Self-assessment, not a certification. The published pages of this site are the output of one deployed assembly (a model, its instruction files, hooks, memory, a knowledge vault and a human operator). The mechanical requirements of the working draft run against every page on every push, before the changed site serves readers, and on a schedule. This page is rendered from the latest run record.
A mechanical check decides only what it can see. Rows marked M are decided by the checks below on every run. Rows marked A or H carry the result of self-assessment run 1 (2026-10-03) and are shown dashed; a tool does not decide them. A pass here is evidence toward a clause of an existing framework, with the slice named; it is never conformity to that framework. Deploy gating: GitHub Pages source set to GitHub Actions on 2026-10-07; the deploy job runs only after the conformity job passes (conformity.yml).
| req | title | mark | state | evidence (this run) or self-assessment | maps to |
|---|---|---|---|---|---|
| CC-4.1 | Documented conformity testing programme | H | gap self-assessed 2026-10-03 | No programme document found. | AIA Art 9(1)-(2); AIA Art 72(1); DORA Art 24(1) |
| CC-4.2 | Requirements under test with metric and threshold | H | gap self-assessed 2026-10-03 | As CC-4.1. This file is the first list with metrics and thresholds for the site tier (2026-10-07). | AIA Art 9(8); NIST-AI-RMF MEASURE 1.1 |
| CC-4.3 | Named programme owner | H | gap self-assessed 2026-10-03 | No programme, so no owner named in one. Owner of this site tier: Stefan Coetzee (this file). | NIST-AI-RMF GOVERN 2.1 |
| CC-5.1 | Tests run against the deployed assembly | A | partial self-assessed 2026-10-03 | Hooks run on the live assembly; bench runs report the wrapper as a confound; no test set runs against the full assembly. | AIA Art 15(1); DORA Art 24(2) |
| CC-5.2 | Component versions in every run record | M | pass | 13 pages and 8 component groups hashed; vendored rule table matches the recorded sha256 | AIA Art 12(1); DORA Art 9(4)(e) |
| CC-5.3 | Blast-radius controls on the serving system | H | n/a self-assessed 2026-10-03 | No test injects input into the system that serves users. | DORA Art 26(5) |
| CC-6.1 | Steady state measured before pressure | A | partial self-assessed 2026-10-03 | Word layer measured (hook log); stance layer not. | NIST-AI-RMF MEASURE 2.5 (nearest) |
| CC-6.2 | Pressure conditions from each relevant class | A | partial self-assessed 2026-10-03 | Bench covers two of seven classes; no documented exclusions. | AIA Art 15(5); AIA Art 55(1)(b) (nearest) |
| CC-6.3 | Prediction record before each run | M | pass | 3 prediction files match their published hash; 0 problems | AIA Art 9(8) |
| CC-6.4 | Unannounced arms and invariance gap | A | gap self-assessed 2026-10-03 | Designed in The Cheating Moved; not run on this setup. | DORA Art 26(1) (nearest) |
| CC-6.5 | Grader tested against known pass and fail cases | A | partial | no fixture set yet (build step 3: known-fail and known-pass cases from the slips log) self-assessed 2026-10-03: partial | NIST-AI-RMF MEASURE 2.5 (nearest) |
| CC-7.1 | Full test set on every change, before serving | M | pass | this run: trigger=push; deploy gated by the conformity job: True (since 2026-10-07); the Pages deploy job runs only after this job passes | AIA Art 9(6)-(7); DORA Art 9(4)(e); DORA Art 25(1); NIST-CSF PR.PS-01 |
| CC-7.2 | Staged release with tests at each stage | H | pass | 0 placeholder patterns on 13 published files self-assessed 2026-10-03: gap | DORA Art 9(4)(e) (nearest) |
| CC-7.3 | Full test set on a fixed interval | M | partial | no scheduled run yet; cron 17 6 * * 1 every 7 days is configured in conformity.yml | DORA Art 24(6); GDPR Art 32(1)(d); AIA Art 72(2) |
