Security Appraisal Framework and Enablement
The OCP S.A.F.E.™ (Security Appraisal Framework and Enablement) Program, a Sub-Project of the OCP Security Project, standardizes firmware security reviews across the data center supply chain. Modern data center devices run updatable firmware and microcode whose provenance and integrity require rigorous assurance; S.A.F.E. reduces duplicate audit effort, gives device consumers consistent, independent conformance assurance, and builds a growing public record of reviewed products. Independent Security Review Providers accredited by the OCP Foundation conduct reviews against a published framework and review scope; approved products are listed on the OCP Marketplace and may carry the S.A.F.E. logo. Program documentation, SRP criteria, and all published findings reports are maintained openly on GitHub.
Get involved
Steering Committee Representative
Project Leads
About This Sub-Project
Modern data centers rely on a wide variety of processing devices (CPU, GPU, FPGA) and peripheral components (network controllers, accelerators, storage devices). These devices run updatable firmware and microcode whose provenance and supply chain integrity require rigorous security assurance.
The OCP S.A.F.E.™ (Security Appraisal Framework and Enablement) Program standardizes firmware security reviews across the data center supply chain — reducing duplicate audit effort, providing consistent conformance assurance to device consumers, and building a growing public record of reviewed products.
Program Goals
- Reduce overhead and redundancy of security audits across the ecosystem.
- Provide independent security conformance assurance to device consumers.
- Decrease competitive barriers that prevent source code sharing for robust security testing.
- Increase the number of devices whose firmware and updates are reviewed on a continuous basis.
- Progressively advance security posture across the hardware and firmware supply chain through iterative refinement.
Learn About OCP S.A.F.E.™
Start with the introductory eLearning course on OCP Academy, then explore approved products and the program documentation on GitHub.
OCP S.A.F.E.™ eLearning Course on OCP Academy
GitHub Resources
All program documentation, review criteria, SRP listings, and published findings reports are maintained in the OCP S.A.F.E.™ GitHub repository. These resources are openly accessible and continuously updated.
| Resource | Description | Link |
| Framework | Core objectives and program rules | View on GitHub → |
| Review Scope (Review Areas) | What every security review must cover | View on GitHub → |
| SRP Requirements & Criteria | How to qualify as a Security Review Provider | View on GitHub → |
| Approved SRPs | Current list of accredited review providers | View on GitHub → |
| Published Reports | All submitted S.A.F.E. Findings Reports (SFRs) | View on GitHub → |
| GitHub Repository (root) | Full program documentation and history | View on GitHub → |
Accredited Security Review Providers
OCP S.A.F.E.™ Security Review Providers (SRPs) are independent third-party firms accredited by the OCP Foundation to conduct firmware and hardware security conformance reviews. Device vendors choose from this approved list to initiate a review.
| Security Review Provider | Website | Contact Email |
| Anvil Secure | anvilsecure.com | [email protected] |
| Atredis Partners | atredis.com/ocp-safe | [email protected] |
| Brightsight | brightsight.com/ocp-safe | [email protected] |
| IOActive | info.ioactive.com | [email protected] |
| ivision | ivision.com | [email protected] |
| Keysight Riscure | keysight.com | [email protected] |
| Kudelski IoT | kudelski-iot.com | [email protected] |
| NCC Group | nccgroup.com | [email protected] |
| NetSPI | netspi.com | TBD |
| Tetrel Security | tetrelsec.com | [email protected] |
| Trail of Bits | trailofbits.com | [email protected] |
Current SRP list: View on GitHub
How to Participate
For Device Vendors
- Become an OCP Member and join the OCP Solution Provider Program.
- Review the Framework and Review Scope documentation, then select an accredited SRP to conduct your review.
- Once the SRP submits the Security Findings Report to the OCP, your product is designated OCP S.A.F.E.™ Approved, listed on the OCP Marketplace, and the OCP issues the S.A.F.E.™ logo for go-to-market use.
For Security Review Providers
- Review the SRP Requirements & Criteria documentation and contact the OCP S.A.F.E.™ Project Leads to discuss an application.
- The OCP Foundation and Security Project Leads review the SRP Criteria Assessment. Upon approval, sign the relevant agreements and pay the corresponding fees.
- Approved SRPs are listed on the OCP Membership and Solution Provider Directories.
Scope
OCP S.A.F.E.™ reviews cover the following security domains:
Full review scope details: Review Areas on GitHub
