—Baseline thebaselinefoundation.org Verification tiers

Concept overview — working architecture

Compliance by construction
Verified independently
Open to everyone

Compliance by construction.

Baseline is an open methodology and reference tooling for building software that is compliant with security standards — from the moment it's architected, not assessed after the fact. One control, mapped once against every applicable standard, generates its own audit-ready artifact as a byproduct of the build itself.

Concept, spec, and reference tooling — documented in the open.

Map once — satisfy many One control set, resolved once, evidenced across every standard it touches.
  • NIST 800-53Federal baseline
  • NIST 800-171CMMC
  • ISO 27001Certification
  • SOC 2Attestation
  • FedRAMPAuthorization
  • HIPAASafeguards

The problem, and the shift

01 — Why Baseline exists

The problem

Every framework re-evidences the same controls.

Small organizations pay to translate a system they already built into an assessor's language, over and over — once per standard. It is cost that scales with system complexity, not with actual risk.

$50k–$100k per standard, spent on translation rather than security

The shift

Resolve the control set at design time.

Derive the applicable controls from a system's own characteristics, then build to them directly. The resulting evidence — code, config, policy, test — is generated once and is valid across every standard it maps to.

Built on OSCAL and the Secure Controls Framework as the control ontology — not a reinvented one.

Six parts, clearly separated

02 — Working architecture

The methodology, the tooling, the commercial service, and the trust record are deliberately distinct things — so that using Baseline never requires buying Baseline.

01

Baseline Foundation

Nonprofit, neutral steward. Owns the spec, the control crosswalk, and the open-source reference tooling. Accepts donations; no fiscal requirement to use the methodology.

Nonprofit steward
02

Baseline Protocol

The published, open methodology — how a system's applicable controls are resolved, what qualifies as a valid artifact, and how generated policy routes to the accountable role for approval.

Open spec
03

Baseline Core

Free, open-source reference implementation of the Protocol — the crosswalk resolver, artifact generator, and policy workflow engine. Transparent by design; runnable by anyone.

Open source
04

Baseline Cloud

Commercial hosted service. Executes and reports validation from infrastructure the assessed company doesn't control — the structural basis for an independence claim. Funds the Foundation.

Commercial
05

Baseline Registry

Public, checkable record of verification status — the reference point insurers, agencies, and buyers look up instead of running their own process.

Public record
06

Baseline Partner Network

Independent 3PAOs and licensed assessors, signing off on the specific subset of controls that legally still require a human opinion — narrowed over time, not eliminated by decree.

Human assessors

Two levels of verification

03 — What a Baseline mark means

The entry tier is accessible to any organization regardless of budget. The higher-assurance tier exists for regulated and higher-criticality systems — and says so plainly.

Tier one

Baseline Verified

— Attested

B

Built and validated with Baseline Core, self-run and self-reported. Transparent and low-cost — the accessible entry point for any organization, regardless of budget.

  • Self-run with open-source Core
  • Artifacts public and checkable
  • No cost barrier to entry

Tier two

Baseline Verified

— Certified

B

Executed and reported through Baseline Cloud, with Partner Network sign-off wherever a standard legally requires an independent human assessor.

  • Validation run outside your control
  • Licensed assessor sign-off
  • For regulated, higher-criticality systems

Working principle

Independence is a property of who controls execution and reporting — not of a tool's license.
Narrow what needs a human Prove the automated majority is reliable Never claim to eliminate independent judgment

Concept to a running pipeline

04 — Implementation

The same shape applies whether this is one app or an ecosystem of them: source the control set once, check for it automatically, and never let the system grading the build be the system that built it.

01

Start from an existing control catalog

Pull NIST's OSCAL catalogs (800-53 rev5, 800-171) and the Secure Controls Framework crosswalk as-is. Don't invent a new taxonomy — the goal is interoperability with what auditors and agencies already expect, not a private standard.

02

Define one check per atomically verifiable control

Each check is a small script tagged with the control IDs it evidences. Split checks into deterministic (static analysis, config linting, dependency scanning) and judgment-based (a narrowly scoped question answered with cited evidence) — keep the two visibly distinct in the registry.

03

Run the validator as its own process

Execute checks against the finished repo from outside the build — a separate script invocation or CI job, never a follow-up question inside the session that wrote the code. This is what keeps the resulting artifact meaningful rather than self-graded.

04

Aggregate to control, then to standard

Roll individual check results up to a status per control, then roll controls up per mapped standard in the same pass — one run produces simultaneous status across every framework a control touches.

05

Render the audit-ready artifact

Produce structured JSON (the OSCAL-ready record) and a human-readable report, citing the exact file and line behind every control's status. This is the artifact that stands in for the manual translation work an assessor would otherwise bill for.

06

Close gaps, then re-run — don't re-audit

Treat each fail or partial as a scoped fix tied to a specific control and a specific piece of evidence. Re-running after a fix updates the same trail in place, in minutes, instead of restarting a new assessment cycle.

07

Scale, then layer on trust infrastructure

Extend the catalog and check registry as more applications join. Once the Attested tier has a real track record, layer on Baseline Cloud, the Registry, and Partner Network sign-off for the subset of controls that still legally require an independent human opinion.

Open methodology

Build it compliant. Prove it once.

The protocol, the crosswalk, and the reference implementation are documented in the open. If you build software that has to answer to a standard — or you assess software that does — the approach is there to read and to run.

thebaselinefoundation.org

Protocol, crosswalk, and reference implementation — documented in the open.