GCCR Global Conformity and Compliance Registry logo Global Conformity & Compliance Registry
GCCR

Global Conformity & Compliance Registry

From Static Certificates to Continuous Conformity

GCCR brings certificates, product tests, regulatory declarations, second-party audits, professional reviews, improvement records and official evidence into one continuously updated, publicly verifiable conformity registry.

We do not only ask whether an organization once held a certificate. We ask whether its organization, product or service continues to meet the applicable requirements today.

Public Registry Search

Search certificates and conformity records

Search published records by organization, certificate, product or service name.

Our Mission

Make conformity transparent, fair and continuously verifiable

Certificates are evidence. Continuous conformity is the goal. GCCR helps organizations publish evidence, versions, improvements and review status in a form the public can understand and verify.

Transparency

Make evidence sources, applicable versions, improvement status and complaint outcomes reasonably available for public review.

Fairness

Apply consistent rules regardless of company size, country, certification provider, adviser or commercial relationship.

Accessibility

Lower the cost of credible conformity evidence for smaller businesses, non-profits, open-source projects and new ventures.

Professionalism

Keep every review traceable to a professional identity, method, scope, qualification and supporting evidence.

Quality

Look beyond document existence to evidence quality, implementation, corrective action and continuing effectiveness.

Public Participation

Let organizations, customers, suppliers, researchers, professionals and the public contribute evidence or raise concerns under clear rules.

Compliance should not be controlled only by a small number of institutions. It should be transparent, verifiable and open to professional participation.
Open Professional Participation

Qualified professionals can contribute

People with relevant knowledge, experience or qualifications may participate in evidence submission, second-party audits, technical checks, document reviews, improvement verification or complaint investigations under GCCR rules.

  • ISO lead and internal auditors
  • Information security professionals
  • Privacy and data protection specialists
  • Software, firmware and hardware engineers
  • Testing laboratory personnel
  • Regulatory and product compliance specialists
  • Quality management professionals
  • Supply-chain auditors
  • Industry domain experts
  • Academic and professional community members
Apply as a GCCR Professional
GCCR Assurance Levels

Three levels of traceable conformity evidence

Each level builds on the evidence and transparency requirements of the level before it.

01GCCR Level 1

Open Evidence

Self-Declaration + Second-Party or Professional Evidence

  • Defined scope and applicable requirements
  • Current version and implementation evidence
  • Professional or second-party review
  • Published improvements and complaint response
  • Periodic conformity updates

Designed for SMEs, start-ups, open-source projects, non-profits and supply-chain assessments.

02GCCR Level 2

Certified Evidence

Level 1 + Certification Body or Independent Third-Party Evidence

  • All Level 1 requirements
  • ISO or product certificates
  • Third-party audit or laboratory reports
  • SOC, security, privacy or assurance reports
  • Certificate scope, validity and status tracking

A certificate does not automatically prove that every requirement continues to be met.

03GCCR Level 3

Accredited or Official Evidence

Level 2 + IAF, IEC, IATF, Government or Official Recognition

  • All Level 1 and Level 2 requirements
  • Traceability to an accreditation or official scheme
  • IAF MLA, IEC, IECEE, IECEx or IATF evidence
  • Government, notified body or national AB evidence
  • Continuing status and historical integrity

Level 3 confirms traceability; GCCR does not replace an official or accreditation authority.

GCCR assurance level comparison
RequirementLevel 1Level 2Level 3
Self-declarationRequiredRequiredRequired
Published implementation evidenceRequiredRequiredRequired
Second-party or professional reviewRequiredRequiredRequired
CB or independent third-party evidenceOptionalRequiredRequired
Official or accreditation traceabilityOptionalOptionalRequired
Version, improvement and complaint statusRequiredRequiredRequired
Continuous conformity updatesRequiredRequiredRequired
Conformity Evidence

Certificates are one part of a wider evidence system

GCCR can connect formal certificates with declarations, technical records, operating evidence and verified improvements.

Certificates

ISO and IEC certificates, product certificates, management-system certificates and official registrations.

Declarations

Self-declarations, supplier declarations, EU declarations of conformity and regulatory declarations.

Audit and Assessment

Second-party, internal, certification and customer audits, professional reviews and controlled AI-assisted reviews.

Technical Evidence

Test reports, penetration tests, SBOMs, vulnerability scans, source analysis, threat models and risk assessments.

Operational Evidence

Training, monitoring, patching, recovery tests, incident handling and supplier assessment records.

Improvement Evidence

Nonconformities, corrective and preventive actions, root-cause analysis, plans and closure verification.

Certificates are evidence. Continuous conformity is the goal.
Continuous Conformity Lifecycle

Evidence must stay current as organizations and products change

  1. 1

    Declare

    Define scope, requirements and responsibility.

  2. 2

    Submit Evidence

    Provide certificates, reports and operating records.

  3. 3

    Review

    Use second-party, professional, CB or official review.

  4. 4

    Publish

    Show status, versions, summaries and limitations.

  5. 5

    Improve

    Track risks, complaints and corrective actions.

  6. 6

    Revalidate

    Refresh evidence and reconfirm conformity.

A GCCR registration is not permanent. Material changes to a product version, scope, supplier, regulation, certificate status or risk require updated evidence and renewed confirmation.

What GCCR Makes Visible

A registry profile that supports informed decisions

Sensitive information, trade secrets and personal data may be protected, while dates, scope, hashes, evidence summaries and verification results remain visible enough to support the published conclusion.

