Back to Frameworks

Sigstore - Software Artifact Signing and Verification

International (OpenSSF)
v1.0 GA (2024)
8 domains
17 controls

Sigstore is a set of open-source tools for signing, verifying, and protecting software artifacts. Created by Google, Red Hat, and Purdue University, now under the OpenSSF. Components: Cosign (container and artifact signing), Fulcio (certificate authority for ephemeral certificates), Rekor (transparency log), and Gitsign (git commit signing). Sigstore enables keyless signing using OIDC identity (GitHub, Google, Microsoft accounts). Used by npm, PyPI, Kubernetes, Homebrew, and major package ecosystems. Over 20 million signatures in the public Rekor transparency log. Adopted by Kubernetes as the standard for supply chain security.

Verified

Sigstore - Software Artifact Signing and Verification is a compliance framework from International (OpenSSF) with 8 domains and 17 controls that map to 120 other frameworks. The largest domains are Sigstore: Cosign Signing and Storage (4 controls), Sigstore: Fulcio Certificate Authority (3 controls), Sigstore: Rekor Transparency Log (3 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (8)

Cosign

1 controls
Controls in the Cosign domain of Sigstore - Software Artifact Signing and Verification1 controls
CodeTitle
SIGSTORE-3Sigstore for Containers and Artifacts (Cosign)

Keyless Signing

1 controls
Controls in the Keyless Signing domain of Sigstore - Software Artifact Signing and Verification1 controls
CodeTitle
SIGSTORE-1Keyless Signing with Short-Lived Certificates

Private Deployment

1 controls
Controls in the Private Deployment domain of Sigstore - Software Artifact Signing and Verification1 controls
CodeTitle
SIGSTORE-4Private Deployment, Long-Lived Migration, Regulated Environments

Sigstore: Cosign Signing and Storage

4 controls
Controls in the Sigstore: Cosign Signing and Storage domain of Sigstore - Software Artifact Signing and Verification4 controls
CodeTitle
SIGSTORE-COS-1Keyless Signing
SIGSTORE-COS-2Key-Based Signing
SIGSTORE-COS-3OCI Registry Storage
SIGSTORE-COS-4Signature Verification

Sigstore: Fulcio Certificate Authority

3 controls
Controls in the Sigstore: Fulcio Certificate Authority domain of Sigstore - Software Artifact Signing and Verification3 controls
CodeTitle
SIGSTORE-FUL-1Short-Lived Certificate Issuance
SIGSTORE-FUL-2Identity Binding
SIGSTORE-FUL-3Certificate Transparency

Sigstore: Rekor Transparency Log

3 controls
Controls in the Sigstore: Rekor Transparency Log domain of Sigstore - Software Artifact Signing and Verification3 controls
CodeTitle
SIGSTORE-REK-1Signature Transparency Logging
SIGSTORE-REK-2Tamper-Evident Storage
SIGSTORE-REK-3RESTful API Validation

Sigstore: Verification and Policy Enforcement

3 controls
Controls in the Sigstore: Verification and Policy Enforcement domain of Sigstore - Software Artifact Signing and Verification3 controls
CodeTitle
SIGSTORE-VER-1Timestamp Verification
SIGSTORE-VER-2Supply Chain Attestation
SIGSTORE-VER-3Policy Enforcement

Transparency Log

1 controls
Controls in the Transparency Log domain of Sigstore - Software Artifact Signing and Verification1 controls
CodeTitle
SIGSTORE-2Transparency Log (Rekor) and Verification

Your Compliance Coverage

If you comply with Sigstore - Software Artifact Signing and Verification, you already cover:

+ 117 more: ISO 15189:2022 - Medical Laboratories Requirements for Quality and Competence (24%), Singapore Government Instruction Manual on ICT&SS Management (IM8) (24%)

