Administration Authority |
An entity authorized by the Governing Body to operate the Compliance Program on its behalf. It is responsible for recognizing and certifying key compliance roles that agree to participate in the program. The C2PA Technical Working Group Conformance Task Force operates in this capacity. |
Applicant |
An entity that has created a Generator Product or Validator Product and wishes to have it recognized as a "Compliant Product" and added to the C2PA Compliant Product List (CPL) under the governance framework of the C2PA Compliance Program. |
Applicant Representative |
A natural person who is an employee or agent formally authorized by the Applicant. |
Assertion |
A data structure used to represent a statement made (or "created") by a signer, or collected at Claim Generation time, about an Asset. This data is part of a C2PA Manifest. |
Asset |
A file or data stream containing digital content, asset metadata, and an optional C2PA Manifest. |
Assurance Level |
An indication to a Relying Party of the degree of confidence that assertions and claims signed using a given C2PA Claim Signing Certificate reflect the intended behavior of the Generator Product instance. A higher Assurance Level means a higher degree of confidence a Relying Party may have. |
Attestation |
The process of providing a digital signature over a set of measurements securely stored in hardware, which is then verified by a requesting party along with the set of measurements. |
C2PA Certificate Policy |
A document specifying the requirements that a Certification Authority (CA) MUST satisfy when issuing digital certificates to Subscribers implementing C2PA-compliant products (used to create assets with digital content and C2PA Manifests), and the requirements that Subscribers MUST satisfy when using such certificates. |
C2PA Claim |
A digitally signed, tamper-evident data structure that references a set of assertions about an Asset and the information needed to characterize content binding. If any assertion has been redacted, a corresponding claim description is included. This data is part of a C2PA Manifest. |
C2PA Claim Signing Certificate |
An X.509 certificate issued by a CA in the C2PA Trust List to a Compliant Generator Product instance of a Conformance Implementer, where the certificate Subject name identifies the Generator Product. |
C2PA Compliance Program |
A risk-based governance program designed to allow Applicants to demonstrate conformance and obtain C2PA recognition by satisfying procedural requirements. The program includes evaluating C2PA-relevant functionality of the Applicant’s products, assessing security attributes to assign a maximum Assurance Level, evaluating the CA’s processes and technical capabilities, and signing legal agreements to join the program. |
C2PA Compliant Product List |
The authoritative record of all Compliant Products recognized as compliant under the C2PA Compliance Program. |
C2PA Content Credentials |
The preferred non-technical term for a C2PA Manifest. Accordingly, a C2PA Manifest store represents the Content Credentials of an Asset.
Content Credentials also refers to the overall C2PA technology and is therefore essentially treated as a plural noun. If a C2PA Manifest is Content Credentials, then multiple C2PA Manifests or the broader, general concept constitute Content Credentials.
|
C2PA Content Credentials Specification |
A globally recognized standard providing content provenance and authenticity for digital assets, designed to enable individuals and organizations to adopt digital provenance technology through a rich ecosystem while satisfying security requirements. |
C2PA Governance Framework |
A set of governance documents defining the C2PA trust ecosystem, including roles, requirements, and processes. |
C2PA Manifest |
A collection of provenance information about an Asset formed from a combination of one or more Assertions (including content binding), a Claim, and a Claim signature. A C2PA Manifest is part of a C2PA Manifest Store. |
C2PA Trust List |
In the context of the Compliance Program, a list of X.509 certificate trust anchors (Root CAs or Subordinate CAs) managed by C2PA, where these CAs issue certificates to Compliant Generator Products in accordance with this C2PA Certificate Policy. |
C2PA TSA Trust List |
A list of trust anchors managed by C2PA from which CAs issue Timestamp signing certificates to Timestamp Authorities (TSAs). |
Certification Authority (CA) |
A trusted entity responsible for issuing, signing, and revoking digital certificates that bind public keys to Subscriber identities. Generator Products use digital certificates issued by a CA to sign C2PA Manifests. |
Compliance Criteria |
A set of normative requirements that C2PA requires Governed Parties to demonstrate compliance with under the Compliance Program, including requirements from the specification itself, the Generator Product Security Requirements document, and the C2PA Certificate Policy. |
Conformance Implementer |
An Applicant that has become a member of the C2PA Compliance Program and has at least one product in good standing in the CPL. |
Compliant Product |
A Generator or Validator Product that has been recognized as compliant by the program and added to the CPL with a status of "conformant." A Compliant Generator Product is assigned a maximum Assurance Level. |
Dynamic Evidence |
Attributes evaluated by the CA during automated certificate enrollment for a Generator Product instance, typically forwarded in the form of verifiable hardware-backed artifacts (e.g., key or platform attestation reports). |
Generator Product |
A collection of software, hardware, and platform configurations created by an Applicant that work together as a system to produce digital assets with C2PA Manifests. The product, acting as the signer, is responsible for whether the assets produced conform to normative requirements. |
Generator Product Security Requirements |
Security-related implementation requirements that a Generator Product must meet in order to achieve a particular maximum Assurance Level. |
Governed Party |
An organization wishing to assume a recognized role in the C2PA Compliance Program. The program requires it to sign legal agreements and undergo review before its products are included in the C2PA Trust List or Compliant Product List. Governed Parties in the C2PA ecosystem include Certification Authorities and Applicants that choose to apply for and comply with the requirements of the C2PA Compliance Program. |
Governance Body |
The organization responsible for the trustworthiness of the ecosystem. It authorizes the Administration Authority to manage the ecosystem and authorizes certification entities to convey trust. C2PA serves as the Governance Body of the Compliance Program, driven by its Steering Committee. |
Hosted Environment |
A server-side environment hosting a subset of the mechanisms and functions of a Generator Product or Validator Product. |
Implementation Category – Back-end |
An implementation architecture for a target of evaluation where assets, assertions, claims, and claim signatures are generated in one or more hosted environments, including instances hosted on-premises or by commercial cloud service providers. |
Implementation Category – Distributed |
An implementation architecture for a target of evaluation consisting of an edge subsystem and a back-end subsystem, where the generation of assets, assertions, claims, and claim signatures is distributed across both types of subsystems. |
Implementation Category – Edge |
An implementation architecture for a target of evaluation where assets, assertions, claims, and claim signatures are generated on network edge endpoints. |
Maximum Assurance Level |
A numeric designation determined at the sole discretion of the C2PA Compliance Program, based on its evaluation of the security functions and attributes of an Applicant’s Generator Product. |
Registration Authority (RA) |
An entity authorized by a CA to collect, verify, and submit Applicant and/or Subscriber information for inclusion in public key certificates. The RA operates under the authority of the CA and complies with the CA’s CPS. |
Reliable Communication Method |
A communication method verified through a source other than the Applicant’s Representative, such as a postal/courier address, telephone number, or email address. |
Manifest Consumer |
A diverse and numerous population of consumers relying on Content Credentials to ensure provenance and authenticity of digital objects. To consume C2PA-supported Content Credentials, Manifest Consumers must use C2PA-approved service providers. |
Relying Party |
An entity that evaluates the trustworthiness of assertions made by a signer in a C2PA asset, based on the signer’s identity and the Assurance Level encoded in the certificate. |
Security Incident |
An actual or potential event that compromises the confidentiality, integrity, or availability of an information system and the information the system processes, stores, or transmits, or constitutes a violation (or imminent threat of violation) of security policies, security procedures, or acceptable use policies. |
Signer |
In the context of the Compliance Program, a Compliant Generator Product instance in the CPL is always the signer. |
Static Evidence |
Attributes of the Generator Product target of evaluation documented in the Generator Product Security Requirements document, reviewed by the Administration Authority when evaluating an Applicant’s Generator Product to determine the maximum Assurance Level. |
Subscriber |
An Applicant that has become a customer of a CA in the C2PA Trust List and is eligible to receive certificates for its Compliant Generator Product instances. |
Target of Evaluation |
A system whose functional correctness and implementation security are evaluated by the Compliance Program, comprising the Generator Product or Validator Product and the subsystems it relies upon. |
Timestamp Authority (TSA) |
A server providing electronic authentication and trust services by creating hash values to verify the date and time a file was created or modified, serving as an independent witness that a file has not changed since it was signed. |
Trusted Execution Environment (TEE) |
See NIST definition. |
Validator |
A Manifest Consumer that performs the operations described in the validation process. |
Validator Product |
A collection of software, hardware, and platform configurations created by an Applicant that work together as a system to verify digital assets with C2PA Manifests. A Validator Product may integrate validator functionality monolithically or rely on a separate validator service locally (e.g., on-device) or remotely (e.g., cloud-hosted). Because the Validator Product is always the entity listed on the C2PA Compliant Product List (CPL), it is responsible for producing correct validation results in accordance with normative requirements, whether it directly integrates or relies on a separate service. |