Transparency
Make evidence sources, applicable versions, improvement status and complaint outcomes reasonably available for public review.
From Static Certificates to Continuous Conformity
GCCR brings certificates, product tests, regulatory declarations, second-party audits, professional reviews, improvement records and official evidence into one continuously updated, publicly verifiable conformity registry.
We do not only ask whether an organization once held a certificate. We ask whether its organization, product or service continues to meet the applicable requirements today.
Search published records by organization, certificate, product or service name.
Certificates are evidence. Continuous conformity is the goal. GCCR helps organizations publish evidence, versions, improvements and review status in a form the public can understand and verify.
Make evidence sources, applicable versions, improvement status and complaint outcomes reasonably available for public review.
Apply consistent rules regardless of company size, country, certification provider, adviser or commercial relationship.
Lower the cost of credible conformity evidence for smaller businesses, non-profits, open-source projects and new ventures.
Keep every review traceable to a professional identity, method, scope, qualification and supporting evidence.
Look beyond document existence to evidence quality, implementation, corrective action and continuing effectiveness.
Let organizations, customers, suppliers, researchers, professionals and the public contribute evidence or raise concerns under clear rules.
Compliance should not be controlled only by a small number of institutions. It should be transparent, verifiable and open to professional participation.
People with relevant knowledge, experience or qualifications may participate in evidence submission, second-party audits, technical checks, document reviews, improvement verification or complaint investigations under GCCR rules.
Each level builds on the evidence and transparency requirements of the level before it.
Self-Declaration + Second-Party or Professional Evidence
Designed for SMEs, start-ups, open-source projects, non-profits and supply-chain assessments.
Level 1 + Certification Body or Independent Third-Party Evidence
A certificate does not automatically prove that every requirement continues to be met.
Level 2 + IAF, IEC, IATF, Government or Official Recognition
Level 3 confirms traceability; GCCR does not replace an official or accreditation authority.
| Requirement | Level 1 | Level 2 | Level 3 |
|---|---|---|---|
| Self-declaration | Required | Required | Required |
| Published implementation evidence | Required | Required | Required |
| Second-party or professional review | Required | Required | Required |
| CB or independent third-party evidence | Optional | Required | Required |
| Official or accreditation traceability | Optional | Optional | Required |
| Version, improvement and complaint status | Required | Required | Required |
| Continuous conformity updates | Required | Required | Required |
GCCR can connect formal certificates with declarations, technical records, operating evidence and verified improvements.
ISO and IEC certificates, product certificates, management-system certificates and official registrations.
Self-declarations, supplier declarations, EU declarations of conformity and regulatory declarations.
Second-party, internal, certification and customer audits, professional reviews and controlled AI-assisted reviews.
Test reports, penetration tests, SBOMs, vulnerability scans, source analysis, threat models and risk assessments.
Training, monitoring, patching, recovery tests, incident handling and supplier assessment records.
Nonconformities, corrective and preventive actions, root-cause analysis, plans and closure verification.
Define scope, requirements and responsibility.
Provide certificates, reports and operating records.
Use second-party, professional, CB or official review.
Show status, versions, summaries and limitations.
Track risks, complaints and corrective actions.
Refresh evidence and reconfirm conformity.
A GCCR registration is not permanent. Material changes to a product version, scope, supplier, regulation, certificate status or risk require updated evidence and renewed confirmation.
Sensitive information, trade secrets and personal data may be protected, while dates, scope, hashes, evidence summaries and verification results remain visible enough to support the published conclusion.
Publishing an issue does not automatically mean an organization is nonconforming. Open disclosure, corrective action and closure evidence often reveal more than a certificate alone.
Customers, employees, suppliers, researchers, professionals and the public may challenge a registry record or provide additional evidence. Personal data, trade secrets and unverified harmful allegations must not be published.
ISO, IEC, IATF, SOC, product certifications and government documents are important GCCR evidence sources. GCCR also examines the current version, actual scope, material changes, unresolved complaints, technical validity and improvement status.
Support every material claim with appropriate evidence.
Identify the source, date, scope and provider of evidence.
Connect conformity to a defined product, system, document or standard version.
Require reviewers and evidence providers to disclose conflicts.
Give challenged organizations a reasonable opportunity to respond and appeal.
Encourage disclosure, corrective action and renewed verification.
Match review depth to risk, scale and intended use.
Preserve significant changes, withdrawals, suspensions and improvements.
GCCR brings certificates, declarations, assessment reports, technical evidence, improvements and public oversight into one traceable conformity profile.
GCCR does not replace ISO, IEC, IATF, IAF, standards organizations, accreditation bodies, certification bodies, regulators or government authorities. Evidence remains attributable to its original issuer, reviewer or official source.
GCCR is an independent, non-profit information initiative. Registry results support due diligence by adding evidence, version, improvement, complaint and continuing-status context; they do not replace confirmation with the responsible authority.
Explore the purpose and typical focus of the ISO and ISO/IEC standards represented in the registry. This library will continue to expand as new standards and evidence categories are added.
Defines requirements for an information security management system (ISMS), helping organizations manage risks to the confidentiality, integrity and availability of information.
Establishes requirements and guidance for a privacy information management system (PIMS), supporting organizations acting as controllers or processors of personally identifiable information.
Provides cloud-specific information security controls and implementation guidance for both cloud service providers and cloud service customers.
Offers guidance for protecting personally identifiable information in public cloud services when the cloud provider acts as a PII processor.
Provides principles, a framework and a process for managing uncertainty and risk across strategy, operations, projects and organizational decision-making.
Specifies requirements for an AI management system (AIMS), enabling organizations to govern AI risks, opportunities, transparency and responsible use.
Defines quality management system requirements that help organizations consistently meet customer and regulatory needs while improving processes and customer satisfaction.
Sets quality management system requirements for organizations involved in medical device design, production and related services, with strong regulatory and risk-management emphasis.
Specifies requirements for an environmental management system (EMS), helping organizations manage impacts, meet obligations and improve environmental performance.
Send a question about a database record, technical issue or general enquiry. Our team will review your message and respond by email.