About CHERI Enabled
The CHERI Enabled logo identifies a named product whose submitted evidence has been reviewed against the Alliance certification programme.
The CHERI Enabled programme gives product developers and buyers a common way to identify products that apply CHERI security principles. Certification belongs to the exact product and version recorded by the programme, not automatically to every derivative or system that contains it.
What the logo means
The Alliance reviews evidence supplied through a questionnaire and interviews. If the application meets the programme requirements, the product may be listed and use the CHERI Enabled logo subject to the Alliance’s trademark requirements.
The programme publishes certification answers so users can examine matters such as:
- the implemented CHERI instruction-set architecture and extensions;
- how hardware behaviour was verified;
- paths that can access memory without an explicit capability;
- how capability tags are protected;
- the approach to temporal memory safety;
- compiler and software support;
- limitations and integration assumptions.
What the logo does not mean
The Alliance states that it does not currently conduct independent product testing and relies on the applicant’s responses and interviews. The logo does not guarantee the overall security of a product. A complete product evaluation must also cover its integration, software, configuration, lifecycle, and operating environment.
Certification is reviewed against a programme that evolves with standards, test suites, and learning from applications. The Alliance expects a product’s certification to be reviewed every two years.
Who can use it
Only products approved through the programme may use the CHERI Enabled logo, and only in line with the applicable trademark rules. Membership of the Alliance does not itself certify a product.
See the current programme, process, and application information on the Alliance website. Organisations evaluating a claim should also consult the product’s published certification record and confirm that its version and configuration match the intended use.
