International

SLSA

24 controls. 143 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

24 controls 143 frameworks share controls with it International verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
SLSA-BUILD-L1-1Documented Build Process0
SLSA-BUILD-L1-2Provenance Generation0
SLSA-BUILD-L2-1Hosted Build Platform0
SLSA-BUILD-L2-2Signed Provenance0
SLSA-BUILD-L3-1Hardened Build Platform0
SLSA-BUILD-L3-2Isolated Provenance Generation0
SLSA-BUILD-PARAM-1Build Parameter Recording0
SLSA-CONSUMER-1Provenance Verification by Consumer0
SLSA-CONSUMER-2Artifact Storage and Distribution Integrity0
SLSA-DEP-1Dependency Inventory0
SLSA-DEP-2Dependency Provenance Verification0
SLSA-DEP-3Vulnerability Monitoring of Dependencies0
SLSA-EXPECT-1Expectations Document for Artifacts0
SLSA-INCIDENT-1Supply Chain Incident Response0
SLSA-PROD-1Producer Identification0
SLSA-PROD-2Public Source Repository0
SLSA-RUNNER-1Build Runner Integrity0
SLSA-SRC-1Verified Source History0
SLSA-SRC-2Two Person Reviewed Changes0
SLSA-VSA-1Verification Summary Attestation0
SUPCHAIN-1Build Integrity - Source, Build, Provenance131
SUPCHAIN-2Source Integrity - Branch Protection, Code Review, Two-Person Rule89
SUPCHAIN-3Dependency Verification and SBOM26
SUPCHAIN-4Verification, Attestation, In-Toto Integration0

Tell me when SLSA files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What this page is

A control-level reference for SLSA, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition