Technical standards

Standards

Direct answer

Primary technical standards and official policy sources used by the knowledge architecture. The page is part of the source-grounded ᚲ.com knowledge release and remains bounded to knowledge authority.

Standards used by the knowledge model

PROV-O: The PROV Ontology

Vocabulary for representing provenance information.

W3C

Decentralized Identifiers (DIDs) v1.0

Technical standard relevant to identifier control and verification methods; it does not by itself establish legal identity.

W3C

Verifiable Credentials Data Model v2.0

Data model for tamper-evident credentials and presentations; credential integrity is distinct from truth and authority.

W3C

JSON-LD 1.1

Linked-data serialization used for public knowledge records.

W3C

Web Content Accessibility Guidelines (WCAG) 2.2

Accessibility requirements used as the public-interface target.

W3C

Artificial Intelligence Risk Management Framework (AI RMF 1.0)

Risk-management reference for systems described by industry and government as AI. Version 1.0 remains the published framework but is under revision as of the 2026-08-14 research cutoff.

NIST

NIST SP 800-218 Secure Software Development Framework Version 1.1

Final secure software development practices used for implementation and release controls. Version 1.2 remained an initial public draft at the research cutoff.

NIST

NIST SP 800-53 Rev. 5, Release 5.2.0 Security and Privacy Controls

Current 2025 minor release of the Rev. 5 control catalog used for assurance, access control, audit and resilience references.

NIST

RFC 5280: Internet X.509 Public Key Infrastructure Certificate and CRL Profile

Certificate profile useful for understanding key-bound credentials and revocation.

IETF

RFC 6962: Certificate Transparency

Experimental Certificate Transparency v1 protocol, now obsolete and superseded by RFC 9162; retained for historical comparison.

IETF

RFC 3161: Time-Stamp Protocol

Protocol relevant to evidence that a representation existed by a specified time.

IETF

Supply-chain Levels for Software Artifacts (SLSA) Specification v1.2

Current approved software supply-chain integrity specification at the 2026-08-14 research cutoff, relevant to attributable releases and provenance.

OpenSSF

in-toto Attestation Framework

Attestation framework for software supply-chain steps and evidence.

in-toto project

C2PA Technical Specification v2.4

Current content-provenance specification at the 2026-08-14 research cutoff; provenance assertions remain distinct from factual truth.

Coalition for Content Provenance and Authenticity

RFC 9162: Certificate Transparency Version 2.0

Experimental Certificate Transparency v2 protocol that obsoletes RFC 6962; useful as a design reference for append-only, publicly auditable logs.

IETF

WCAG Evaluation Methodology (WCAG-EM) 2.0

Informative evaluation methodology for defining scope, exploring a product, selecting representative samples, evaluating them, and reporting findings; it does not add or replace WCAG requirements.

W3C

Accessibility Conformance Testing (ACT) Rules Format 1.1

W3C Recommendation defining a common format for documenting automated and manual accessibility test rules; a test-rule format does not itself establish whole-site conformance.

W3C

NIST SP 800-82 Revision 3 — Guide to Operational Technology Security

Official guidance for securing operational technology while addressing performance, reliability, and safety requirements.

National Institute of Standards and Technology

NIST SP 800-207 — Zero Trust Architecture

Official zero-trust architecture guidance that removes implicit trust based on network location and focuses protection on resources, identities, and policy decisions.

National Institute of Standards and Technology

Call for Comments on NIST SP 800-82 Revision 4

Official notice that NIST initiated revision of SP 800-82; the notice does not itself supersede Revision 3.

National Institute of Standards and Technology

NERC Critical Infrastructure Protection Reliability Standards Catalog

Official catalog for current CIP reliability standards. Applicability depends on BES registration, asset categorization, effective dates, implementation plans, and jurisdiction-specific enforcement; this catalog is not a facility compliance determination.

North American Electric Reliability Corporation

DOE Cyber-Informed Engineering

Official DOE method page describing integration of cyber-security considerations into engineering conception, design, development, and operation, with priority on worst-consequence pathways.

