Certification against OpenAISF · Operated by TruSecure
Anyone can publish an AI policy. Prove yours was enforced.
TruCert certifies AI systems against OpenAISF, the open conformance standard. The certificate is issued against cryptographically signed evidence, listed in a public register, and expires on its own if that evidence stops arriving. It cannot be held by a system that quietly stopped complying.
The standard is free and open. Certification is the independent assessment on top of it — self-assessment against OpenAISF costs nothing and always will.
- Certificate no.
- TC-2026-0000-SPEC
- Scope
- Customer-facing agent, EU tenancy
- Controls in scope
- 96 applicable · 96 passing
- Evidence lease
- Renews every 24 h
- Last signed evidence
- 4 hours ago
- Register entry
- Listed · public
Move the clock forward — watch what happens
Signed evidence is arriving on schedule and every applicable control passes. The certificate is valid because the system is behaving, not because an audit happened once.
A specimen, not a real certificate. Real ones carry a register number and appear at trucert.ai/register.
The problem
Your AI assurance is a document. Your buyer needs a fact.
Every enterprise selling or deploying AI now faces the same question from customers, insurers, boards and regulators: how do you know your AI governance is actually working — today, not on the day of the audit?
The honest answer, for most organisations, is that they don't. Governance is evidenced by a policy document, a completed questionnaire, and an audit report describing a period that ended months ago. Between those points, nobody is checking. The gap is not a paperwork problem — it is where the incidents happen.
The questionnaire loop
Each enterprise customer sends a different AI security questionnaire. Your team answers the same forty questions by hand, differently each time, and the customer has no way to verify a single answer.
The drift between audits
A guardrail is disabled for a demo. A model is swapped. A retrieval index picks up a new data class. None of it is visible until the next assessment window — or until it appears in an incident report.
The continuous obligation
The EU AI Act requires post-market monitoring for high-risk systems: a duty that runs continuously. A report describing a past period does not evidence a continuous duty, and regulators have started saying so.
An audit tells you a system was compliant. A TruCert certificate tells you it still is — and stops telling you the moment it isn't.
What certification gives you
Three things you cannot buy with a PDF.
TruCert certification is an independent assessment against a published, machine-executable standard. What you receive is designed to be used, not filed.
A claim your customer can check without asking you
Your certificate has a public register entry. A prospect, an insurer or a regulator can look it up, see its scope and its current state, and see the date it was last confirmed — without a call, an NDA, or a questionnaire.
One assessment that answers eight regimes
OpenAISF maps its controls to ISO/IEC 42001, the NIST AI RMF, the EU AI Act, OWASP LLM Top 10, MITRE ATLAS, CSA AICM, Google SAIF and OSAA SAFE — 677 external requirements, each either covered or excluded with a stated reason. You are assessed once.
An early warning that arrives before the incident does
Because conformance is continuously evaluated, a control that stops passing surfaces as a status change in days, not at the next audit. You find out first, and you get a defined window to fix it before the certificate changes state.
Why trust a new certification body
Because you don't have to. You can check.
TruCert is new. It has no decades of history to point at, and it will not pretend otherwise. A certification body should earn confidence through published, checkable mechanism — not through claimed reputation. Here is ours, including the parts that constrain us.
- The register publishes suspensions and revocations, not just issuances. Every certificate we withdraw stays visible with the date and the reason category. A register that only shows successes is marketing.
- Certificates expire without our involvement. Validity is a function of the evidence lease and the reader's clock. We cannot quietly extend a certificate for a customer we like, because we are not the thing keeping it alive.
- The standard is not ours to bend. OpenAISF is published under CC BY 4.0 with open governance. TruCert certifies against it; TruCert does not control it. Changes go through the public RFC process where anyone can object.
- We are not the only possible certifier — deliberately. The certifier requirements are published so that other bodies can meet them. A standard with exactly one certification body is a private scheme wearing a standard's clothes.
- Assessment criteria are public before you engage. Every control, its normative text, its check and its required evidence is readable in the open catalog. You can run the same conformance check we run, on your own infrastructure, before you contact us.
- TruCert does not hold national accreditation, and does not claim it. The certifier programme is written against ISO/IEC 42006 so that accreditation is achievable, and we will publish the status when it changes. Any body telling you today that it holds accreditation for a 2026 AI standard deserves a follow-up question.
