Skip to content

Evidence request lists

Sigstore - Software Artifact Signing and Verification

Evidence request list. 17 controls, 17 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Cosign

SIGSTORE-3
Sigstore for Containers and Artifacts (Cosign)

Per Sigstore Cosign: sign + verify container images + OCI artifacts. Integrate with admission control + supply chain security.

Artefacts an auditor will ask for
  • Sigstore evidence for SIGSTORE-3
Where this commonly fails
  • adoption + private deployment partial

Keyless Signing

SIGSTORE-1
Keyless Signing with Short-Lived Certificates

Per Sigstore: keyless signing. Requirements include (a) Keyless Signing With Short-Lived Certificates via Fulcio + (b) OIDC identity-based signing + (c) Certificate Transparency Monitoring + (d) Reusable Workflow and Pipeline Hardening + (e) maintain Sigstore client integration.

Artefacts an auditor will ask for
  • Sigstore evidence for SIGSTORE-1
Where this commonly fails
  • adoption + private deployment partial

Private Deployment

SIGSTORE-4
Private Deployment, Long-Lived Migration, Regulated Environments

Per Sigstore: private deployment + migration. Requirements include (a) Private Sigstore Deployment for Regulated Environments + (b) Long-Lived Key Migration and Sunset + (c) operate enterprise-internal Sigstore.

Artefacts an auditor will ask for
  • Sigstore evidence for SIGSTORE-4
Where this commonly fails
  • adoption + private deployment partial

Sigstore: Cosign Signing and Storage

SIGSTORE-COS-1
Keyless Signing

Support identity-based keyless signing using Fulcio certificates and Rekor transparency log by default

Artefacts an auditor will ask for
  • Cosign deployment documentation
  • OIDC identity provider integration
  • ephemeral key procedures
  • signing pipeline records
Where this commonly fails
  • no OIDC integration
  • long-lived keys persisting
  • no signing in CI/CD
SIGSTORE-COS-2
Key-Based Signing

Support signing with hardware tokens, KMS systems, or cosign-generated encrypted key pairs

Artefacts an auditor will ask for
  • key generation procedures
  • key storage documentation
  • key rotation records
  • signing pipeline integration
Where this commonly fails
  • weak key storage
  • no rotation
  • no HSM use
SIGSTORE-COS-3
OCI Registry Storage

Store signatures and attestations in OCI-compliant registries alongside container images

Artefacts an auditor will ask for
  • OCI registry configuration
  • signature attachment procedures
  • registry access controls
  • retention policy
Where this commonly fails
  • signatures not stored alongside artifacts
  • weak access controls
  • no retention policy
SIGSTORE-COS-4
Signature Verification

Verify signed artifacts using timestamps and short-lived certificate validity windows

Artefacts an auditor will ask for
  • verification policies
  • admission controller configurations
  • verification logs
  • policy bundle records
Where this commonly fails
  • no admission controller
  • weak verification policies
  • missing logs

Sigstore: Fulcio Certificate Authority

SIGSTORE-FUL-1
Short-Lived Certificate Issuance

Issue short-lived certificates binding ephemeral keys to OpenID Connect identities

Artefacts an auditor will ask for
  • Fulcio integration records
  • ephemeral certificate logs
  • lifetime policy documentation
  • monitoring records
Where this commonly fails
  • overly long certificate lifetimes
  • no Fulcio integration
  • weak monitoring
SIGSTORE-FUL-2
Identity Binding

Bind signer identity from OIDC provider to certificate for attributable signing without long-lived keys

Artefacts an auditor will ask for
  • OIDC provider integration
  • identity claim documentation
  • binding verification records
  • policy mapping
Where this commonly fails
  • weak identity mapping
  • no policy enforcement on identity claims
  • missing audit
SIGSTORE-FUL-3
Certificate Transparency

Log all issued certificates to certificate transparency logs for auditability

Artefacts an auditor will ask for
  • CT log monitoring records
  • SCT verification procedures
  • log inclusion proofs
  • audit records
Where this commonly fails
  • no CT monitoring
  • weak SCT verification
  • missing inclusion proofs

Sigstore: Rekor Transparency Log

SIGSTORE-REK-1
Signature Transparency Logging

Log all signing events in immutable transparency log providing auditable record of signature creation

Artefacts an auditor will ask for
  • Rekor log entries
  • inclusion proof records
  • log monitoring procedures
  • audit records
Where this commonly fails
  • no Rekor logging
  • no inclusion proof verification
  • weak monitoring
SIGSTORE-REK-2
Tamper-Evident Storage

Store entries in append-only Merkle tree providing tamper-evident and verifiable record of signing events

Artefacts an auditor will ask for
  • Merkle tree verification records
  • consistency proof logs
  • monitoring procedures
  • audit reports
Where this commonly fails
  • no consistency proof checks
  • weak monitoring
  • no auditor role
SIGSTORE-REK-3
RESTful API Validation

Provide RESTful API for submission, validation, and querying of transparency log entries

Artefacts an auditor will ask for
  • API integration documentation
  • validation procedures
  • API rate limiting records
  • test results
Where this commonly fails
  • no API integration testing
  • weak rate limiting
  • missing validation

Sigstore: Verification and Policy Enforcement

SIGSTORE-VER-1
Timestamp Verification

Verify signed timestamp in bundle ensuring it falls within certificate issuance time window

Artefacts an auditor will ask for
  • timestamp authority integration
  • timestamp verification records
  • TSA configuration documentation
  • audit logs
Where this commonly fails
  • no TSA integration
  • weak verification
  • no audit
SIGSTORE-VER-2
Supply Chain Attestation

Support in-toto attestation format for software supply chain metadata and provenance verification

Artefacts an auditor will ask for
  • in-toto attestations
  • SLSA framework alignment records
  • provenance documents
  • verification policies
Where this commonly fails
  • no provenance generation
  • weak SLSA alignment
  • missing verification
SIGSTORE-VER-3
Policy Enforcement

Enforce admission policies in container orchestrators to require valid Sigstore signatures before deployment

Artefacts an auditor will ask for
  • policy bundles
  • policy controller configurations
  • enforcement logs
  • policy versioning records
Where this commonly fails
  • no policy bundles
  • weak controller deployment
  • missing versioning

Transparency Log

SIGSTORE-2
Transparency Log (Rekor) and Verification

Per Sigstore: Rekor transparency log. Requirements include (a) record signing events to Rekor + (b) verify signatures + Rekor entries + (c) implement verification policy + (d) integrate with consumers.

Artefacts an auditor will ask for
  • Sigstore evidence for SIGSTORE-2
Where this commonly fails
  • adoption + private deployment partial
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Sigstore - Software Artifact Signing and Verification framework page.