See all 120 mapped frameworks ↓

Maps to 120 other frameworks

17 total controls
NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements
5 source controls mapped|10 target controls covered
29%
NIST SP 800-53 Rev 5
5 source controls mapped|18 target controls covered
29%
South Korea ISMS-P
5 source controls mapped|7 target controls covered
29%
24%
Singapore Government Instruction Manual on ICT&SS Management (IM8)
4 source controls mapped|3 target controls covered
24%
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0
4 source controls mapped|11 target controls covered
24%
ISO/IEC 27011:2024
4 source controls mapped|5 target controls covered
24%
ISO 27799
4 source controls mapped|7 target controls covered
24%
FTC GLBA Safeguards Rule (16 CFR Part 314)
4 source controls mapped|1 target controls covered
24%
ISO 13485
4 source controls mapped|8 target controls covered
24%
ISO 27017
4 source controls mapped|5 target controls covered
24%
BSI IT-Grundschutz
4 source controls mapped|9 target controls covered
24%
ISO 27043
4 source controls mapped|13 target controls covered
24%
IEC 62351 - Power Systems Communication Security
4 source controls mapped|3 target controls covered
24%
ISO/SAE 21434
4 source controls mapped|12 target controls covered
24%
MARS-E - Minimum Acceptable Risk Standards for Exchanges
4 source controls mapped|2 target controls covered
24%
NIST SP 800-190
4 source controls mapped|5 target controls covered
24%
ISO 27018
4 source controls mapped|5 target controls covered
24%
TISAX - Trusted Information Security Assessment Exchange
3 source controls mapped|6 target controls covered
18%
FBI CJIS Security Policy
3 source controls mapped|3 target controls covered
18%
Annex 11 to EU GMP - Computerised Systems
3 source controls mapped|3 target controls covered
18%
ISO/IEC 27010:2015
3 source controls mapped|5 target controls covered
18%
18%
ISO/IEC 27400:2022
3 source controls mapped|2 target controls covered
18%
Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023)
3 source controls mapped|2 target controls covered
18%
Saudi Arabia PDPL
3 source controls mapped|2 target controls covered
18%
Bahrain PDPL
3 source controls mapped|2 target controls covered
18%
ISO 19011
3 source controls mapped|4 target controls covered
18%
UK Open Banking Standard
3 source controls mapped|4 target controls covered
18%
APPI
3 source controls mapped|2 target controls covered
18%
ASD Strategies to Mitigate Cyber Security Incidents
3 source controls mapped|4 target controls covered
18%
Authorised Economic Operator (AEO) Programmes - Global Standards
2 source controls mapped|4 target controls covered
12%
ISO 28001:2007 Supply Chain Security Management
2 source controls mapped|3 target controls covered
12%
NIST Cybersecurity Framework 2.0
2 source controls mapped|6 target controls covered
12%
NIST SP 1800-32
2 source controls mapped|6 target controls covered
12%
ISO 27019
2 source controls mapped|6 target controls covered
12%
API 1164
2 source controls mapped|6 target controls covered
12%
AS9100D:2016 - Quality Management Systems for Aviation, Space, and Defence
2 source controls mapped|2 target controls covered
12%
IEC 62443
2 source controls mapped|6 target controls covered
12%
UK Security and Emergency Measures Direction (SEMD) - Water Industry
2 source controls mapped|2 target controls covered
12%
SLSA
2 source controls mapped|1 target controls covered
12%
FFIEC Cybersecurity Assessment Tool (CAT)
2 source controls mapped|4 target controls covered
12%
PCI SSF
2 source controls mapped|1 target controls covered
12%
FFIEC IT Examination Handbook
2 source controls mapped|1 target controls covered
12%
ISO 31000:2018
2 source controls mapped|2 target controls covered
12%
PCI PIN Security
2 source controls mapped|1 target controls covered
12%
PCI P2PE
2 source controls mapped|1 target controls covered
12%
Vietnam PDPD
2 source controls mapped|1 target controls covered
12%
Turkey KVKK
2 source controls mapped|1 target controls covered
12%
ISO 22739:2024 - Blockchain and Distributed Ledger Technologies Vocabulary
2 source controls mapped|4 target controls covered
12%
ISO/IEC 23837 - Security Requirements for Quantum Key Distribution
2 source controls mapped|3 target controls covered
12%
NSA Guidance for Transition to Quantum-Resistant Cryptography
2 source controls mapped|4 target controls covered
12%
ISO/IEC 29115:2023 - Entity Authentication Assurance Framework
2 source controls mapped|4 target controls covered
12%
ISO 20000-1
2 source controls mapped|2 target controls covered
12%
ISO 20400:2017 - Sustainable Procurement
1 source controls mapped|3 target controls covered
6%
UK FCA/PRA Operational Resilience Framework
1 source controls mapped|1 target controls covered
6%
ISO 50001:2018 - Energy Management Systems
1 source controls mapped|1 target controls covered
6%
6%
ISO 22318
1 source controls mapped|1 target controls covered
6%
ISO 22317
1 source controls mapped|1 target controls covered
6%
SQF Code Edition 9 - Safe Quality Food
1 source controls mapped|1 target controls covered
6%
ISO/IEC 27003:2017
1 source controls mapped|2 target controls covered
6%
ISO 26000:2010
