Skip to main content
Public verificationCheck certification and field status without entering a restricted workspace.
Independent reviewCertification decisions remain tied to reviewable evidence and accountable personnel.
Protected recordsSensitive evidence stays separated from the public trust view.
NASCA end-to-end engineering team and organization guide

How to register, certify, physically label, verify, and maintain an autonomous system.

Use this operating map before public deployment. It covers account creation, organization authority, repository evidence, equipment registration, testing, paid certification, NRID issuance, official QR-label and certificate ordering, serialized shipment custody, installation evidence, independent verification, field-ready release, public lookup, and lifecycle change control.

Maintain repository-change review, recertification, incident, and replacement custody after release.

Registration is not certification

Submitting an equipment record creates an auditable intake authority. It does not claim a passing test, successful payment, or certification issuance.

Certification is not field-ready release

Field-ready status requires independent physical-placement verification. NRID and certification issuance remain distinct from physical QR-label and certificate installation. Deployment reliance stays blocked until independent placement verification completes.

Public verification is not restricted access

Public registry and QR pages disclose approved trust posture only. Restricted mailing, repository, shipment, evidence, and reviewer records stay protected.

Field-ready release is not permanent immunity

Material changes, incidents, credential replacements, and deployment-scope changes continue through lifecycle review, recertification, or emergency hold when required.

Prepare before intake

Pre-requisites and evidence requirements

Project-template instructions

Organization authority

Identify who is legally accountable before intake begins.

  • Legal organization name, operating jurisdiction, accountable owner, and authorized organization administrator
  • Primary operator name and email for system-bound notices and approval actions
  • Internal approval to register each autonomous system, drone, vehicle, robot, or covered equipment record
  • A mailing contact authorized to receive official credential shipments

System identity

Prepare one manufacturer-bound record for each equipment item or model that will be relied on operationally.

  • System or equipment name, category, manufacturer legal name, model identity, and serial number
  • Primary operation country and intended public-impact use
  • Operational Design Domain boundaries, prohibited conditions, safety-zone behavior, and human-override posture
  • A list of every model, device, or equipment record requiring its own official QR sticker and certificate display plan

Repository and evidence readiness

Link the real source-of-truth repositories used to build, govern, and operate the system.

  • Repository provider, URL, owner, project name, default branch, visibility, verification method, and evidence purpose
  • Authorization to connect private or internal repositories for restricted review
  • Safety case, repeatable test plan, telemetry contract, incident-response plan, repository-change policy, and evidence index
  • Commit or release references that identify the version submitted for certification testing

Fulfillment and placement readiness

Certification issuance is not the end of onboarding. Plan physical credential delivery and installation before deployment.

  • Secure mailing address for official certificates and serialized stick-on QR labels
  • QR placement location for each covered equipment record and certificate-display location
  • Authorized installer identity and a separate independent reviewer identity
  • Evidence capture method for installation photographs, restricted references, and SHA-256 integrity hashes
Engineering team project template

Start from the NASCA certifiable-system repository instead of discovering requirements during review.

The downloadable starter repository includes guided manifests, starter runtime boundaries, tests, replacement instructions, evidence-pack tooling, and local preflight commands. Replace instructional values with real project evidence. Local execution proves preparation only; NASCA certification issues only from the live authority workflow.

npm test
npm run template:inspect
npm run source:manifest
npm run source:verify
npm run certification:preflight
npm run evidence:generate
npm run audit:verify
npm run registration:payload
01
Identity and authority

Account and authority: create the account and establish the accountable organization

Begin with a verified account and an organization-bound authority record. Every later action must resolve to an authenticated actor and organization scope.

Accountable ownerOrganization owner or authorized organization administrator

Required actions

  1. Create the registry account or sign in to the existing organization account.
  2. Complete required account security, identity verification, and password rotation when prompted.
  3. Enter the legal organization, operator, jurisdiction, and notification contacts.
  4. Confirm which users may act as owner, administrator, engineering team, operator, compliance reviewer, auditor, or viewer.

Evidence retained

  • Authenticated account
  • Organization application record
  • Role-scoped membership
  • Accountable operator contact
Completion gateAn organization-bound authenticated session exists and the accountable organization record is ready for system intake.
Sign up or sign in
02
Engineering team preparation

Download the project template and map the certification requirements into the repository

The starter repository gives engineering teams a complete evidence structure before live intake. It prevents teams from discovering required manifests only after review begins.

Accountable ownerLead engineering team, safety engineer, and compliance owner

Required actions

  1. Download the NASCA certifiable-system starter repository.
  2. Read the replacement map and replace instructional values with project-specific evidence.
  3. Document system identity, ODD boundaries, human override, telemetry, incident response, public disclosure posture, repository-change review, and the evidence index.
  4. Run the included local structure, integrity, preflight, evidence-pack, audit, and registration-payload commands.