Organization and product or serviceRegistered scope Applicable standard or regulationGCCR level Current versionDeclaration owner and reviewer Evidence and certification providerAccreditation body Certificate number and validityEvidence and update dates Next review dateOpen nonconformities Closed improvementsComplaint response status Vulnerability statusHistorical changes
Improvement Status

Transparent improvement is evidence of maturity

Publishing an issue does not automatically mean an organization is nonconforming. Open disclosure, corrective action and closure evidence often reveal more than a certificate alone.

OpenUnder ReviewCorrective Action in ProgressEvidence SubmittedVerifiedClosedOverdueDisputed
Improvement GCCR-2026-0710Verified
Issue
Outdated dependency identified
Severity
Medium
Detected
2026-07-10
Corrective Action
Upgrade dependency and repeat security scan
Closed
2026-07-18
Verified By
GCCR Professional Reviewer
Complaints and Public Oversight

A fair process for evidence, response and appeal

Customers, employees, suppliers, researchers, professionals and the public may challenge a registry record or provide additional evidence. Personal data, trade secrets and unverified harmful allegations must not be published.

  1. Submit Complaint
  2. Identity and Evidence Check
  3. Notify Organization
  4. Organization Response
  5. Independent Review
  6. Decision and Corrective Action
  7. Publish Status
  8. Appeal
Certificates Are Evidence, Not the Entire Story

A valid certificate is important, but continuing evidence provides context

ISO, IEC, IATF, SOC, product certifications and government documents are important GCCR evidence sources. GCCR also examines the current version, actual scope, material changes, unresolved complaints, technical validity and improvement status.

Certificate + Evidence + Version + Improvement + Complaints + Continuous Review = GCCR
GCCR Trust Principles

A transparent framework for evidence and accountability

01

Evidence before claims

Support every material claim with appropriate evidence.

02

Traceability

Identify the source, date, scope and provider of evidence.

03

Version awareness

Connect conformity to a defined product, system, document or standard version.

04

Conflict-of-interest disclosure

Require reviewers and evidence providers to disclose conflicts.

05

Right to respond

Give challenged organizations a reasonable opportunity to respond and appeal.

06

Continuous improvement

Encourage disclosure, corrective action and renewed verification.

07

Proportional assurance

Match review depth to risk, scale and intended use.

08

Historical integrity

Preserve significant changes, withdrawals, suspensions and improvements.

About GCCR

An independent evidence registry and transparency framework

GCCR brings certificates, declarations, assessment reports, technical evidence, improvements and public oversight into one traceable conformity profile.

GCCR does not replace ISO, IEC, IATF, IAF, standards organizations, accreditation bodies, certification bodies, regulators or government authorities. Evidence remains attributable to its original issuer, reviewer or official source.

GCCR is an independent, non-profit information initiative. Registry results support due diligence by adding evidence, version, improvement, complaint and continuing-status context; they do not replace confirmation with the responsible authority.

Traceable verificationSearch published records and review their evidence source and scope.
Responsible referenceUse results as one input to a complete supplier, product or compliance review.
Continuous perspectiveConnect certificates with versions, changes, improvements and ongoing review.
International Standards Library

Understand the standards behind conformity evidence

Explore the purpose and typical focus of the ISO and ISO/IEC standards represented in the registry. This library will continue to expand as new standards and evidence categories are added.

Information security

ISO/IEC 27001

Defines requirements for an information security management system (ISMS), helping organizations manage risks to the confidentiality, integrity and availability of information.

ISMSRisk controlsCyber resilience
Privacy management

ISO/IEC 27701

Establishes requirements and guidance for a privacy information management system (PIMS), supporting organizations acting as controllers or processors of personally identifiable information.

PIMSPII governanceAccountability
Cloud security

ISO/IEC 27017

Provides cloud-specific information security controls and implementation guidance for both cloud service providers and cloud service customers.

Cloud controlsShared rolesSecure services
Cloud privacy

ISO/IEC 27018

Offers guidance for protecting personally identifiable information in public cloud services when the cloud provider acts as a PII processor.

Cloud PIITransparencyPrivacy controls
Risk management

ISO 31000

Provides principles, a framework and a process for managing uncertainty and risk across strategy, operations, projects and organizational decision-making.

Risk frameworkDecisionsResilience
Artificial intelligence

ISO/IEC 42001

Specifies requirements for an AI management system (AIMS), enabling organizations to govern AI risks, opportunities, transparency and responsible use.

AIMSAI governanceResponsible AI
Quality management

ISO 9001

Defines quality management system requirements that help organizations consistently meet customer and regulatory needs while improving processes and customer satisfaction.

QMSCustomer focusImprovement
Medical devices

ISO 13485

Sets quality management system requirements for organizations involved in medical device design, production and related services, with strong regulatory and risk-management emphasis.

Medical QMSSafetyRegulatory needs
Environmental management

ISO 14001

Specifies requirements for an environmental management system (EMS), helping organizations manage impacts, meet obligations and improve environmental performance.

EMSEnvironmental impactCompliance
Contact

How can we help?

Send a question about a database record, technical issue or general enquiry. Our team will review your message and respond by email.

Enter at least 2 characters.

Four-digit image verification code

Enter the four digits shown in the image.

Do not include passwords, payment details or other sensitive information.