1 source controls mapped|1 target controls covered
6%
BRCGS Global Standard for Food Safety Issue 9
1 source controls mapped|1 target controls covered
6%
ISO 22316
1 source controls mapped|1 target controls covered
6%
Protective Security Policy Framework (PSPF) Release 2024
1 source controls mapped|1 target controls covered
6%
AS9100D - Aerospace Quality Management System
1 source controls mapped|1 target controls covered
6%
ISO 41001:2018 - Facility Management Systems
1 source controls mapped|1 target controls covered
6%
SASB Standards
1 source controls mapped|1 target controls covered
6%
Space ISAC (Information Sharing and Analysis Center) - Threat Framework
1 source controls mapped|1 target controls covered
6%
Automotive SPICE (ASPICE) v4.0 - Process Assessment Model
1 source controls mapped|1 target controls covered
6%
ISO/IEC 23894:2023
1 source controls mapped|1 target controls covered
6%
APRA CPS 230 Operational Risk Management
1 source controls mapped|2 target controls covered
6%
BREEAM - Building Research Establishment Environmental Assessment Method
1 source controls mapped|1 target controls covered
6%
21 CFR Part 211 - Current Good Manufacturing Practice
1 source controls mapped|1 target controls covered
6%
Solvency II
1 source controls mapped|3 target controls covered
6%
UK Telecommunications (Security) Act 2021
1 source controls mapped|1 target controls covered
6%
Security of Critical Infrastructure Act 2018 (SOCI)
1 source controls mapped|1 target controls covered
6%
NIST SP 800-171
1 source controls mapped|1 target controls covered
6%
ISO/IEC 25012:2008 - Data Quality Model
1 source controls mapped|1 target controls covered
6%
Virginia CDPA
1 source controls mapped|1 target controls covered
6%
Uruguay DPL
1 source controls mapped|1 target controls covered
6%
Texas Data Privacy Act
1 source controls mapped|1 target controls covered
6%
Taiwan PDPA
1 source controls mapped|1 target controls covered
6%
SOC for Cybersecurity - Cybersecurity Risk Management Examination
1 source controls mapped|1 target controls covered
6%
3GPP 5G Security Architecture (TS 33.501)
1 source controls mapped|1 target controls covered
6%
US ITAR and EAR - Export Control and Data Security
1 source controls mapped|2 target controls covered
6%
Secure by Design: A Guide for Manufacturers (CISA)
1 source controls mapped|1 target controls covered
6%
ISO 27005
1 source controls mapped|1 target controls covered
6%
W3C Verifiable Credentials (VC) Data Model 2.0
1 source controls mapped|1 target controls covered
6%
ISO/IEC TR 24028:2020
1 source controls mapped|1 target controls covered
6%
Vermont Artificial Intelligence and Consumer Data Act (AICDA)
1 source controls mapped|1 target controls covered
6%
USMCA Chapter 19 - Digital Trade (United States-Mexico-Canada Agreement)
1 source controls mapped|1 target controls covered
6%
US EPA Safe Drinking Water Act (SDWA) - Cybersecurity Requirements
1 source controls mapped|1 target controls covered
6%
UK Gambling Commission - Cyber Resilience Requirements
1 source controls mapped|1 target controls covered
6%
UK Defence Standard 05-138 - Cyber Security for Defence Suppliers
1 source controls mapped|1 target controls covered
6%
Regional Comprehensive Economic Partnership (RCEP) - E-Commerce Chapter
1 source controls mapped|1 target controls covered
6%
TSA Pipeline Cybersecurity Directives
1 source controls mapped|1 target controls covered
6%
TEFCA - Trusted Exchange Framework and Common Agreement
1 source controls mapped|1 target controls covered
6%
SWIFT CSCF
1 source controls mapped|1 target controls covered
6%
ISO/IEC 38500:2024 - Governance of IT
1 source controls mapped|1 target controls covered
6%
Illinois Biometric Information Privacy Act (BIPA)
1 source controls mapped|2 target controls covered
6%
Armenia Law on Protection of Personal Data (2015)
1 source controls mapped|1 target controls covered
6%
AML/CTF Act 2006 (Australia)
1 source controls mapped|1 target controls covered
6%
Bank Secrecy Act / Anti-Money Laundering (BSA/AML)
1 source controls mapped|1 target controls covered
6%
Florida Digital Bill of Rights (FDBR)
1 source controls mapped|2 target controls covered
6%
ITU-T X.805 - Security Architecture for End-to-End Communications
1 source controls mapped|2 target controls covered
6%
Canada ITSG-33 - IT Security Risk Management
1 source controls mapped|1 target controls covered
6%
US Consumer Product Safety Commission (CPSC) - Connected Product Safety
1 source controls mapped|1 target controls covered
6%
Samoa Telecommunications Act (2005) - Privacy & Data Protection
1 source controls mapped|2 target controls covered
6%
DAMA-DMBOK2 - Data Management Body of Knowledge (2nd Edition)
1 source controls mapped|2 target controls covered
6%
US Automated Commercial Environment (ACE) - CBP Trade Data Requirements
1 source controls mapped|1 target controls covered
6%
ICAO Annex 17 - Aviation Security (AVSEC)
1 source controls mapped|1 target controls covered
6%
ITIL 4
1 source controls mapped|1 target controls covered
6%
NRC 10 CFR 73.54 - Nuclear Facility Cybersecurity
1 source controls mapped|1 target controls covered
6%

