Procurement
Procurement can ask for measurable memory-safety and containment outcomes while requiring suppliers to show exactly what their CHERI claims cover.
An effective requirement describes the risk to reduce and the evidence a supplier must provide. Requiring a product to be “CHERI-based” without defining scope can turn a useful architecture into an unverifiable checkbox.
Specify outcomes and scope
Ask bidders to identify:
- the processor, CHERI architecture profile, and execution mode;
- which firmware, operating-system, application, and third-party components use capabilities;
- which components are isolated and what authority each receives;
- how spatial and temporal memory safety are addressed;
- any memory access that bypasses normal capability checks, including debug and device paths;
- supported toolchains, updates, vulnerability handling, and product lifetime;
- known limitations and residual risks.
Where CHERI Enabled status is required or rewarded, name the certified product and version and verify it against the current CHERI Enabled product directory. Do not treat a component certificate as certification of the integrated product.
Ask for evidence
The evidence can be organised around five questions:
- Does the implementation match its specification? Relevant evidence can include compliance tests, design verification, and a certification record.
- How much software is protected? Ask for a build manifest, the execution mode, an inventory of unsafe code, and port test results.
- Do the compartment boundaries hold? An authority map, interface definitions, tests for denied access, and fault-injection results can support this claim.
- How will the product be supported? Look for a security policy, update commitment, diagnostic information, and an end-of-life plan.
- Can the supply chain be traced? A dependency inventory, version history, disclosure process, and change controls help answer this.
Make evidence proportionate to risk. A safety controller and a development board need different levels of independent review.
Preserve interoperability and competition
Where the outcome can be met in more than one way, allow equivalent evidence. Memory-safe languages, process isolation, CHERI, and other hardware protections can be complementary. State when a specific CHERI profile is essential for binary compatibility or integration, and when the requirement is instead for a security property.
Evaluate lifecycle cost
Compare purchase price together with integration, porting, assurance, support, updates, training, and exit costs. Ask suppliers to identify separate code branches, mainline contribution status, licensing, platform availability, and who maintains the toolchain.
Procurement and legal teams should adapt requirements to the applicable jurisdiction, sector, and contract. This page is technical guidance, not model legal wording.
