The Verified Sovereign Computing Mark
Turning conformance into a rating a buyer can compare
The conformance checklist tells an operator whether it qualifies. The Verified Sovereign Computing Mark turns that into something a buyer can recognise and compare across competing clouds. This part of the framework is in active development; the shape below is the working model.
A Mark has two parts: a tier for how much of the framework a cloud meets, and an assessment level for how rigorously that has been verified. Written together they form a single grade - A/2, say - that a buyer can read at a glance.
A tiered rating
The Mark grades a cloud into one of four tiers. The tier is a coarse classification for a procurement comparison; finer ranking within a tier is by operational metrics and market plurality, not by raw item counts.
| Tier | Meaning |
|---|---|
| Tier 1 — Conformant | Passes every MUST and the Sovereignty Test. |
| Tier 2 — Conformant with exceptions | Passes the cross-cutting MUSTs and the Sovereignty Test; a small number of named MUST exceptions, each with a dated remediation plan. |
| Tier 3 — Aspirant | Passes the cross-cutting MUSTs; has a published roadmap to Tier 1. |
| Tier 4 — Non-conformant | Anything below Tier 3, including any cloud claiming a tier without a current public report. |
The tier says what a cloud meets. How thoroughly that claim has been checked is a separate axis - the assessment level.
Assessment levels
How much scrutiny stands behind a Mark is graded from A to C, with A the strongest. The level is set by who verified the claim, not by the operator alone.
- Assessment level A — Audited technology
- The Sovereign Computing Initiative has audited the running technology itself, not only the paperwork. The strongest form of the Mark.
- Assessment level B — Audited report
- The Initiative has independently reviewed the conformance report and the evidence behind it.
- Assessment level C — Self-assessed
- The operator has published, dated and signed its own conformance report. Credible, but not independently verified.
Reading the Mark
A Mark is written as level/tier - the assessment level first, then the tier. A/2 is an audited-technology assessment of a Tier 2 cloud; C/1 is a self-assessed Tier 1 claim.
Not every combination is offered. Independent audit is available to clouds that reach Tier 1 or Tier 2; an Aspirant (Tier 3) may only self-assess; and a non-conformant cloud (Tier 4) earns no Mark at all.
| Conformance | A — Audited technology | B — Audited report | C — Self-assessed |
|---|---|---|---|
| Tier 1 — Conformant | A/1 | B/1 | C/1 |
| Tier 2 — With exceptions | A/2 | B/2 | C/2 |
| Tier 3 — Aspirant | — | — | C/3 |
| Tier 4 — Non-conformant | — | — | — |
Evidence
The assessment level grades the report as a whole. Within it, every individual claim is backed by evidence of a stated class:
- Publicly verifiable - a linked, dated public artefact. Acceptable for any item.
- Audit-verified - confirmed by an independent auditor's review of internal systems.
- Declared - self-declared by the operator. Counts only for SHOULDs, never toward Tier 1 or Tier 2 qualification.
Components bound the score
A cloud is a composition of components, and its tier is bounded by the weakest one - with a deliberate exception. A non-conformant component that the customer can substitute through the cloud's documented APIs does not drag the tier down; only a load-bearing, non-conformant component does. The Component Conformance Manifest records which is which.
The procurement comparison
The Mark is designed to drop into a procurement comparison. For each candidate cloud, a buyer can line up:
- the Mark - assessment level and tier - with the last audit date and the auditor
- the number of independent providers at support Levels 1 to 4 - the measure of market plurality
- open MUST exceptions, and the count of load-bearing non-conformant components
- a link to the full conformance report
What the Mark does not measure
Some things cannot honestly be reduced to a rating and need a parallel due-diligence process: the strategic alignment of a cloud's governance with your legal and regulatory environment, the quality of the Level 5 advisory available to you, and the political or ownership exposure of the operator and of each component's maintainer.
The Mark measures openness and replaceability. It does not measure fitness for a specific sovereignty mandate. For what the tiers are built on, see conformance and the Sovereignty Test.