The conformance checklist tells an operator whether it qualifies. The Verified Sovereign Computing Mark turns that into something a buyer can recognise and compare across competing clouds. This part of the framework is in active development; the shape below is the working model.

A Mark has two parts: a tier for how much of the framework a cloud meets, and an assessment level for how rigorously that has been verified. Written together they form a single grade - A/2, say - that a buyer can read at a glance.

A tiered rating

The Mark grades a cloud into one of four tiers. The tier is a coarse classification for a procurement comparison; finer ranking within a tier is by operational metrics and market plurality, not by raw item counts.

Tier Meaning
Tier 1 — Conformant Passes every MUST and the Sovereignty Test.
Tier 2 — Conformant with exceptions Passes the cross-cutting MUSTs and the Sovereignty Test; a small number of named MUST exceptions, each with a dated remediation plan.
Tier 3 — Aspirant Passes the cross-cutting MUSTs; has a published roadmap to Tier 1.
Tier 4 — Non-conformant Anything below Tier 3, including any cloud claiming a tier without a current public report.

The tier says what a cloud meets. How thoroughly that claim has been checked is a separate axis - the assessment level.

Assessment levels

How much scrutiny stands behind a Mark is graded from A to C, with A the strongest. The level is set by who verified the claim, not by the operator alone.

Assessment level A — Audited technology
The Sovereign Computing Initiative has audited the running technology itself, not only the paperwork. The strongest form of the Mark.
Assessment level B — Audited report
The Initiative has independently reviewed the conformance report and the evidence behind it.
Assessment level C — Self-assessed
The operator has published, dated and signed its own conformance report. Credible, but not independently verified.

Reading the Mark

A Mark is written as level/tier - the assessment level first, then the tier. A/2 is an audited-technology assessment of a Tier 2 cloud; C/1 is a self-assessed Tier 1 claim.

Not every combination is offered. Independent audit is available to clouds that reach Tier 1 or Tier 2; an Aspirant (Tier 3) may only self-assess; and a non-conformant cloud (Tier 4) earns no Mark at all.

Conformance A — Audited technology B — Audited report C — Self-assessed
Tier 1 — Conformant A/1 B/1 C/1
Tier 2 — With exceptions A/2 B/2 C/2
Tier 3 — Aspirant C/3
Tier 4 — Non-conformant
Three example Marks. A/1 with a gold Verified band: audited technology, fully conformant. B/2 with a silver band: audited report, conformant with exceptions. C/3 with a bronze band: self-assessed aspirant.
A stronger letter (A over C) means deeper verification; a lower tier number (1 over 3) means broader conformance. Both read from the Mark alone.

Evidence

The assessment level grades the report as a whole. Within it, every individual claim is backed by evidence of a stated class:

  • Publicly verifiable - a linked, dated public artefact. Acceptable for any item.
  • Audit-verified - confirmed by an independent auditor's review of internal systems.
  • Declared - self-declared by the operator. Counts only for SHOULDs, never toward Tier 1 or Tier 2 qualification.

Components bound the score

A cloud is a composition of components, and its tier is bounded by the weakest one - with a deliberate exception. A non-conformant component that the customer can substitute through the cloud's documented APIs does not drag the tier down; only a load-bearing, non-conformant component does. The Component Conformance Manifest records which is which.

The procurement comparison

The Mark is designed to drop into a procurement comparison. For each candidate cloud, a buyer can line up:

  • the Mark - assessment level and tier - with the last audit date and the auditor
  • the number of independent providers at support Levels 1 to 4 - the measure of market plurality
  • open MUST exceptions, and the count of load-bearing non-conformant components
  • a link to the full conformance report

What the Mark does not measure

Some things cannot honestly be reduced to a rating and need a parallel due-diligence process: the strategic alignment of a cloud's governance with your legal and regulatory environment, the quality of the Level 5 advisory available to you, and the political or ownership exposure of the operator and of each component's maintainer.

The Mark measures openness and replaceability. It does not measure fitness for a specific sovereignty mandate. For what the tiers are built on, see conformance and the Sovereignty Test.