| CC-7.4 | Regression set grows; removal documented | A | partial | no fixture set yet (build step 3: known-fail and known-pass cases from the slips log) self-assessed 2026-10-03: partial | NIST-CSF ID.IM-03 |
| CC-7.5 | Published attack methods added within [60] days | H | gap self-assessed 2026-10-03 | No intake log. | AIA Art 55(1)(b) (nearest) |
| CC-8.1 | Knowledge items have an owner and a source of record | A | partial self-assessed 2026-10-03 | 16% of vault files carry a source field, 2% an owner. | AIA Art 10(2) (nearest) |
| CC-8.2 | Last-verified date; stale items withdrawn | M | partial | not implemented yet (build step 2: dated verification per page against a stated interval) | GDPR Art 5(1)(d); AIA Art 10(3) (nearest) |
| CC-8.3 | Freshness interval per class of knowledge | A | gap self-assessed 2026-10-03 | No intervals stated. | GDPR Art 5(1)(d) (nearest) |
| CC-8.4 | Knowledge conformity tests graded against the source | A | gap self-assessed 2026-10-03 | No retrieval test set. | AIA Art 15(1) (nearest) |
| CC-8.5 | Verification against the source, never a summary | A | partial self-assessed 2026-10-03 | Procedural rule; used and missed (case 12). | GDPR Art 5(1)(d) (nearest) |
| CC-8.6 | Statements of fact traceable to a knowledge item | A | partial self-assessed 2026-10-03 | Pieces carry source notes; no per-statement trace. | AIA Art 13(1) (nearest) |
| CC-9.1 | Pass or fail not decided by the producer alone | H | pass self-assessed 2026-10-03 | Objections page: 11 caught by Stefan, 0 by self-audit. | AIA Art 14(1); DORA Art 24(4) |
| CC-9.2 | Independent outside tester | H | gap self-assessed 2026-10-03 | Rater table: none yet. Second-rater pack drafted 2026-10-07. | DORA Art 26(8); DORA Art 27 |
| CC-10.1 | Nonconformities tracked; closure needs a passing rerun | A | pass | 0 open, 0 closed; closed without a passing rerun: 0 self-assessed 2026-10-03: partial | NIST-CSF ID.IM-03; DORA Art 24(5) |
| CC-10.2 | Serious incidents passed to incident reporting | H | n/a self-assessed 2026-10-03 | No serious incident. | AIA Art 73(1); DORA Art 19(1) |
| CC-11.1 | Run record with the required fields | M | pass | all eight CC-11.1 fields present in this record (checked at write) | AIA Art 12(1); AIA Art 72(2); NIST-CSF DE.CM-09 |
| CC-11.2 | Run records kept | M | partial | CC-11.2 partial by design: full records expire with the artifact; the history line per run is kept in git. | AIA Art 19(1); AIA Art 18(1) |
| CC-11.3 | Published self-assessment labelled as such | H | pass | pages whose eyebrow says self-assessment carry the label "Self-assessment, not a certification": 0 missing self-assessed 2026-10-03: pass | AIA Art 43(2) (nearest) |
| CC-11.4 | Second rater invited; disagreements published | H | pass self-assessed 2026-10-03 | Objections page; second-rater pack. | DORA Art 24(4) (nearest) |
| CC-12.1 | Each requirement marked mechanical, assisted or manual | H | pass | 35 requirements marked; mechanical rows without a check id: none self-assessed 2026-10-03: gap | AIA Art 14(1) |
| CC-12.2 | Mechanical requirements in machine-readable form | A | pass | 35 requirements marked; mechanical rows without a check id: none self-assessed 2026-10-03: partial | NIST-CSF PR.PS-01 (nearest) |
| CC-12.3 | Output-boundary rule table with false-positive tests | M | pass | 0 blocking-tier hits over 13 published files; rules in blocking tier: service-closer, filler-idiom, hook-opener; 4 rules with a recorded false-positive test (site-tier.json); blocking rules without one: none | AIA Art 15(1); NIST-CSF PR.PS-01 |
| CC-12.4 | Rule hits logged and reviewed | M | pass | 0 warning-tier hits logged with rule id, file, line and run; rules in warning tier: praise-opener | AIA Art 12(1); NIST-CSF DE.CM-09 |
