Security Appraisal Framework and Enablement

The OCP S.A.F.E.™ (Security Appraisal Framework and Enablement) Program, a Sub-Project of the OCP Security Project, standardizes firmware security reviews across the data center supply chain. Modern data center devices run updatable firmware and microcode whose provenance and integrity require rigorous assurance; S.A.F.E. reduces duplicate audit effort, gives device consumers consistent, independent conformance assurance, and builds a growing public record of reviewed products. Independent Security Review Providers accredited by the OCP Foundation conduct reviews against a published framework and review scope; approved products are listed on the OCP Marketplace and may carry the S.A.F.E. logo. Program documentation, SRP criteria, and all published findings reports are maintained openly on GitHub.

OCP S.A.F.E.™ Program

Get involved

Steering Committee Representative

Roksana Golizadeh Mojarad

Project Leads

About This Sub-Project


Modern data centers rely on a wide variety of processing devices (CPU, GPU, FPGA) and peripheral components (network controllers, accelerators, storage devices). These devices run updatable firmware and microcode whose provenance and supply chain integrity require rigorous security assurance.

The OCP S.A.F.E.™ (Security Appraisal Framework and Enablement) Program standardizes firmware security reviews across the data center supply chain — reducing duplicate audit effort, providing consistent conformance assurance to device consumers, and building a growing public record of reviewed products.

Program Goals

  • Reduce overhead and redundancy of security audits across the ecosystem.
  • Provide independent security conformance assurance to device consumers.
  • Decrease competitive barriers that prevent source code sharing for robust security testing.
  • Increase the number of devices whose firmware and updates are reviewed on a continuous basis.
  • Progressively advance security posture across the hardware and firmware supply chain through iterative refinement.

Learn About OCP S.A.F.E.™

Start with the introductory eLearning course on OCP Academy, then explore approved products and the program documentation on GitHub.

OCP S.A.F.E.™ eLearning Course on OCP Academy

Approved Products & Published Reports on GitHub

View S.A.F.E.™ Approved Products on the OCP Marketplace

GitHub Resources

All program documentation, review criteria, SRP listings, and published findings reports are maintained in the OCP S.A.F.E.™ GitHub repository. These resources are openly accessible and continuously updated.

Resource Description Link
Framework Core objectives and program rules View on GitHub →
Review Scope (Review Areas) What every security review must cover View on GitHub →
SRP Requirements & Criteria How to qualify as a Security Review Provider View on GitHub →
Approved SRPs Current list of accredited review providers View on GitHub →
Published Reports All submitted S.A.F.E. Findings Reports (SFRs) View on GitHub →
GitHub Repository (root) Full program documentation and history View on GitHub →

Accredited Security Review Providers

OCP S.A.F.E.™ Security Review Providers (SRPs) are independent third-party firms accredited by the OCP Foundation to conduct firmware and hardware security conformance reviews. Device vendors choose from this approved list to initiate a review.

Security Review Provider Website Contact Email
Anvil Secure anvilsecure.com [email protected]
Atredis Partners atredis.com/ocp-safe [email protected]
Brightsight brightsight.com/ocp-safe [email protected]
IOActive info.ioactive.com [email protected]
ivision ivision.com [email protected]
Keysight Riscure keysight.com [email protected]
Kudelski IoT kudelski-iot.com [email protected]
NCC Group nccgroup.com [email protected]
NetSPI netspi.com TBD
Tetrel Security tetrelsec.com [email protected]
Trail of Bits trailofbits.com [email protected]

Current SRP list: View on GitHub

How to Participate

For Device Vendors

  1. Become an OCP Member and join the OCP Solution Provider Program.
  2. Review the Framework and Review Scope documentation, then select an accredited SRP to conduct your review.
  3. Once the SRP submits the Security Findings Report to the OCP, your product is designated OCP S.A.F.E.™ Approved, listed on the OCP Marketplace, and the OCP issues the S.A.F.E.™ logo for go-to-market use.

For Security Review Providers

  1. Review the SRP Requirements & Criteria documentation and contact the OCP S.A.F.E.™ Project Leads to discuss an application.
  2. The OCP Foundation and Security Project Leads review the SRP Criteria Assessment. Upon approval, sign the relevant agreements and pay the corresponding fees.
  3. Approved SRPs are listed on the OCP Membership and Solution Provider Directories.

Scope

OCP S.A.F.E.™ reviews cover the following security domains:

Boot Code Integrity — standard hardware interface and protocols for ensuring boot code integrity
Security Hardware Firmware — open-source firmware for dedicated security hardware
Firmware APIs & Protocols — security firmware APIs and protocols
Change of Ownership — change of ownership of IT gear (e.g., resale scenarios)
Provisioning — firmware security provisioning methodologies
Secure Boot — secure boot of firmware and operating system
Recovery — recovery from a compromised or untrusted state
Mutable Storage — securing and verifying all mutable storage (flash for BIOS, BMC, microcontrollers, CPLD, etc.)
Secure Updates — secure updates to mutable storage with versatile rollback-protection options

Full review scope details: Review Areas on GitHub