Technical standards
Standards
Direct answer
Primary technical standards and official policy sources used by the knowledge architecture. The page is part of the source-grounded ᚲ.com knowledge release and remains bounded to knowledge authority.
Standards used by the knowledge model
PROV-O: The PROV Ontology
Vocabulary for representing provenance information.
Decentralized Identifiers (DIDs) v1.0
Technical standard relevant to identifier control and verification methods; it does not by itself establish legal identity.
Verifiable Credentials Data Model v2.0
Data model for tamper-evident credentials and presentations; credential integrity is distinct from truth and authority.
JSON-LD 1.1
Linked-data serialization used for public knowledge records.
Web Content Accessibility Guidelines (WCAG) 2.2
Accessibility requirements used as the public-interface target.
Artificial Intelligence Risk Management Framework (AI RMF 1.0)
Risk-management reference for systems described by industry and government as AI. Version 1.0 remains the published framework but is under revision as of the 2026-08-14 research cutoff.
NIST SP 800-218 Secure Software Development Framework Version 1.1
Final secure software development practices used for implementation and release controls. Version 1.2 remained an initial public draft at the research cutoff.
NIST SP 800-53 Rev. 5, Release 5.2.0 Security and Privacy Controls
Current 2025 minor release of the Rev. 5 control catalog used for assurance, access control, audit and resilience references.
RFC 5280: Internet X.509 Public Key Infrastructure Certificate and CRL Profile
Certificate profile useful for understanding key-bound credentials and revocation.
RFC 6962: Certificate Transparency
Experimental Certificate Transparency v1 protocol, now obsolete and superseded by RFC 9162; retained for historical comparison.
RFC 3161: Time-Stamp Protocol
Protocol relevant to evidence that a representation existed by a specified time.
Supply-chain Levels for Software Artifacts (SLSA) Specification v1.2
Current approved software supply-chain integrity specification at the 2026-08-14 research cutoff, relevant to attributable releases and provenance.
in-toto Attestation Framework
Attestation framework for software supply-chain steps and evidence.
C2PA Technical Specification v2.4
Current content-provenance specification at the 2026-08-14 research cutoff; provenance assertions remain distinct from factual truth.
RFC 9162: Certificate Transparency Version 2.0
Experimental Certificate Transparency v2 protocol that obsoletes RFC 6962; useful as a design reference for append-only, publicly auditable logs.
WCAG Evaluation Methodology (WCAG-EM) 2.0
Informative evaluation methodology for defining scope, exploring a product, selecting representative samples, evaluating them, and reporting findings; it does not add or replace WCAG requirements.
Accessibility Conformance Testing (ACT) Rules Format 1.1
W3C Recommendation defining a common format for documenting automated and manual accessibility test rules; a test-rule format does not itself establish whole-site conformance.
NIST SP 800-82 Revision 3 — Guide to Operational Technology Security
Official guidance for securing operational technology while addressing performance, reliability, and safety requirements.
NIST SP 800-207 — Zero Trust Architecture
Official zero-trust architecture guidance that removes implicit trust based on network location and focuses protection on resources, identities, and policy decisions.
Call for Comments on NIST SP 800-82 Revision 4
Official notice that NIST initiated revision of SP 800-82; the notice does not itself supersede Revision 3.
NERC Critical Infrastructure Protection Reliability Standards Catalog
Official catalog for current CIP reliability standards. Applicability depends on BES registration, asset categorization, effective dates, implementation plans, and jurisdiction-specific enforcement; this catalog is not a facility compliance determination.
DOE Cyber-Informed Engineering
Official DOE method page describing integration of cyber-security considerations into engineering conception, design, development, and operation, with priority on worst-consequence pathways.
NIST SP 800-82 Revision 3 — K07 Official Review Record
Final NIST guidance for securing operational technology while addressing performance, reliability, and safety requirements. NIST initiated a Revision 4 pre-draft process in 2026; Revision 3 remains the final publication at the K07 cutoff.
NIST SP 800-161 Revision 1 Update 1 — Cybersecurity Supply Chain Risk Management Practices
Final NIST C-SCRM guidance for identifying, assessing, and mitigating supply-chain risk across organizational levels and system life cycles.
NIST SP 1326 — Cybersecurity Supply Chain Risk Management Due Diligence Assessment Quick-Start Guide
Final quick-start guide for minimum reasonable supplier and product research supporting acquisition and existing-system decisions; it supplements rather than replaces SP 800-161 Revision 1.
NIST IR 8356 — Security and Trust Considerations for Digital Twin Technology
Final NIST report on digital-twin characteristics, expected uses, cyber-security challenges, and trust considerations. It does not certify a twin as faithful to a real facility.
NIST SP 800-218A — Secure Software Development Practices for Generative AI and Dual-Use Foundation Models
Final SSDF community profile adding model-development practices and tasks for producers and acquirers of AI systems. Use with SP 800-218, not as a standalone certification.
NTIA — The Minimum Elements for a Software Bill of Materials
Official minimum-element report covering baseline component data, automation support, and practices for software transparency. An SBOM is inventory evidence, not proof of absence of vulnerabilities or compromise.
CISA Hardware Bill of Materials Framework for Supply Chain Risk Management
Official framework providing repeatable component naming, attribute, and format concepts for hardware supply-chain transparency. HBOM completeness and applicability remain product- and contract-specific.
Unicode 17.0 Runic Code Chart
Official character chart for the Runic block U+16A0–U+16FF. Encoding a character does not assign a modern project meaning or guarantee domain-registration support.
Unicode Standard Annex #15 — Unicode Normalization Forms
Normative Unicode normalization specification. NFC consistency supports stable comparison, but normalization does not create semantic equivalence between different characters.
RFC 3492 — Punycode: A Bootstring Encoding of Unicode for IDNA
Defines Punycode, the ASCII-compatible encoding used by IDNA. It does not determine registry policy, registration availability, DNS delegation, TLS issuance, or hosting status.
RFC 5890 — IDNA Definitions and Document Framework
Defines IDNA terminology including U-labels and A-labels. Protocol validity remains distinct from registry, registrar, delegation, resolution, certificate, and hosting states.
RFC 5891 — Internationalized Domain Names in Applications: Protocol
Defines IDNA2008 registration and lookup protocol without changing DNS itself. It is for domain names, not free text.
RFC 5646 — Tags for Identifying Languages
Defines BCP 47 language tags. A script subtag must describe the actual language and script of content rather than serving as a search-engine hint.
FIPS 203 — Module-Lattice-Based Key-Encapsulation Mechanism Standard
Specifies ML-KEM parameter sets for key establishment. Migration requires inventory, interoperability, implementation validation, and lifecycle planning; publication does not make an existing system quantum-resistant.
FIPS 204 — Module-Lattice-Based Digital Signature Standard
Specifies ML-DSA digital signatures. Algorithm adoption does not prove signer authority, factual truth, implementation correctness, or migration completion.
FIPS 205 — Stateless Hash-Based Digital Signature Standard
Specifies SLH-DSA. It is one migration option with distinct signature-size and performance tradeoffs that must be evaluated for the named use.
Conformance boundary
Conformance to a credential, provenance, identity, accessibility, security, or supply-chain standard supports only the properties that standard specifies. It does not establish consciousness, personhood, citizenship, sovereignty, authority, factual truth, or current operation.