Evidence retained

  • Certification manifests
  • Safety-case evidence
  • Repository-change policy
  • Local preflight output
Completion gateThe repository contains project-specific evidence and passes its preparation checks. Local preflight does not claim NASCA certification.
Open project template guide
03
Covered equipment intake

Register every autonomous system, drone, vehicle, robot, or covered equipment record

An organization may own many systems. Each covered equipment record enters the same central registration authority and appears in the organization portfolio.

Accountable ownerOrganization owner, administrator, or operator

Required actions

  1. Open organization onboarding for the first system or use Register system from the logged-in shell for additional equipment.
  2. Record the manufacturer-bound identity, category, serial number, primary country, and public-safe summary.
  3. Declare planned public-impact operation and the required physical-credential workflow.
  4. Repeat the intake for every covered model or equipment item that must be independently tracked.

Evidence retained

  • System registration public ID
  • Organization portfolio event
  • Manufacturer identity
  • Public-operation acknowledgement
Completion gateThe equipment record is committed to the organization portfolio and opens from its protected system-detail page.
Register a system
04
Source provenance

Connect the repositories used to build, test, release, and govern the system

NASCA review depends on verifiable source provenance. Repository evidence stays provider-neutral and private URLs remain redacted from public registry views.

Accountable ownerEngineering team or organization authority permitted to bind repository evidence

Required actions

  1. Connect GitHub, GitLab, Bitbucket, Azure DevOps, Gitea, Forgejo, or generic Git repositories.
  2. Record the real URL, owner, repository name, default branch, visibility, verification method, and evidence use.
  3. Confirm the organization is authorized to connect each repository.
  4. Attach every repository used for software, firmware, safety-case, test, deployment, and evidence custody when they are separated.

Evidence retained

  • Provider-neutral repository linkage
  • Ownership attestation
  • Verification posture
  • Restricted repository evidence
Completion gateThe registration package identifies the repositories required for review and source-change custody.
Review repository linkage
05
Public trust profile

Configure organization branding and public-safe disclosures

The public should be able to identify the responsible organization and verify approved trust facts without receiving restricted operational evidence.

Accountable ownerOrganization owner or administrator

Required actions

  1. Set the organization public slug, display name, headline, overview, website, public support email, logo, hero image, and brand colors.
  2. Choose public, unlisted, or private visibility.
  3. Choose whether public pages show system inventory, certification summary, and field-readiness posture.
  4. Publish the revision and retain the evidence hash and revision chain.

Evidence retained

  • Organization public-profile revision
  • Snapshot hash
  • Revision-chain hash
  • Public-safe projection
Completion gateThe organization profile is published according to the selected disclosure posture without exposing restricted records.
Open organization portfolio
06
Testing-center readiness

Prepare the system-bound testing plan and submitted release version

Testing must be bound to the registered system and the release evidence under review. The test plan should prove the public-impact controls claimed during intake.

Accountable ownerEngineering team, safety engineer, and organization testing operator

Required actions

  1. Confirm the exact repository version, firmware release, configuration, and evidence pack entering testing.
  2. Review ODD limits, prohibited conditions, human override, emergency stop, telemetry integrity, incident response, and applicable safety lanes.
  3. Schedule or enter the organization trust testing center and execute the required suites.
  4. Preserve failed attempts, remediation notes, reruns, and passing outcomes as separate auditable records.

Evidence retained

  • System-bound test attempt
  • Execution evidence
  • Pass/fail history
  • Custody hashes
Completion gateThe required testing suites have a persisted passing outcome for the submitted system version.
Open organization testing center
07
Certification checkout

Select the certification tier and complete verified payment

Every certification tier is paid, including Base. Payment and testing must both succeed before issuance releases the NRID, QR code, and NASCA seal posture.

Accountable ownerAuthorized organization billing contact

Required actions

  1. Choose Base or a higher certification tier and the billing cycle.
  2. Review any support-code or affiliate attribution disclosures before checkout.
  3. Accept the court-defensible certification terms.
  4. Complete secure checkout or a validated sponsored-waiver receipt when an authorized program applies.

Evidence retained

  • Selected paid tier
  • Checkout receipt
  • Payment verification
  • Commercial attribution evidence when applicable
Completion gateThe system has a persisted passing test and a successful paid or authorized sponsored-waiver checkout posture.
Review certification tiers
08
Certification issuance

Receive the NRID, digital QR materials, seal posture, and issuance proof

Certification issuance proves that the required decision gates completed. It does not yet prove that the equipment is ready for field deployment.

Accountable ownerNASCA issuance authority and organization operator

Required actions

  1. Open the issuance workspace after successful testing and payment.
  2. Review the NRID, downloadable QR materials, seal posture, certification record, and deployment-eligibility hold.
  3. Download digital materials for records and internal preparation.
  4. Acknowledge that official mailed copies and verified placement remain mandatory before field-ready release.

