An OWASP Foundation Project

Operationalize Trust
with CycloneDX Attestations

Turn compliance checklists into verifiable attestations. An open source platform to map controls to standards, collect evidence, and exchange results machines can verify and humans can trust.

See It in Action

A Platform Built for
Clarity and Control

From high-level compliance dashboards to granular assessment workflows, Assessors Studio gives every stakeholder the view they need.

Dashboard — Overview
Active Projects
2
Total Assessments
4
Completion Rate
25%
Overdue
1
Requirement Conformance
Conformant39
Non-Conformant1
Unassessed3
Assessment Pipeline
New
Pending
In Progress
Complete
Risk Insights
2
High Blind Spot
PCI Secure Software Lifecycle requirements have no assessed requirements
High Overdue
"Product A ASVS Assessment" is 10 days overdue

Compliance at a Glance

Widget-based dashboard surfaces conformance posture, assessment progress, and risk insights across your organization.

Entities — Graph View
AI Acme Inc AS Acme Security AI Acme IT SP SecureAudit AC Compliance AIP Identity Plat. SA Supplier A PG AS Owns Assesses Contains

Entity Relationship Mapping

Visualize organizational structures, suppliers, products, and their assessment relationships in an interactive graph.

Assessments — SSDF Assessment
Supplier A SSDF Assessment
NIST SSDF v1.1 Complete
Standard
Assessment
Evidence
Claims
Attestation
Export
38 of 38 requirements assessed 100%
35 Yes 0 No 3 Partial 0 N/A
ID Name Result Evidence
PO.1.1 Security Policy Yes 2 items
PO.1.2 Roles & Resp. Yes 1 item
PS.1.1 Threat Modeling Partial 3 items

Guided Assessment Workflow

Step through standards, evidence, claims, and attestation generation with full traceability at every stage.

Core Capabilities

Everything You Need for
Structured Assurance

Built for modern assurance workflows. Assessors Studio replaces spreadsheets and static reports with structured, machine-readable, verifiable artifacts.

Structured Assessments

Conduct repeatable assessments aligned to defined requirements, with workflow support for contributors, reviewers, and approvers.

Evidence Management

Attach documentation, scan results, test artifacts, and third-party reports directly to claims while preserving provenance.

Claim Authoring

Express conformance statements in a standardized format that downstream systems can parse, validate, and automate against.

Machine-Readable Attestations

Generate CycloneDX attestation documents consumable by governance, risk, compliance, and security automation platforms.

Electronic & Digital Signatures

Support for both electronic and cryptographic digital signatures enables flexible deployment from internal approvals to legally binding attestations.

Standards Library

Import and manage machine-readable standards. Map internal controls to recognized frameworks and generate attestations aligned to multiple standards.

How It Works

From Requirements
to Verifiable Attestations

The CycloneDX attestation model structures assurance around four core primitives.

Requirement
MFA Implementation
Claim (CDXA)
"Control is active on all endpoints"
Evidence
sha256:8f3c...2d1e
Attestation
Signed, machine-readable artifact
01

Define Requirements

Import standards and define what must be satisfied. Map requirements to recognized compliance frameworks.

02

Author Claims

Assert conformance in a structured, standardized format. Reference supporting and counter evidence with mitigation strategies.

03

Gather Evidence

Attach artifacts that substantiate claims. Scan results, documentation, test reports, and third-party attestations.

04

Issue Attestations

Produce machine-readable, signed attestation documents ready for automated validation and exchange.

Built for Integration

Designed for Machines,
Not Just People

Assessors Studio works as a hands-on platform and as a node in your automated infrastructure. Every workflow that runs through the UI can also run through code, pipelines, and cross-system integrations.

API-First Architecture

Every capability exposed through the UI is also available programmatically. Build integrations, trigger assessments, and retrieve attestations through a consistent, well-documented API surface.

Pipeline Native

Embed attestation generation directly into CI/CD workflows. Validate compliance gates, produce signed artifacts, and propagate trust signals as part of every build and release.

Ecosystem Interoperability

Exchange attestations across organizational boundaries through transparency ecosystems like the Transparency Exchange API (TEA). Consume and produce artifacts that any compliant system can verify independently.

Example: Generate an attestation from your pipeline
POST /api/v1/attestations

  "standardId": "nist-ssdf-1.1",
  "claims": [...],
  "evidence": [...],
  "signature": { "algorithm": "ES256" }
Use Cases

Built for Real-World
Assurance Workflows

Whether you need regulatory compliance, vendor assurance, or product transparency, Assessors Studio has you covered.

🏛 Regulatory Compliance

  • Cyber Resilience Act (CRA) readiness
  • NIST SSDF alignment
  • PCI DSS assessments
  • Internal secure development policy verification

🔗 Supply Chain Assurance

  • Supplier security posture validation
  • Third-party risk documentation
  • Contractual security claim exchange
  • Automated vendor attestation intake

🛡 Secure Development Lifecycle

  • Secure design confirmation
  • Threat modeling verification
  • Code review attestation
  • Release readiness approval

📊 Executive Reporting

  • Structured evidence of control maturity
  • Automated compliance dashboards
  • Audit-ready artifact generation
  • Customer-facing trust statements
Who It's For

Designed for Security and
Compliance Professionals

Assessors Studio serves the teams responsible for trust, transparency, and assurance across the software supply chain.

🛡

Product Security

Verify secure development practices and generate product assurance artifacts

GRC Leaders

Structured compliance evidence and automated audit-ready documentation

📦

OSPOs

Open source governance with standardized transparency artifacts

🔍

Procurement & Vendor Risk

Validate supplier security posture with machine-readable attestations

📋

Independent Assessors

Conduct structured audits and issue verifiable attestation documents

DevSecOps

Integrate attestations into CI/CD pipelines for automated compliance checks

Ready to Shift from Narrative Compliance to Computational Trust?

Assessors Studio is open source and actively developed. Join the community, contribute, or start using it today.