Certification Tier

ICOSA Certification

Full 11-model pBFT consensus with cryptographic Audit Chain attestation. The definitive AI compliance certification with immutable proof, sealed in ICOSA's proprietary Audit Chain.

An independent council of AI models assesses your system and reaches consensus. No single vendor's opinion decides the outcome.

Who needs ICOSA Certification?

Organisations that must evidence conformity to a regulator, an auditor, or a procurement process — rather than self-attest to it. Certification produces an artefact a third party can verify independently.

If you need a readiness snapshot rather than proof, start with a Sentinel Scan. If you need article-by-article deficiency mapping before certifying, see Pre-Statement Baseline.

What the assessment covers

How the consensus mechanism works

Eleven models deliberate independently and reach consensus under a practical Byzantine Fault Tolerant (pBFT) protocol. A BFT-consensus council detects misalignment through multi-model deliberation rather than single-model judgment, so one model behaving incorrectly cannot determine the verdict.

What the Audit Chain proves

Every verdict is cryptographically signed and sealed in ICOSA's proprietary hash-chained, Ed25519-signed Audit Chain, creating an immutable, tamper-proof audit trail. This is ICOSA's own cryptographic Audit Chain — not a public cryptocurrency blockchain.

Each attestation record carries the verdict hash, an Ed25519 signature over the record, and the rolling Merkle root at the time of append. Anyone holding a certificate can verify an ICOSA certification by recomputing the hash chain and checking the signature.

This is the difference between claiming a verdict is trustworthy and being able to demonstrate it.

Consensus parameters by tier

Byzantine Fault Tolerance requires n = 3f + 1 nodes to tolerate f faulty ones, with a quorum of 2f + 1 agreeing nodes:

TierCouncilQuorumFaulty models tolerated
Sentineln=3, f=02/3Advisory only
Baselinen=5, f=13/51
Certificationn=11, f=37/113

What happens if a model dissents

The consensus process runs in three phases: Pre-Prepare (assessment distribution), Prepare (independent model evaluation), and Commit (vote aggregation and verdict computation).

Dissenting models must provide structured reasoning, and that reasoning is preserved in the audit trail. Disagreement is recorded rather than discarded — the attestation includes the quorum achievement proof, showing how many models agreed against the required threshold. A certification at 7/11 and one at 11/11 are distinguishable after the fact.

What you receive

An immutable compliance certificate, a comprehensive deficiency analysis of the assessed system, and the Audit Chain attestation record backing the verdict. Priority remediation support is included with this tier.

Frameworks assessed against

ICOSA is aligned with 31 international AI compliance frameworks, including the EU AI Act, ISO/IEC 42001, and the NIST AI Risk Management Framework.

Pricing

Certification is priced from the assessed system's risk tier under the EU AI Act — minimal, limited, high, or unacceptable — so the fee scales with the scope of the assessment rather than a flat rate. Current pricing, including any active promotion, is shown in the assessment flow below.

Begin your assessment

Complete the observation framework below to begin.

Loading...
AI Compliance AdvisorICOSA
Welcome! I'm your AI compliance advisor. I can help you determine if your AI system needs EU AI Act compliance and what level of certification you need. Are you here to check your compliance requirements?