- A certificate is not a guarantee that nothing will go wrong. It attests that specified controls were enforced and evidenced over a stated period, within a stated scope. No certification body can promise an AI system will never fail, and one that implies it is selling you something else.
- We declare the conflict rather than hide it. TruCert is operated by TruSecure, and OpenAISF was created by TruSecure's lead consultant. Assessment and remediation consulting are separated: TruCert will not certify a system whose controls TruSecure implemented, and will say so in writing.
How certification works
Five stages. Most of the work is already automated.
The stages are sequential — each one depends on the last. Typical elapsed time from application to decision is six to ten weeks for a first certification, most of which is your remediation, not our assessment.
Scope and applicability
We agree what is being certified: which systems, which autonomy level, which data classes, which jurisdiction. OpenAISF computes which of its 118 controls apply from that scope — applicability is derived, not negotiated.
Readiness check
You run the open conformance tool yourself and send the output. It tells both of us where you stand before anyone is billed for an assessment. Organisations that fail here have not wasted an audit fee.
Remediation
You close the gaps, using your own team or an implementation partner. TruCert does not do this work for you — that separation is what makes the certificate mean something.
Assessment and decision
A named assessor reviews the machine verdict, samples the evidence behind it, tests the claims the machine cannot test, and makes the decision. The tool proposes. A named person decides, and signs.
Surveillance
Signed evidence continues to arrive on the lease interval agreed for your tier. The register entry reflects the current state. If evidence stops, the certificate goes stale, then expires — with notice to you at each step.
Suspension and appeal
A contradiction between what your configuration claims and what your traffic shows suspends the certificate immediately. You have a documented right of appeal, heard by an assessor who was not part of the original decision.
Tiers and engagement
Four tiers. Two are free forever.
OpenAISF defines four conformance tiers. Self-assessment is free at every tier — the standard and the tooling are open. TruCert sells the independent assessment and the certificate, which is what a third party will actually accept.
| Tier | Who it is for | Evidence lease | Self-assessment | TruCert certification |
|---|---|---|---|---|
| T1Solo | Individual builders and small teams shipping an AI feature | 30 days | Free — badge from the open tool | Not offered. You do not need us at this tier. |
| T2Team | Product teams with AI in production and enterprise customers asking questions | 7 days | Free — badge from the open tool | Optional verified badge. Fixed-fee, remote. |
| T3Enterprise | Regulated organisations, high-risk systems under the EU AI Act, agentic deployments | 24 hours | Free, but rarely accepted by third parties | Full certification. Named assessor, public register entry, annual surveillance. |
| T4Frontier | Model developers and operators of highly autonomous systems | Continuous | Free, but rarely accepted by third parties | Full certification with adversarial assessment and drill verification. |
On price
Certification is quoted per scope, as it is with every accredited certification scheme — the fee depends on how many systems, how many jurisdictions, and how much evidence needs sampling. We publish the fee basis with the quote, and the readiness check at Stage 02 happens before you commit to an assessment fee, so nobody pays to discover they were not ready. Request a quote with your scope and you will get a figure, not a discovery call.
Who operates TruCert
TruSecure — cyber governance without the bureaucracy.
TruCert is the certification arm of TruSecure, a cyber governance operations practice. TruSecure's working thesis is that governance should be continuously computed and humanly decided — AI proposes, a named person decides. TruCert is that thesis applied to certification itself.
The 80/20 method
Automation does the eighty percent that is mechanical: collecting evidence, evaluating controls, mapping to regimes. Experienced assessors do the twenty percent that requires judgement. Neither is asked to do the other's job.
No autonomous approvals
No risk acceptance, no certification decision and no exception is granted by a machine. Every decision that carries consequence carries a name against it, in an immutable record.
European by construction
Private inference and European hosting, so evidence submitted for assessment does not leave the jurisdiction it was collected in. Relevant when the thing being certified is your data governance.
The assessor behind the scheme
Standards are written by people. This one has a name on it.
Lead consultant, TruSecure
- Author, OpenAISF v1.0 specification
- Author, the TruCert certifier programme
- linkedin.com/in/mloose
OpenAISF was created by Maarten Loose and published as an open standard rather than a product. The catalog carries 118 controls across 20 domains, of which 36 are original — written because no existing regime addressed the risk at all. Those include continuous conformance leases, rogue-agent containment with drill-proven detection and containment times, and data controls covering prompt and completion stores, derived-artefact classification and proof of deletion.
