Requirements
The registry of requirements classes
Signatif specifies requirements as addressed classes — /req identifiers with matching /conf conformance classes — so that “conforming implementation” is a testable claim, not an adjective.
- Requirements classes
- Requirements
- Conformance classes
- Conformance tests
| Clause | Requirements class | Identifier | Req. | Conformance class | Tests |
|---|---|---|---|---|---|
| 6 | Architecture and trust model | /req/architecture | 11 | /conf/architecture | 11 |
| 6 | Artifact format and signature binding | /req/artifact-format | 19 | /conf/artifact-format | 19 |
| 6 | Cryptographic algorithms | /req/algorithms | 7 | /conf/algorithms | 7 |
| 6 | Threshold signing and federated trust authorities | /req/threshold-signing | 12 | /conf/threshold-signing | 12 |
| 6 | Trust chain and authorization scope governance | /req/scope | 8 | /conf/scope | 8 |
| 6 | Revocation and artifact binding | /req/revocation | 7 | /conf/revocation | 7 |
| 6 | Transparency and multi-log attestation | /req/transparency | 9 | /conf/transparency | 8 |
| 6 | Verification pipeline | /req/verification | 8 | /conf/verification | 8 |
| 6 | Key lifecycle | /req/key-lifecycle | 6 | /conf/key-lifecycle | 6 |
| 6 | Delivery and discovery | /req/delivery | 6 | /conf/delivery | 6 |
| 6 | Ceremony records | /req/ceremony | 5 | /conf/ceremony | 5 |
| 6 | Deployment manifest | /req/manifest | 7 | /conf/manifest | 7 |
| 6 | Governance and mutual recognition | /req/governance | 5 | /conf/governance | 5 |
| 6 | Algorithm agility | /req/algorithm-agility | 4 | /conf/algorithm-agility | 4 |
| Totals | 113 | 113 |
How to read the registry
Requirements classes
Each /req class groups requirements on one subject, identified by stable identifiers such as/req/verification/coverage-report. Requirements are stated as testable characteristics — never as products or vendor names.
Conformance classes
Each class pairs with a /conf class of abstract tests, one per requirement, plus implementation roles — basic and full verifiers, issuing and root authorities, transparency operators, mirrors, and device signers — so an implementation claims exactly what it implements.
Machine-readable source
The registry is generated from YAML requirement sources in the standard’s repository, rendered into the document and the abstract test suite — one source of truth for document, tests, and tooling.
YAML sources on GitHubHow a scheme claims these classes:building a scheme.