About CHERI Enabled

CHERI Enabled provides a common public signal that a named product has been reviewed against the Alliance's programme for applying CHERI security principles.

Products can claim to use CHERI in very different ways. One may implement a capability instruction set in a processor core. Another may run a complete pure-capability software stack. The CHERI Enabled programme gives developers, integrators, and buyers a common record of what a particular product claims and the evidence reviewed by the Alliance.

Why the programme matters

CHERI’s value depends on correct implementation. Its capabilities are protected references carrying memory bounds and permissions. Protected tags distinguish valid capabilities, the architecture governs capability-mediated memory access, and privileged or debug paths can affect the security boundary. A logo without a defined product and scope would not explain whether those properties are present.

The programme connects the CHERI Enabled mark to a named product, version, questionnaire, and review. Published answers provide context about the implementation rather than reducing it to a badge.

What the mark represents

The Alliance reviews evidence supplied by an applicant through written responses and interviews. When the application meets the programme requirements, the named product can be listed and use the CHERI Enabled logo under the applicable trademark terms.

The public record can cover:

This information helps distinguish a processor that implements CHERI correctly from a complete product that also uses capabilities throughout its software. Both may be relevant, but their scope is not the same.

What the mark does not represent

The Alliance states that it does not currently conduct independent product testing. Its decision is based on evidence presented by the applicant and discussed during review.

The mark does not guarantee the overall security of a product. A certified processor core does not automatically certify a system-on-chip, board, operating system, application, or deployed device. Integration, configuration, software, update support, and the operating environment remain outside a component claim unless the certified product explicitly includes them.

Membership of the CHERI Alliance also does not certify an organisation or its products.

Why this can support adoption

Early technology markets often contain claims that are difficult to compare. CHERI Enabled provides a shared vocabulary and a public evidence record. That can reduce uncertainty for organisations deciding whether a product offers the form of memory protection or containment relevant to their system.

The programme is designed to evolve as standards, test suites, and experience develop. The Alliance expects certification to be reviewed every two years so that listed products can be considered against improvements to the programme.

The CHERI Enabled product directory contains the public records for approved products. Certification describes the current programme, fees, review cycle, and application route.

Where next

Certification

Certification records the product, version, submitted evidence, review process, and scope behind the CHERI Enabled mark.

Continue