Assurance & Certification
CHERI evidence can strengthen an assurance case, but certification remains specific to a product, claim, scheme, and operating context.
Assurance explains why defined security or safety claims should be trusted. Certification is a formal judgement made under a particular scheme. Neither follows from using a CHERI-capable processor alone.
Start with a precise claim
Useful claims describe a boundary and an outcome, for example:
In the evaluated configuration, the packet parser can read and write only its assigned buffers and can call only the documented services.
That claim can be traced to the architecture, capability permissions, compartment setup, compiler and runtime behaviour, tests, and analysis. A broad statement such as “CHERI makes the product secure” cannot be tested or certified meaningfully.
Evidence that may contribute
Evidence comes from several connected layers:
- Architecture: the instruction-set specification, threat model, security properties, and behaviour when a check fails.
- Hardware: design verification, formal analysis, compliance tests, protection of capability metadata, and debug controls.
- Toolchain: the compiler version, conformance results, known limitations, and information needed to reproduce a build.
- Software: port reviews, compartment rules, an inventory of unsafe code, test results, and vulnerability handling.
- Integration: the boot chain, device and direct-memory-access paths, configuration, updates, and operational monitoring.
- Product: traceable requirements, risk analysis, security testing, lifecycle support, and recorded residual risks.
Evidence from one layer does not settle the others. A certified processor core, for example, may be integrated with a direct-memory-access engine or debug path that requires additional controls.
Work with the relevant scheme
Sector schemes differ in the claims, independence, documentation, and lifecycle controls they require. Engage assessors early. Explain CHERI in terms of enforced properties and evidence, then map those properties to the scheme rather than expecting the scheme to recognise a technology name.
The Alliance’s CHERI Enabled programme has a narrower purpose: identifying products whose submitted evidence supports correct application of CHERI security principles. It is not a general product-security certificate.
Keep assurance current
Record the exact product, version, architecture profile, toolchain, configuration, and dependencies. Define what changes trigger review. Continue vulnerability handling, regression testing, and evidence maintenance after release.
Good assurance makes limitations visible. That allows customers, integrators, certifiers, and operators to understand both what the CHERI implementation enforces and what the wider system must still provide.
