legal status, consciousness, personhood, citizenship, operational deployment, or authority outside the publisher’s scope.