Certification
CHERI Enabled certification turns a broad technology claim into a product-specific record of implementation, evidence, limitations, and review.
The term “CHERI product” can cover anything from a processor core to a complete software platform. CHERI capabilities are processor-protected references that carry memory bounds and permissions. Certification makes a claim about their implementation more useful by attaching it to a defined product, version, programme, and evidence record.
The CHERI Enabled process
The Alliance’s programme is based on a technical questionnaire and review interviews. Its main stages are:
- definition of the product, version, configuration, and relationship to any previously certified product;
- written answers covering the CHERI implementation and supporting evidence;
- review questions and interviews with the Alliance team;
- a certification decision and, where approved, a published product record;
- authorised display of the CHERI Enabled mark under the programme’s trademark conditions;
- later reassessment as the product or programme changes.
First applications receive a full assessment. Updated, derivative, or previously certified products may follow a reduced reassessment path, with the differences from the earlier record remaining part of the scope.
Why the evidence is technically useful
The questionnaire goes beyond confirmation that CHERI instructions exist. It records details that affect whether capability protection works as intended, including:
- the architecture and extension versions implemented;
- supported execution modes and configurations outside certification;
- design verification and compliance testing;
- memory access that can occur without an explicit capability;
- protection of tags and capability metadata;
- temporal memory-safety mechanisms;
- debug, privilege, and integration behaviour;
- compiler and software support;
- known limitations and assumptions.
These details help an integrator understand whether a certified component fits the architecture of a wider product. They also expose the difference between a processor capability and a system-level security outcome.
A scoped form of confidence
The Alliance currently relies on the applicant’s written evidence and interviews rather than independent product testing. Certification therefore represents the Alliance’s judgement that the submitted evidence supports correct application of CHERI security principles under the programme.
It is not a guarantee of complete product security. It does not replace penetration testing, sector certification, software assurance, supply-chain review, or the integrator’s responsibility for the system surrounding the certified product.
Why periodic review matters
CHERI architectures, tools, verification methods, and implementation experience continue to develop. The programme is intended to evolve with them, and the Alliance expects product certification to be reviewed every two years.
That review model gives the mark value beyond a one-time claim. The published record can remain connected to a known programme version while later assessments reflect improvements in criteria and evidence.
Certification fees
The application fee supports operation of the programme and is non-refundable. The published fees are:
- First certification: £3,000 for non-members or £1,000 for CHERI Alliance members.
- Recertification: £1,500 for non-members or £500 for CHERI Alliance members.
The lower recertification fee also applies to the review of a derivative of a certified product where the programme accepts the relationship to the earlier record.
Programme and application information
The CHERI Enabled product directory shows how the questionnaire answers and certification boundary are published. An organisation considering an application can use the Alliance contact route for the current questionnaire, programme document, and submission arrangements.
