Concept overview — working architecture
Verified independently
Open to everyone
Compliance by construction.
Baseline is an open methodology and reference tooling for building software that is compliant with security standards — from the moment it's architected, not assessed after the fact. One control, mapped once against every applicable standard, generates its own audit-ready artifact as a byproduct of the build itself.
Concept, spec, and reference tooling — documented in the open.
- NIST 800-53Federal baseline
- NIST 800-171CMMC
- ISO 27001Certification
- SOC 2Attestation
- FedRAMPAuthorization
- HIPAASafeguards
The problem, and the shift
The problem
Every framework re-evidences the same controls.
Small organizations pay to translate a system they already built into an assessor's language, over and over — once per standard. It is cost that scales with system complexity, not with actual risk.
The shift
Resolve the control set at design time.
Derive the applicable controls from a system's own characteristics, then build to them directly. The resulting evidence — code, config, policy, test — is generated once and is valid across every standard it maps to.
Six parts, clearly separated
The methodology, the tooling, the commercial service, and the trust record are deliberately distinct things — so that using Baseline never requires buying Baseline.
Baseline Foundation
Nonprofit, neutral steward. Owns the spec, the control crosswalk, and the open-source reference tooling. Accepts donations; no fiscal requirement to use the methodology.
Nonprofit stewardBaseline Protocol
The published, open methodology — how a system's applicable controls are resolved, what qualifies as a valid artifact, and how generated policy routes to the accountable role for approval.
Open specBaseline Core
Free, open-source reference implementation of the Protocol — the crosswalk resolver, artifact generator, and policy workflow engine. Transparent by design; runnable by anyone.
Open sourceBaseline Cloud
Commercial hosted service. Executes and reports validation from infrastructure the assessed company doesn't control — the structural basis for an independence claim. Funds the Foundation.
CommercialBaseline Registry
Public, checkable record of verification status — the reference point insurers, agencies, and buyers look up instead of running their own process.
Public recordBaseline Partner Network
Independent 3PAOs and licensed assessors, signing off on the specific subset of controls that legally still require a human opinion — narrowed over time, not eliminated by decree.
Human assessorsTwo levels of verification
The entry tier is accessible to any organization regardless of budget. The higher-assurance tier exists for regulated and higher-criticality systems — and says so plainly.
Tier one
Baseline Verified
— Attested
Built and validated with Baseline Core, self-run and self-reported. Transparent and low-cost — the accessible entry point for any organization, regardless of budget.
- Self-run with open-source Core
- Artifacts public and checkable
- No cost barrier to entry
Tier two
Baseline Verified
— Certified
Executed and reported through Baseline Cloud, with Partner Network sign-off wherever a standard legally requires an independent human assessor.
- Validation run outside your control
- Licensed assessor sign-off
- For regulated, higher-criticality systems
Working principle
Independence is a property of who controls execution and reporting — not of a tool's license.
Concept to a running pipeline
The same shape applies whether this is one app or an ecosystem of them: source the control set once, check for it automatically, and never let the system grading the build be the system that built it.
Start from an existing control catalog
Pull NIST's OSCAL catalogs (800-53 rev5, 800-171) and the Secure Controls Framework crosswalk as-is. Don't invent a new taxonomy — the goal is interoperability with what auditors and agencies already expect, not a private standard.
Define one check per atomically verifiable control
Each check is a small script tagged with the control IDs it evidences. Split checks into deterministic (static analysis, config linting, dependency scanning) and judgment-based (a narrowly scoped question answered with cited evidence) — keep the two visibly distinct in the registry.
Run the validator as its own process
Execute checks against the finished repo from outside the build — a separate script invocation or CI job, never a follow-up question inside the session that wrote the code. This is what keeps the resulting artifact meaningful rather than self-graded.
Aggregate to control, then to standard
Roll individual check results up to a status per control, then roll controls up per mapped standard in the same pass — one run produces simultaneous status across every framework a control touches.
Render the audit-ready artifact
Produce structured JSON (the OSCAL-ready record) and a human-readable report, citing the exact file and line behind every control's status. This is the artifact that stands in for the manual translation work an assessor would otherwise bill for.
Close gaps, then re-run — don't re-audit
Treat each fail or partial as a scoped fix tied to a specific control and a specific piece of evidence. Re-running after a fix updates the same trail in place, in minutes, instead of restarting a new assessment cycle.
Scale, then layer on trust infrastructure
Extend the catalog and check registry as more applications join. Once the Attested tier has a real track record, layer on Baseline Cloud, the Registry, and Partner Network sign-off for the subset of controls that still legally require an independent human opinion.
Open methodology
Build it compliant. Prove it once.
The protocol, the crosswalk, and the reference implementation are documented in the open. If you build software that has to answer to a standard — or you assess software that does — the approach is there to read and to run.
Protocol, crosswalk, and reference implementation — documented in the open.