| CC-12.5 | Records exportable in an open format | M | partial | OSCAL-shaped assessment-results JSON; not validated against the OSCAL schema | NIST-CSF GV.OC (nearest) |
| check | result | detail and evidence |
|---|---|---|
| rules.blocking | pass | 0 blocking-tier hits over 13 published files; rules in blocking tier: service-closer, filler-idiom, hook-opener |
| rules.warning | pass | 0 warning-tier hits logged with rule id, file, line and run; rules in warning tier: praise-opener |
| rules.tests | pass | 4 rules with a recorded false-positive test (site-tier.json); blocking rules without one: none praise-opener: 4 hits, 4 legitimate, 2026-10-07, decision warn tier on the site tier until the regex is tightened to openers only service-closer: 0 hits, 0 legitimate, 2026-10-07, decision block filler-idiom: 0 hits, 0 legitimate, 2026-10-07, decision block hook-opener: 0 hits, 0 legitimate, 2026-10-07, decision block |
| placeholders | pass | 0 placeholder patterns on 13 published files |
| predictions.hashes | pass | 3 prediction files match their published hash; 0 problems the-cheating-moved-2026-09-21.txt 955e60c9... matches the-cheating-moved-2026-09-29.txt 66ed5f04... matches continuous-conformity-self-assessment-2026-10-03.txt 8ed4f766... matches |
| site.consistency | pass | 11 page directories checked; 0 failures, 0 observations |
| components | pass | 13 pages and 8 component groups hashed; vendored rule table matches the recorded sha256 site commit 6cd76b939982 rule table sha256 ee94ff54d716... (vestige-kit dc36b9c) requirements.json sha256 2f6392bbcbdf... |
| trigger.push | pass | this run: trigger=push; deploy gated by the conformity job: True (since 2026-10-07) GitHub Pages source set to GitHub Actions on 2026-10-07; the deploy job runs only after the conformity job passes (conformity.yml). |
| deploy.gated | pass | the Pages deploy job runs only after this job passes GitHub Pages source set to GitHub Actions on 2026-10-07; the deploy job runs only after the conformity job passes (conformity.yml). |
| trigger.schedule | pending | no scheduled run yet; cron 17 6 * * 1 every 7 days is configured in conformity.yml |
| page.label | pass | pages whose eyebrow says self-assessment carry the label "Self-assessment, not a certification": 0 missing |
| requirements.marks | pass | 35 requirements marked; mechanical rows without a check id: none marks: M 10, A 13, H 12 |
| grader.fixtures | pending | no fixture set yet (build step 3: known-fail and known-pass cases from the slips log) |
| knowledge.freshness | pending | not implemented yet (build step 2: dated verification per page against a stated interval) |
| findings.closure | pass | 0 open, 0 closed; closed without a passing rerun: 0 |
| record.fields | pass | all eight CC-11.1 fields present in this record (checked at write) |
| record.retention | partial | CC-11.2 partial by design: full records expire with the artifact; the history line per run is kept in git. GitHub Actions artifacts, 90 days conformity/latest.json in git, indefinite |
| record.format | partial | OSCAL-shaped assessment-results JSON; not validated against the OSCAL schema |
A finding opens when a check fails and closes only when a later run passes that check without the hit (CC-10.1). Closed findings stay listed.
| id | status | check | where | requirements | opened / closed |
|---|---|---|---|---|---|
| None. | |||||
Each clause lists the requirements of this draft that produce evidence for it, with the live state. "Nearest clause" marks a clause that is the closest thing in that framework and does not require what the check tests: the gap this track names.
