Raknor Cybersecurity Certification
Raknor Cybersecurity Posture Certification Record
CERTIFICATION DENIED
AEGIS Cyber Reasoning System v1.4.0 — Raknor.ai
Record IDRCS-2026-0001
FrameworkNIST CSF 2.0
Score43.7/100 (F)
DecisionNot Certified
Overall security posture below certification threshold (70/100)
System scored 43.7/100. Minimum cybersecurity certification threshold is 70/100.
FRAMEWORK_CONTROL_GAP — Required controls for target framework below threshold
Resubmission eligible after 30-day remediation period.

Decision Narrative

Decision

AEGIS Cyber Reasoning System v1.4.0, submitted by Raknor.ai, has been evaluated under cybersecurity posture certification (Certification ID: RCS-2026-0001). Certification is DENIED with a score of 43.7/100 (Grade: F), below the minimum threshold of 70/100. No Mandatory Failure Conditions (MFCs) were triggered. Certification is denied due to insufficient cybersecurity posture score under framework thresholds. Lowest domain: Compliance Coverage (CP-COM) at 0/100.


Evaluation Scope

This evaluation was conducted under Raknor Standard v1.0.0. Evaluation mode: AEGIS static + symbolic analysis. Observation source: AEGIS evidence bundle. The evaluation consumed evidence from an AEGIS security scan, scoring 7 cybersecurity domains. Framework-specific requirements: NIST CSF 2.0 (minimum 60% control coverage, maximum 1 critical and 10 high findings). Credential validity: 90 days.


Basis for Denial

DECISION BASIS: - No Mandatory Failure Conditions (MFCs) triggered - Score 43.7/100 below minimum threshold 70/100 - Vulnerability Posture (CP-VUL): 48/100 — below required 60 - Compliance Coverage (CP-COM): 0/100 — below required 60 - Continuous Monitoring (CP-MON): 20/100 — below required 60 - Observability & Instrumentation (CP-OBS): 0/100 — below required 60 Outcome: Certification Denied Certification is denied due to the following deterministic conditions: PRIMARY CONDITION: Overall security posture below certification threshold (70/100) Detail: System scored 43.7/100. Minimum cybersecurity certification threshold is 70/100. CONTRIBUTING CONDITIONS: - Required controls for target framework below threshold NIST CSF 2.0 requires 60% control coverage. System achieved 0.0%.


Remediation Requirements

Resubmission is permitted after a 30-day remediation period. Before resubmission, the following must be addressed: - Vulnerability Posture: Score must be raised from 48 to at least 60 to be considered. - Compliance Coverage: Score must be raised from 0 to at least 60 to be considered. - Continuous Monitoring: Score must be raised from 20 to at least 60 to be considered. - Observability & Instrumentation: Score must be raised from 0 to at least 60 to be considered.


Control Framework Mapping

The following controls are mapped to their governing framework functions: CP-VUL → NIST CSF: DE.CM (Detect: Continuous Monitoring), PR.IP (Protect: Information Protection) CP-COM → NIST CSF: ID.GV (Identify: Governance), PR.IP (Protect: Information Protection) CP-MON → NIST CSF: DE.CM (Detect: Continuous Monitoring), RS.CO (Respond: Communications) CP-OBS → NIST CSF: DE.AE (Detect: Anomalies & Events), DE.CM (Detect: Continuous Monitoring), ID.RA (Identify: Risk Assessment) CP-REM → NIST CSF: RS.MI (Respond: Mitigation), RS.AN (Respond: Analysis) CP-SUP → NIST CSF: ID.SC (Identify: Supply Chain), PR.DS (Protect: Data Security) CP-PRV → NIST CSF: PR.DS (Protect: Data Security), DE.AE (Detect: Anomalies & Events)


Determination

Based on the totality of observed evidence, AEGIS Cyber Reasoning System v1.4.0 does not meet the minimum requirements for Raknor certification (Certification ID: RCS-2026-0001). No Mandatory Failure Conditions were triggered; denial is based on insufficient score under framework thresholds. Controls cited in this determination: CP-VUL, CP-COM, CP-MON, CP-OBS, CP-REM, CP-SUP, CP-PRV. This determination was made through independent evaluation based on observed system security posture based on AEGIS-generated evidence under controlled analysis conditions. Every finding referenced above is reproducible from the recorded evidence.


Controls referenced: CP-VUL, CP-COM, CP-MON, CP-OBS, CP-REM, CP-SUP, CP-PRV
Raknor Cybersecurity Posture Certification Record
AEGIS Cyber Reasoning System
Raknor.ai · Version 1.4.0 · NIST CSF 2.0
RCS-2026-0001 · March 27, 2026 · AEGIS Evidence

1. Executive Summary

AEGIS Cyber Reasoning System was evaluated against the Raknor Cybersecurity Posture criteria with NIST CSF 2.0 framework requirements applied. The evaluation consumed evidence from an AEGIS security scan covering 177 files across javascript, rust.

Decision: Denied — 43.7/100


2. Cybersecurity Posture — Domain Scores

Vulnerability Posture CP-VUL ×0.25
48/100
Remediation Capability CP-REM ×0.15
100/100
Compliance Coverage CP-COM ×0.20
0/100
Supply Chain Security CP-SUP ×0.10
75/100
Provenance & Integrity CP-PRV ×0.10
82/100
Continuous Monitoring CP-MON ×0.05
20/100
Observability & Instrumentation CP-OBS ×0.15
0/100
Weighted Total

43.7 / 100


4. Framework Compliance — NIST CSF 2.0

NIST CSF 2.0 Threshold Requirements
RequirementThresholdActualStatus
Control Coverage 60% 0.0% FAIL
Max Critical Findings 1 0 PASS
Max High Findings 10 1 PASS
Credential Validity 90 days

Special: No function below 40%


Evidence Chain

AEGIS Evidence Bundle
Bundle ID: aegis-evidence-2026-03-27T04-59-49-519Z-06bb125f
Run ID: aegis-self-scan-src-1774587589450
AEGIS Version: 1.4.0
Generated:
Provenance Hash: N/A
Provenance Valid: YES
Integrity Verified: YES
Packages: sarif, html, interactive-report, stride, stride-infra, architecture, systems-explainer, instrumentation-plan, invariants, oscal-ssp, oscal-ar, oscal-poam
Credential Integrity & Verification
Certification ID RCS-2026-0001
Scope AEGIS Cyber Reasoning System — Cybersecurity Posture
Signed By Raknor.ai Certification Authority
HMAC-SHA256: v3:rk1:1eb1913f9080794a4e7afd3258f112a43b842d986820a53fa91ea55b74040a0b
Signature Anchor: v3:rk1:1eb19 (embedded in QR)
Scan to verify
certification with Raknor
Independent verification

This certification record was produced by the Raknor Arena as part of a structured evaluation engagement. Raknor Governance Certification is operated by Raknor.ai. The governance scorecard is derived from the Equilateral AI Governance Scorecard (CC BY 4.0). Raknor operates at arm's length from agent platform vendors. Certification cannot be self-attested. This record constitutes a formal decision by the Raknor Certification Authority and may be independently verified by scanning the QR code above or visiting the verification URL. The QR code contains a cryptographic signature anchor — any alteration to the badge or QR code will be detected at verification time.