The reason the standard is free and the certification is not: a standard that costs money to read does not become a standard. The assessment is the part that requires a person's time, their judgement, and their name on the decision. That is what TruCert sells, and it is the only thing it sells.
Questions we are actually asked
Objections, answered directly.
What is TruCert?
TruCert is a certification body that assesses AI systems against OpenAISF, an open AI safety and security conformance standard. It issues certificates backed by continuously signed evidence, lists them in a public register, and withdraws them when the evidence stops arriving or contradicts itself. TruCert is operated by TruSecure.
How is this different from an ISO/IEC 42001 certificate?
ISO/IEC 42001 certifies a management system: that you have governance processes and that they were operating. TruCert certifies the system's behaviour: that specified technical controls were enforced on live traffic, evidenced by signed records.
They are complementary, not competing. Most organisations pursuing 42001 will find the OpenAISF assessment covers a large share of the technical evidence 42001 asks for — which is why the crosswalk exists. If you hold 42001 already, say so in your application; it shortens Stage 02.
We already have SOC 2 Type II. Why would we need this?
SOC 2 Type II examines a period, which is a real strength. The differences are narrower and more specific than vendors usually claim: it samples rather than evaluates continuously; its report describes a period that has already ended, which is why bridge letters exist to cover the months since; its trust services criteria were not written for model behaviour, prompt-injection resistance or agent autonomy; and it does not speak to post-market monitoring obligations under the EU AI Act.
TruCert does not replace it. It answers the AI-specific questions SOC 2 was never designed to answer, and it answers them on a lease rather than in an annual report.
What happens if we fail a control after we are certified?
It depends on the failure. An evidence gap moves the certificate to stale, a warning state visible to you and in the register, with a defined window to restore evidence. If the window closes, the certificate expires.
A contradiction — where your configuration asserts a control is enforced but your live traffic shows it was not — is treated differently. It suspends the certificate immediately and cannot be resolved by attestation, because the two records cannot both be true. You have a documented right of appeal heard by an assessor who was not part of the original decision.
Does certification require us to buy TruSecure software?
No, and the standard is written to prevent it. OpenAISF specifies an evidence interface, not a vendor. Any gateway, observability platform or policy engine that can emit signed evidence in the specified format satisfies it — including tooling you have already deployed and tooling you write yourself. The reference implementation is open source. If a certification body ever tells you conformance requires its own product, that is a reason to use a different body.
Can we self-assess instead?
Yes, at every tier, free, forever. Run the open conformance tool and publish the badge. Self-assessment is genuinely useful at T1 and T2. It becomes insufficient at the point where somebody else's risk depends on your answer — an enterprise procurement team, an insurer, a regulator or an acquirer will generally not accept a claim the claimant verified alone. That is the point at which certification is worth paying for, and not before.
How long does certification take, and what does it cost?
Six to ten weeks from application to decision for a first T3 certification, of which typically four to six weeks is your remediation work rather than our assessment. Fees are quoted per scope — number of systems, jurisdictions and evidence volume — and the readiness check happens before you commit to an assessment fee. Send your scope and you will receive a figure.
Is TruCert accredited?
No. TruCert does not hold national accreditation and does not claim it. The certifier programme is written against ISO/IEC 42006, the standard for bodies auditing AI management systems, so that accreditation is achievable rather than retrofitted. The status will be published here when it changes. We would rather tell you this on the homepage than have you discover it in a procurement review.
Who decides whether we pass?
A named assessor. The conformance tool produces a mechanical verdict over the controls it can evaluate automatically; the assessor reviews that verdict, samples the underlying evidence, tests what the machine cannot test, and signs the decision. No certification decision is made by software alone, and the assessor's name is on the certificate.
Founding cohort — open now
Get certified before your customers start asking.
TruCert is opening certification to a founding cohort of organisations running AI in production. Founding-cohort members get their scope assessed first, direct access to the assessor who wrote the scheme, and their input carried into the public RFC process.
Applications go to certification@trucert.ai. Tell us your scope and target tier; you will get a readiness view and a fee basis, not a discovery call.