Enterprise FAQs for registration, certification, repository evidence, physical credentials, and field-ready release.
These answers preserve the operational truth boundaries: registering is not certification, certification is not field readiness, public verification is not restricted access, and a deployed system remains subject to lifecycle governance.
Getting started
3 answers covering the operational handoffs in this lane.
Who should register a system?
The organization legally accountable for the autonomous system or covered equipment should create or use its organization account. An organization owner, administrator, or authorized operator can submit the equipment record. Engineering teams may prepare repositories and evidence, but system intake remains bound to the authenticated organization authority.
Start organization onboardingWhat equipment should be registered?
Register each autonomous system, drone, robot, autonomous vehicle, medical autonomy system, industrial system, or other covered equipment record that requires an independently traceable operational identity. Organizations with multiple devices or models should register every equipment record requiring its own certification, physical credential placement, or lifecycle history.
How does an existing organization register additional equipment?
Authenticated organizations can use the persistent Register system action from any shell-backed page, open the organization portfolio, or go directly to the covered-equipment intake route. Every entry point uses the same central registration authority and appends the same organization-bound portfolio evidence event.
Register additional equipmentRepository and engineering team evidence
4 answers covering the operational handoffs in this lane.
Is there a project template for engineering teams?
Yes. The NASCA certifiable-system starter repository includes the guided manifests, starter runtime boundaries, evidence-pack scripts, audit verification commands, tests, and replacement instructions needed to prepare a system repository without guessing the intake structure. Local checks prove preparation only; they do not issue certification.
Open the starter repository guideWhich source-control providers can be connected?
The intake supports GitHub, GitLab, Bitbucket, Azure DevOps, Gitea, Forgejo, and generic Git repositories. Record the real repository URL, owner, repository name, default branch, visibility, verification method, and evidence use for every source-of-truth repository required for review.
Review repository providersAre private repository URLs exposed publicly?
No. Private and internal repository evidence remains restricted. Public profiles disclose only public-safe trust posture. The organization must still attest that it is authorized to connect each repository for evidence collection and source-change review.
What happens when software or firmware changes after certification?
Material repository, release, firmware, hardware, configuration, or deployment-scope changes must enter repository-change review. The change classification can require operator review, recertification, or an emergency hold. Field-ready status does not bypass lifecycle governance.
Open repository change reviewTesting, payment, and issuance
3 answers covering the operational handoffs in this lane.
Is the Base certification tier free?
No. Every certification tier is paid, including Base. Registration intake may begin before checkout, but NRID, QR materials, seal posture, and certification issuance release only after a persisted passing test and successful paid checkout or an authorized sponsored-waiver receipt.
What happens when a system fails a test?
The failed attempt remains preserved in the testing history. The organization remediates the system, documents the corrected release evidence, and runs the required suites again. Previous failed attempts are not overwritten by a later pass.
Open the testing centerWhy can a certified system still show a deployment hold?
Certification issuance and field deployment are intentionally separate facts. Passing testing and payment can issue the NRID and certification record, but field-ready release remains blocked until the required official QR stickers and certificates are shipped, delivered, installed, evidenced, and independently verified.
Official QR stickers and certificates
4 answers covering the operational handoffs in this lane.
Are official stick-on QR labels and certificates mandatory?
Yes. Each covered equipment record must complete the tracked physical-credential workflow. The organization orders at least one serialized QR sticker and one official certificate, then follows the declared placement plan. Additional quantities should be ordered for models, devices, or locations that require separate physical credentials.
How is shipment custody tracked?
Authorized fulfillment operators verify the restricted mailing address, serialize artifacts, record chain-linked fulfillment events, record masked shipment posture, and confirm delivery. Shipment cannot begin before serialization. Lost, damaged, or invalidated artifacts enter replacement-required handling.
Is the organization mailing address public?
No. Mailing details are restricted. Public verification must not disclose full addresses, full carrier tracking values, private repositories, reviewer identities, or restricted evidence references. Public surfaces receive only approved public-safe projections.
What evidence is required after the QR labels arrive?
Install each serialized QR sticker on the correct registered equipment record and place or retain the certificate according to the display plan. Submit the placement description, restricted photographs or evidence references, installer attestation, and SHA-256 evidence hash for each required artifact.
Field readiness and public verification
3 answers covering the operational handoffs in this lane.
Can the installer approve their own credential placement?
No. The installer cannot approve their own installation. A separate authorized reviewer acquires a time-bounded review lock, checks the equipment binding and evidence, and either approves the placement or records a replacement-required disposition.
What exactly releases field-ready status?
Field-ready status is released only after every required QR-label and certificate placement is independently verified and the NRID physical-mark record is created. A system can be CERTIFIED while still blocked from deployment reliance.
What should a public QR scan show?
The public scan should show a public-safe organization and system profile, certification posture, testing history, QR posture, and deployment eligibility. It must distinguish certification from field readiness and must not leak restricted fulfillment or review evidence.
Open public verificationMulti-system organizations and lifecycle governance
3 answers covering the operational handoffs in this lane.
How are large fleets organized?
The organization profile lists the complete portfolio of registrations and issued systems. Each card opens a protected system-detail page with registration, issuance, NRID, shipment, serialized-artifact, installation-evidence, independent-review, and deployment-eligibility posture.
Open organization portfolioCan organizations brand their public profile?
Yes. Organization owners and administrators can set the public slug, display name, headline, overview, website, public support email, logo, hero image, accent colors, visibility, and disclosure controls. Every published change creates a revisioned hash-chained evidence record.
What happens if a QR label is damaged, lost, or replaced?
The artifact must enter replacement-required handling. Record the custody disposition, order the replacement, complete shipment tracking, reinstall the correct serialized artifact, submit new evidence, and complete independent verification again before relying on the replacement placement.
Auditability, privacy, and oversight
3 answers covering the operational handoffs in this lane.
What makes the workflow court defensible?
The workflow preserves authenticated actors, organization scope, manufacturer-bound system identity, hash-chained portfolio and fulfillment events, SHA-256 evidence hashes, serialized artifacts, shipment custody, installer attestations, independent review locks, immutable testing attempts, and exportable evidence packages. Public data is projected separately from restricted evidence.
How do auditors or law enforcement request access?
Auditors and law-enforcement personnel use the credential-access governance intake. Access is purpose-bound and scope-limited. Public verification does not grant restricted operational access.
Request oversight credentialsCan an organization export the workflow evidence?
Yes. The system supports custody evidence-package export for the physical-credential workflow and broader audit export routes for persisted evidence. Exported evidence should be retained according to the organization's legal, compliance, and incident-response obligations.
Open audit export