What is Sigstore - Software Artifact Signing and Verification and who does it apply to?

Sigstore - Software Artifact Signing and Verification is a compliance framework from International (OpenSSF) with 8 domains and 17 controls. Sigstore is a set of open-source tools for signing, verifying, and protecting software artifacts. Created by Google, Red Hat, and Purdue University, now under the OpenSSF. Components: Cosign (container and artifact signing), Fulcio (certificate authority for ephemeral certificates), Rekor (transparency log), and Gitsign (git commit signing). Sigstore enables keyless signing using OIDC identity (GitHub, Google, Microsoft accounts). Used by npm, PyPI, Kubernetes, Homebrew, and major package ecosystems. Over 20 million signatures in the public Rekor transparency log. Adopted by Kubernetes as the standard for supply chain security. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does Sigstore - Software Artifact Signing and Verification actually require?

Sigstore - Software Artifact Signing and Verification has 17 controls organised across 8 domains. The largest domains are Sigstore: Cosign Signing and Storage (4 controls), Sigstore: Fulcio Certificate Authority (3 controls), Sigstore: Rekor Transparency Log (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of Sigstore - Software Artifact Signing and Verification do I already cover?

Sigstore - Software Artifact Signing and Verification maps to 120 other compliance frameworks. The top mapping partners are NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements (29% coverage), NIST SP 800-53 Rev 5 (29% coverage), South Korea ISMS-P (29% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement Sigstore - Software Artifact Signing and Verification?

Start your Sigstore - Software Artifact Signing and Verification compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Sigstore - Software Artifact Signing and Verification requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 17 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.

Get Started Free →

Free forever — no credit card required