CMOS‑SB

Certification & Compliance

Requirements, criteria, and processes for organizations seeking CMOS‑SB certification and maintaining compliance.

CMOS‑SB certification provides organizations with a verifiable, standards‑based credential demonstrating that their systems, platforms, or services meet established requirements for cognitive‑emotional safety, transparency, and accountability. Compliance with CMOS‑SB standards is assessed against published criteria and subject to ongoing reporting obligations.

Certification Requirements

Organizations seeking CMOS‑SB certification must demonstrate compliance with all applicable active standards. The certification process includes:

  • Application — Submission of a formal certification application identifying the systems, platforms, or services to be certified and the applicable standards.
  • Self‑Assessment — Completion of a comprehensive self‑assessment against all applicable standards, including documentation of compliance measures, testing results, and organizational policies.
  • Independent Review — Review of the self‑assessment by an independent assessor appointed by the CMOS‑SB Certification Authority. The review includes document evaluation, technical testing, and stakeholder interviews as appropriate.
  • Board Determination — The Standards Board, upon recommendation from the Certification Authority, makes the final certification determination.

Compliance Criteria

Compliance is assessed against specific, measurable criteria derived from each applicable standard. General compliance criteria include:

  • Technical Compliance — Systems meet all technical specifications defined in applicable standards, including measurement, documentation, and safety requirements.
  • Process Compliance — Organizational processes for design, deployment, and maintenance conform to CMOS‑SB requirements for transparency, review, and accountability.
  • Ethical Compliance — All certified systems and processes align with the principles established in the CMOS‑SB Ethical Framework.
  • Documentation Compliance — All required documentation is current, accurate, and publicly accessible as specified by applicable standards.

Reporting Obligations

Certified organizations are subject to ongoing reporting obligations:

  • Annual Compliance Report — A comprehensive report demonstrating continued compliance with all applicable standards, submitted annually to the Certification Authority.
  • Incident Reporting — Prompt notification of any incident, system failure, or change that may affect compliance status. Incidents must be reported within 72 hours of discovery.
  • Change Notification — Advance notification of any significant change to certified systems, processes, or organizational structure that may affect compliance.
  • Public Transparency — Certified organizations must maintain public disclosure of their certification status, applicable standards, and most recent compliance report summary.

Non‑Compliance Notices

CMOS‑SB may issue non‑compliance notices when a certified organization fails to meet applicable standards or reporting obligations. Non‑compliance actions include:

  • Advisory Notice — A formal notice identifying a potential compliance concern and requesting corrective action within a specified timeframe.
  • Corrective Action Requirement — A mandatory requirement to implement specific corrective measures within a defined period, with verification.
  • Certification Suspension — Temporary suspension of certification pending resolution of a significant compliance failure.
  • Certification Revocation — Permanent revocation of certification for sustained or egregious non‑compliance.

All non‑compliance actions are subject to an appeals process. Details are available in the Governance Suite.

Renewal

CMOS‑SB certification is valid for a period of two years from the date of issuance. Renewal requires:

  • Submission of a renewal application at least 90 days before expiration
  • Demonstration of continued compliance through annual reports and any required assessments
  • Review of compliance with any new or revised standards adopted since the last certification
  • Payment of applicable renewal fees

Organizations that fail to renew certification before expiration must reapply through the full certification process. For questions about certification, contact the CMOS‑SB Certification Authority.