Register 09 · Compliance controls

C-SCRM.

C-SCRM is a provenance standard: it cares about where an artifact came from and whether the chain is unbroken. Planisphere's evidence record can preserve sha-pinned, Merkle-rooted provenance in the format C-SCRM expects for review.

register 09 · Compliance controls· Supply-chain / provenance standard

Reviewed 2026-07-08

01 ·

What this is.

Seventy-two regulatory cite-anchors, organized for evidence lookup and review

Use. supply-chain risk · NIST SP 800-161r1.

Register. 09 · Compliance controls — one of the 17 registers of the PLANiSPHERE corpus library.

02 ·

See it work.

Evidence record you can check — not code you have to trust.

Planisphere measures your tool deployment against C-SCRM and seals the result into a signed, Merkle-rooted evidence record. The grade recomputes on your own hardware; the model state never crosses the boundary.

03 ·

Promise. compliance

The contract this mark binds — derived, not asserted.

C-SCRM is a provenance standard: it cares about where an artifact came from and whether the chain is unbroken. Planisphere's evidence record can preserve sha-pinned, Merkle-rooted provenance in the format C-SCRM expects for review.

Answers: How does a Planisphere evidence record support C-SCRM review?

04 ·

Where this provenance chain ships.

Related marks, and the surface this one funnels to.

C-SCRM (supply-chain risk · NIST SP 800-161r1) asks for an evidence record: C-SCRM is a provenance standard: it cares about where an artifact came from and whether the chain is unbroken. Read the related defense AI workflow product context at /defense.

FIPS 140-3 reg 09 · crypto module validation · 4 security levels SBOM reg 09 · software bill of materials · NTIA + CISA SCITT reg 09 · supply-chain integrity, transparency, trust · IETF SHA-256 / FIPS 180-4 reg 09 · hash algorithm · per-file pinning primitive SLSA v1.0 reg 09 · supply-chain levels for software artifacts
05 ·

Routes here from.

Where this mark is referenced in the Planisphere surface.

Any internal link in the Planisphere site that names "C-SCRM" canonicalises here.

See the record C-SCRM asks for.

The console shows the evidence; the docs show the endpoints; the briefing shows what the product does and does not claim.

API ·

When C-SCRM asks for proof, hand over records — not assurances.

record the duty · seal the receipt · verify offline

Planisphere records each duty event — an output marked, a disclosure shown, a review made — and seals it into a receipt that verifies offline against our published keys. You send hashes, never content. A record is evidence a third party can check; it is not a certification and not a legal determination.

See how a record is checked