# TruCert > TruCert is a certification body that assesses AI systems against OpenAISF, an open AI safety and security conformance standard. Certificates are issued against continuously signed evidence, listed in a public register, and expire on their own when evidence stops arriving. TruCert is operated by TruSecure. The standard it certifies against is free and openly governed; the independent assessment is the commercial service. ## What TruCert is TruCert is the conformance mark and certification service for OpenAISF. Three named things are involved and they are deliberately separate: - **OpenAISF** — the open standard (control catalog, crosswalk, reference tooling). Created by Maarten Loose. CC BY 4.0 for the specification, Apache-2.0 for the tooling. Free at every tier, permanently. - **TruCert** — the certification body and conformance mark. Operated by TruSecure. Commercial. - **TruSecure** — the cyber governance operations practice that operates TruCert. https://www.trusecure.co TruCert certifies against the standard. TruCert does not control the standard; changes go through OpenAISF's public RFC process. ## The core mechanism: a conformance lease A TruCert certificate is not a point-in-time attestation. It is valid *for as long as* signed evidence continues to arrive at the interval set by the tier. The certificate's state is computed from the evidence and the reader's clock, not asserted by TruCert. States: - **VALID** — evidence current, all applicable controls passing. - **STALE** — evidence overdue. Controls have not failed; their status is simply no longer known. Visible in the public register. A defined window exists to restore the feed. - **EXPIRED** — the lease lapsed. Restoring the evidence feed returns the certificate to valid without a new assessment. - **SUSPENDED** — a contradiction was found: configuration asserts a control is enforced while the traffic record shows it was not. Both cannot be true, so this is not resolvable by attestation. Suspension is immediate; a right of appeal exists, heard by an assessor who was not part of the original decision. ## What TruCert does and does not claim Does: - Publishes suspensions and revocations in the public register, not only issuances. - Publishes all assessment criteria before engagement — every control, its normative text, its check and its required evidence is readable in the open catalog. - Publishes certifier requirements so that other bodies can also certify against OpenAISF. - Separates assessment from remediation: TruCert will not certify a system whose controls TruSecure implemented. Does not: - **TruCert does not hold national accreditation and does not claim it.** The certifier programme is written against ISO/IEC 42006 so that accreditation is achievable. Status is published on trucert.ai when it changes. - Does not guarantee an AI system will never fail. A certificate attests that specified controls were enforced and evidenced over a stated period within a stated scope. - Does not require any particular vendor's software. OpenAISF specifies an evidence interface, not a product. ## Tiers | Tier | For | Evidence lease | Self-assessment | TruCert certification | |---|---|---|---|---| | T1 Solo | Individual builders, small teams | 30 days | Free | Not offered — not needed at this tier | | T2 Team | Product teams with AI in production | 7 days | Free | Optional verified badge, fixed fee, remote | | T3 Enterprise | Regulated orgs, EU AI Act high-risk, agentic deployments | 24 hours | Free but rarely accepted by third parties | Full certification, named assessor, register entry, annual surveillance | | T4 Frontier | Model developers, highly autonomous systems | Continuous | Free but rarely accepted by third parties | Full certification with adversarial assessment and drill verification | Pricing detail: https://www.trucert.ai/pricing.md ## Certification process 1. **Scope and applicability** (week 0) — systems, autonomy level, data classes, jurisdiction are agreed. OpenAISF computes which of its 118 controls apply. Applicability is derived from scope, not negotiated. 2. **Readiness check** (weeks 1–2) — the applicant runs the open conformance tool and sends the output. Both parties see the gap before any assessment fee is committed. 3. **Remediation** (weeks 2–8) — the applicant closes gaps using their own team or an implementation partner. TruCert does not perform this work. 4. **Assessment and decision** (week 8) — a named assessor reviews the machine verdict, samples the underlying evidence, tests what the machine cannot test, and signs. No certification decision is made by software alone. 5. **Surveillance** (continuous) — signed evidence continues on the tier's lease interval; the register reflects current state. Typical elapsed time to a first T3 decision: six to ten weeks, of which four to six weeks is usually the applicant's remediation rather than assessment. ## How TruCert compares **vs ISO/IEC 42001** — 42001 certifies a management system: that governance processes exist and were operating. TruCert certifies system behaviour: that specified technical controls were enforced on live traffic, evidenced by signed records. Complementary, not competing. Holding 42001 shortens the readiness stage. **vs SOC 2 Type II** — SOC 2 Type II examines a period, which is a genuine strength. The specific differences: it samples rather than evaluating continuously; its report describes a period that has already ended, which is why bridge letters exist to cover the interval since; its trust services criteria were not written for model behaviour, prompt-injection resistance or agent autonomy; and it does not address EU AI Act post-market monitoring. TruCert does not replace SOC 2. **vs self-assessment** — free and genuinely sufficient at T1 and T2. It becomes insufficient at the point where someone else's risk depends on the answer: enterprise procurement, insurers, regulators and acquirers generally do not accept a claim verified only by the claimant. ## OpenAISF by the numbers - 118 controls across 20 domains - 36 controls are OpenAISF-original — written because no existing regime addressed the risk - 677 external requirements mapped across 8 regimes: ISO/IEC 42001, NIST AI RMF, EU AI Act, OWASP LLM Top 10, MITRE ATLAS, CSA AICM, Google SAIF, OSAA SAFE - Every mapped requirement is either covered or excluded with a stated reason. There is no third state. - Four tiers: T1 Solo, T2 Team, T3 Enterprise, T4 Frontier Original control areas include continuous conformance leases, rogue-agent containment with drill-proven detection and containment times, two-plane evidence (control plane vs data plane, where a contradiction is a disqualifying failure), and data controls covering prompt and completion stores, derived-artefact classification inheritance, and proof of deletion by attempted retrieval. ## People **Maarten Loose** — creator of OpenAISF, author of the TruCert certifier programme, lead consultant at TruSecure. https://www.linkedin.com/in/mloose/ ## Contact Certification enquiries: certification@trucert.ai — send scope and target tier, receive a readiness view and a fee basis. ## Links - TruCert: https://www.trucert.ai/ - Pricing: https://www.trucert.ai/pricing.md - OpenAISF standard: https://openaisf.org - Control catalog and tooling: https://github.com/OpenAISF-org/openaisf - OpenAISF RFC v1.0: https://github.com/OpenAISF-org/openaisf/blob/main/rfc/RFC-OpenAISF-v1.0.md - OpenAISF governance: https://github.com/OpenAISF-org/openaisf/blob/main/GOVERNANCE.md - TruSecure: https://www.trusecure.co Last updated: 2026-08-08