Evidence retained

  • NRID issuance
  • Digital QR material
  • Certification record
  • Deployment hold
Completion gateCertification is issued, but the system remains blocked from field-ready reliance until physical credentials are verified.
09
Official credential order

Order serialized QR stickers and official certificates for the equipment

Every covered equipment record must display official QR materials and certificate information according to its placement plan.

Accountable ownerOrganization operator and authorized fulfillment contact

Required actions

  1. Acknowledge the QR-label placement plan and certificate-display location.
  2. Enter the restricted mailing address for official copies.
  3. Order at least one serialized stick-on QR label and one official certificate for the registered equipment record.
  4. Order the correct quantities for every model, device, or display location requiring an official physical credential.

Evidence retained

  • Physical-credential workflow
  • Placement-plan acknowledgement
  • Official copy order
  • Restricted address hash
Completion gateThe official copy order is accepted with the minimum required QR-label and certificate quantities.
10
Fulfillment custody

Track production, serialization, shipment, and delivery custody

Physical credentials require a traceable custody trail from production through delivery. Shipment cannot begin before the artifacts are serialized.

Accountable ownerAuthorized NASCA fulfillment operator

Required actions

  1. Verify the restricted mailing address and queue production.
  2. Serialize each official QR sticker and certificate artifact.
  3. Record fulfillment events, carrier posture, masked tracking information, shipment custody, and delivery confirmation.
  4. Use replacement-required handling when artifacts are lost, damaged, or invalidated.

Evidence retained

  • Serialized artifact ledger
  • Chain-linked fulfillment events
  • Shipment posture
  • Delivery confirmation
Completion gateThe organization has received the tracked official QR stickers and certificates for installation.
11
Equipment placement

Install the physical credentials and submit placement evidence

The QR label must be visibly bound to the correct equipment. The certificate must be displayed or retained according to the declared plan.

Accountable ownerAuthorized organization installer

Required actions

  1. Install each serialized QR sticker on the correct registered model, device, or equipment record.
  2. Place or retain the official certificate according to the display plan.
  3. Submit restricted installation photographs or evidence references, the placement description, installer attestation, and SHA-256 evidence hash.
  4. Do not treat uploaded evidence as self-approval. The installer cannot verify their own installation.

Evidence retained

  • Installation record
  • Restricted evidence reference
  • SHA-256 evidence hash
  • Installer attestation
Completion gatePlacement evidence exists for every required physical credential artifact and awaits independent review.
12
Independent review

Complete independent placement verification and release field-ready status

A separate reviewer must validate the installation evidence. A time-bounded review lock prevents collisions and preserves operator accountability.

Accountable ownerIndependent authorized reviewer

Required actions

  1. Acquire the review lock for the physical-credential workflow.
  2. Confirm the QR artifact, certificate artifact, placement location, evidence hash, installer attestation, and correct equipment binding.
  3. Approve valid placement or mark replacement required with an auditable disposition.
  4. Verify that the NRID physical-mark record is created and every required placement is independently approved.

Evidence retained

  • Independent reviewer disposition
  • Collision-safe review lock
  • NRID physical-mark record
  • Field-ready release event
Completion gateThe system is marked field-ready only after every required physical placement passes independent verification.
13
Public reliance

Verify the field-ready posture through the public registry and QR lookup

Certification and field readiness remain separate public facts. A public scan should never imply deployment eligibility when physical placement verification is incomplete.

Accountable ownerOrganization, customer, inspector, auditor, or member of the public

Required actions

  1. Open the public registry or scan the official QR sticker.
  2. Confirm the organization public profile, system identity, certification status, testing history, QR posture, and deployment eligibility.
  3. Treat certification-issued but not field-ready status as a deployment hold.
  4. Escalate discrepancies through the applicable support, audit, or enforcement channel.

Evidence retained

  • Public registry record
  • Public QR lookup
  • Testing-history disclosure
  • Field-readiness posture
Completion gateThe system can be independently verified by the public without exposing restricted custody evidence.
Verify a system
14
Lifecycle control

Lifecycle change control: maintain repository-change review, recertification, incident, and replacement custody after release

Field-ready release is not a permanent exemption. Material software, firmware, hardware, ownership, placement, or incident changes must remain auditable.

Accountable ownerOrganization owner, engineering team, compliance reviewer, and NASCA operator as applicable

Required actions

  1. Submit material repository and release changes through repository-change review.
  2. Trigger operator review, recertification, or emergency hold when the change classification requires it.
  3. Record incidents, credential replacements, lost labels, damaged labels, ownership changes, and deployment-scope changes.
  4. Export evidence packs and preserve lifecycle custody for audit, enforcement, and court-defensible review.

Evidence retained

  • Repository-change review
  • Recertification posture
  • Replacement custody
  • Evidence-pack export
Completion gateThe deployed system remains traceable, reviewable, and current throughout its operational lifecycle.
Open repository change review
Ready to move through the authority flow

Keep the registration guide open while the team completes intake.

The FAQ page answers enterprise implementation questions. The starter repository gives engineering teams a concrete replacement map before source linkage begins.