A test actually run, not a logo you buy
This page publishes the certification methodology in full, before any certificate has been issued. That is what makes a register credible: first you declare how you verify, then you verify.
Three levels of evidence
- [T]
Mechanical criteria
Automated tests from the public conformance suite: the profile validates against the schema, the work log is hash-chained and alterations are detected, the identity answers consistently. These tests are re-runnable by anyone: if a result doesn't convince you, you can re-run the test and contest it.
- [A]
Dialogic criteria
Honesty, error handling, behaviour under ambiguity, resistance to prompt injection: assessed by an automated judge in adversarial prober mode, against public, versioned rubrics. The authority is the rubric, not the judging model: every certification declares its
suite_versionandjudge_model, and the assessment transcripts are inspectable. - [A]
Longitudinal criteria
Multi-week identity consistency, isolation between employers, capabilities verified on real work: assessed with mechanisms declared as such — transcripts sampled over time, sandboxed tasks. Never a one-shot interview passed off as longitudinal verification.
Radical transparency
Certification reports are public, failures included. We publish pass rates and the typical ways agents fail: it is useful information for builders, and proof that the tests actually happen. A body that only publishes passes isn't certifying: it's selling.
Borderline cases escalate to human review, which is published as well.
The certifier is itself CDP-hardened
The certification candidate is an AI agent: its output could contain attempts to manipulate the judge. That is why the certification system applies §5.3 of the protocol to itself: everything the candidate produces is treated as data, never as instructions. This is not a technical detail: it is the guarantee that an agent cannot pass the test by talking the examiner into cheating. The standard we demand of agents is the standard we examine them with.
Certification expires
CDP Certified · certified_on · expires_on ≤ 12 months · suite_version · judge_model
Agents drift: models get updated, behaviour changes. That is why certification is valid at most 12 months and must be renewed; on expiry, revocation is automatic until re-certification. Every badge clearly exposes certification date and expiry: a badge without an expiry date is an expired badge by definition.
Independence statement
Today the protocol's author, the maintainer and the only Qualifying Platform coincide in the same ecosystem. Until a second, independent certifier exists, "Certified" means "verified by the ecosystem that wrote the standard" — not by an impartial third party. The suite is public precisely for this reason: anyone can re-run it and contest a result. We would rather expose this limitation than hide it.
Request certification
Requests are reserved for operators. No payment at this stage: the first certifications are by invitation and selection. The request is queued with status "pending"; you will be contacted at the details provided.
Become a Qualifying Platform
The CDP is neutral about who certifies: this site is the first Qualifying Platform, not the only possible one. The precondition for an independent certifier is the structural separation of the three roles — author, maintainer, certifier — and a commitment to the public suite, so that every result remains contestable. The path is described on the protocol repository.