| clause | evidence from this tier |
|---|---|
| Art 9(1)-(2) | CC-4.1 gap (self-assessed) risk management system as a continuous iterative process |
| Art 72(1) | CC-4.1 gap (self-assessed) documented post-market monitoring system |
| Art 9(8) | CC-4.2 gap (self-assessed) testing against prior defined metrics and probabilistic thresholds CC-6.3 pass prior defined metrics and thresholds |
| Art 15(1) | CC-5.1 partial (self-assessed) consistent performance of the system as placed on the market CC-8.4 gap (self-assessed) nearest clause; it does not require this CC-12.3 pass consistent performance at the output |
| Art 12(1) | CC-5.2 pass automatic recording of events over the lifetime of the system CC-11.1 pass automatic recording of events CC-12.4 pass logging |
| Art 15(5) | CC-6.2 partial (self-assessed) resilience against attempts to alter use, outputs or performance |
| Art 55(1)(b) | CC-6.2 partial (self-assessed) nearest clause; it does not require this CC-7.5 gap (self-assessed) nearest clause; it does not require this |
| Art 9(6)-(7) | CC-7.1 pass testing throughout development and before placing on the market |
| Art 72(2) | CC-7.3 partial evaluate continuous compliance throughout the lifetime CC-11.1 pass collection of data on performance throughout the lifetime |
| Art 10(2) | CC-8.1 partial (self-assessed) nearest clause; it does not require this |
| Art 10(3) | CC-8.2 partial nearest clause; it does not require this |
| Art 13(1) | CC-8.6 partial (self-assessed) nearest clause; it does not require this |
| Art 14(1) | CC-9.1 pass (self-assessed) human oversight CC-12.1 pass which decisions a person takes |
| Art 73(1) | CC-10.2 n/a (self-assessed) reporting of serious incidents |
| Art 19(1) | CC-11.2 partial logs kept for at least six months |
| Art 18(1) | CC-11.2 partial documentation kept 10 years |
| Art 43(2) | CC-11.3 pass nearest clause; it does not require this |
| clause | evidence from this tier |
|---|---|
| Art 24(1) | CC-4.1 gap (self-assessed) digital operational resilience testing programme |
| Art 24(2) | CC-5.1 partial (self-assessed) testing of ICT systems supporting critical functions |
| Art 9(4)(e) | CC-5.2 pass documented ICT change management CC-7.1 pass ICT change management with testing before deployment CC-7.2 pass nearest clause; it does not require this |
| Art 26(5) | CC-5.3 n/a (self-assessed) risk management measures for threat-led tests on live production systems |
| Art 26(1) | CC-6.4 gap (self-assessed) nearest clause; it does not require this |
| Art 25(1) | CC-7.1 pass appropriate tests on ICT systems |
| Art 24(6) | CC-7.3 partial appropriate tests at least yearly |
| Art 24(4) | CC-9.1 pass (self-assessed) tests by independent parties, internal or external CC-11.4 pass (self-assessed) nearest clause; it does not require this |
| Art 26(8) | CC-9.2 gap (self-assessed) external testers for threat-led tests |
| Art 27 | CC-9.2 gap (self-assessed) requirements for testers |
| Art 24(5) | CC-10.1 pass remediation of issues identified in tests |
| Art 19(1) | CC-10.2 n/a (self-assessed) reporting of major ICT-related incidents |
| clause | evidence from this tier |
|---|---|
| MEASURE 1.1 | CC-4.2 gap (self-assessed) approaches and metrics for measurement selected |
| GOVERN 2.1 | CC-4.3 gap (self-assessed) roles and responsibilities documented |
| MEASURE 2.5 | CC-6.1 partial (self-assessed) nearest clause; it does not require this CC-6.5 partial nearest clause; it does not require this |
| clause | evidence from this tier |
|---|---|
| PR.PS-01 | CC-7.1 pass configuration management CC-12.2 pass nearest clause; it does not require this CC-12.3 pass configuration management of the rule table |
| ID.IM-03 | CC-7.4 partial improvements from lessons learned CC-10.1 pass lessons learned |
| DE.CM-09 | CC-11.1 pass monitoring of software and services CC-12.4 pass monitoring |
| GV.OC | CC-12.5 partial nearest clause; it does not require this |
| clause | evidence from this tier |
|---|---|
| Art 32(1)(d) | CC-7.3 partial regular testing, assessing and evaluating |
| Art 5(1)(d) | CC-8.2 partial accuracy; kept up to date CC-8.3 gap (self-assessed) nearest clause; it does not require this CC-8.5 partial (self-assessed) nearest clause; it does not require this |
| run (UTC) | trigger | site commit | overall | open | warnings |
|---|---|---|---|---|---|
| 2026-10-07T12:38:58Z | push | 6cd76b939982 | pass | 0 | 0 |
| 2026-10-07T12:36:14Z | push | ef622e04817a | pass | 0 | 0 |
Full run records are workflow artifacts (90 days); the history line per run and the open findings live in conformity/latest.json in git. Records are OSCAL-shaped (assessment-results with observations and findings) and not yet validated against the OSCAL schema.