U.S. Department of Energy, CESER

NIST SP 800-82 Revision 3 — K07 Official Review Record

Final NIST guidance for securing operational technology while addressing performance, reliability, and safety requirements. NIST initiated a Revision 4 pre-draft process in 2026; Revision 3 remains the final publication at the K07 cutoff.

National Institute of Standards and Technology

NIST SP 800-161 Revision 1 Update 1 — Cybersecurity Supply Chain Risk Management Practices

Final NIST C-SCRM guidance for identifying, assessing, and mitigating supply-chain risk across organizational levels and system life cycles.

National Institute of Standards and Technology

NIST SP 1326 — Cybersecurity Supply Chain Risk Management Due Diligence Assessment Quick-Start Guide

Final quick-start guide for minimum reasonable supplier and product research supporting acquisition and existing-system decisions; it supplements rather than replaces SP 800-161 Revision 1.

National Institute of Standards and Technology

NIST IR 8356 — Security and Trust Considerations for Digital Twin Technology

Final NIST report on digital-twin characteristics, expected uses, cyber-security challenges, and trust considerations. It does not certify a twin as faithful to a real facility.

National Institute of Standards and Technology

NIST SP 800-218A — Secure Software Development Practices for Generative AI and Dual-Use Foundation Models

Final SSDF community profile adding model-development practices and tasks for producers and acquirers of AI systems. Use with SP 800-218, not as a standalone certification.

National Institute of Standards and Technology

NTIA — The Minimum Elements for a Software Bill of Materials

Official minimum-element report covering baseline component data, automation support, and practices for software transparency. An SBOM is inventory evidence, not proof of absence of vulnerabilities or compromise.

National Telecommunications and Information Administration

CISA Hardware Bill of Materials Framework for Supply Chain Risk Management

Official framework providing repeatable component naming, attribute, and format concepts for hardware supply-chain transparency. HBOM completeness and applicability remain product- and contract-specific.

Cybersecurity and Infrastructure Security Agency

Unicode 17.0 Runic Code Chart

Official character chart for the Runic block U+16A0–U+16FF. Encoding a character does not assign a modern project meaning or guarantee domain-registration support.

Unicode Consortium

Unicode Standard Annex #15 — Unicode Normalization Forms

Normative Unicode normalization specification. NFC consistency supports stable comparison, but normalization does not create semantic equivalence between different characters.

Unicode Consortium

RFC 3492 — Punycode: A Bootstring Encoding of Unicode for IDNA

Defines Punycode, the ASCII-compatible encoding used by IDNA. It does not determine registry policy, registration availability, DNS delegation, TLS issuance, or hosting status.

IETF / RFC Editor

RFC 5890 — IDNA Definitions and Document Framework

Defines IDNA terminology including U-labels and A-labels. Protocol validity remains distinct from registry, registrar, delegation, resolution, certificate, and hosting states.

IETF / RFC Editor

RFC 5891 — Internationalized Domain Names in Applications: Protocol

Defines IDNA2008 registration and lookup protocol without changing DNS itself. It is for domain names, not free text.

IETF / RFC Editor

RFC 5646 — Tags for Identifying Languages

Defines BCP 47 language tags. A script subtag must describe the actual language and script of content rather than serving as a search-engine hint.

IETF / RFC Editor

FIPS 203 — Module-Lattice-Based Key-Encapsulation Mechanism Standard

Specifies ML-KEM parameter sets for key establishment. Migration requires inventory, interoperability, implementation validation, and lifecycle planning; publication does not make an existing system quantum-resistant.

NIST

FIPS 204 — Module-Lattice-Based Digital Signature Standard

Specifies ML-DSA digital signatures. Algorithm adoption does not prove signer authority, factual truth, implementation correctness, or migration completion.

NIST

FIPS 205 — Stateless Hash-Based Digital Signature Standard

Specifies SLH-DSA. It is one migration option with distinct signature-size and performance tradeoffs that must be evaluated for the named use.

NIST

Conformance boundary

Conformance to a credential, provenance, identity, accessibility, security, or supply-chain standard supports only the properties that standard specifies. It does not establish consciousness, personhood, citizenship, sovereignty, authority, factual truth, or current operation.