ASKLERA PDF — Roadmap

03a — Universal standards atlas, part 1: core, codecs, text, colour, security, signatures, smartcards

Each row: the standard (with edition), what it governs, the oracle (reference implementation, official validator, conformance suite or test files that share no code with us), our status from the ledger, and the tier in 04-feature-tiers.md. "Esoteric" is not a dismissal here: it is the list of things competitors skip.

A. Core format and its extensions

Standard Governs Oracle Status Tier
ISO 32000-2:2020 + Errata Collection 3 (sponsored, read) ; ISO 32000-2:2020/Amd 1 (first 92 errata, published) ; DAmd 1.2 in development PDF 2.0 qpdf, mutool, poppler, pdf.js, Arlington TestGrammar, pdf20examples 252/293 rows implemented T0
ISO 32000-1:2008 + Adobe Supplements ExtLevel 3 (2008) and 5 (2009) PDF 1.7 + AES-256 R5, /Extensions, portfolios qpdf --force-R5, Acrobat corpus files ✅ R5 read/write
PDF Reference 1.0–1.6, Adobe errata, blend-modes addendum, implementation notes legacy producers (1993–2006) corpus of period files (pdf.js, pdfium) ✅ read
ISO/TS 32001:2022 (SHA-3/SHAKE), 32002:2022 (ECC curves, EdDSA), 32003:2023 (AES-GCM), 32004:2024 (integrity/MAC), 32005:2023 (hierarchical inclusion) PDF 2.0 extensions pyHanko (32004), veraPDF (32005), OpenSSL 32003 ✅, 32005 ✅, 32001/32002/32004 write side blocked on russl-pades T3 F-036
PDF Association extension registry (pdfa.org/extensions, JSON schema): Brotli (PDFa prefix, ExtensionLevel 1, Revision 2026, RFC 7932 + RFC 9841 large window), Custom metadata structures, Object metadata locations (AN003), Associated files (AN002), Black-point compensation (AN001), PDF Declarations, WTPDF, Deriving HTML registered extensions brotli(1), veraPDF, pdf.js prototype Brotli partial (large window), AN001–003 ✅/partial T3
Vendor extensions with registered prefixes: ADBE (Adobe: AES-256, portfolios, geospatial, 3D, rich media, XFA), GTS_PDFX, ISO_, MSFT? (MIP), ESIC (ETSI?), PTEX (pdfTeX), BDIA? developer extensions dictionaries §7.12 Arlington Extensions table, corpus census extensions-dictionary
Arlington PDF Model (pdf-association, Apache-2.0) machine-readable object model, SinceVersion/Deprecated TestGrammar (pdfium/pdfix backends) 🔬 wired; 288/288 version pairs
RFC 8118 (application/pdf, fragment identifiers #page=, #nameddest=, #zoom=, #search=), Adobe "PDF Open Parameters" URL fragments, viewer behaviour pdf.js, Acrobat ✅ fragments; viewer T5 T5
Linearization (ISO 32000-2 Annex F), hint tables, progressive HTTP range loading fast web view qpdf --check-linearization, pdf.js range loader ✅ write; progressive read T1 F-012 T1
XFA 3.3 (Adobe, deprecated in 2.0 but ubiquitous: SAP ADS, AEM Forms, IRS, cerfa), XDP packaging dynamic/static forms pdfium XFA build, Acrobat (manual), SAP sample forms packets/datasets/strip ✅; rendering 📋 T3 F-035
FDF (ISO 32000-2 §12.7.8), XFDF 3.0 (Adobe) → ISO 19444-1:2019 (not acquired) form data exchange pdftk, xmllint + xfdf.xsd, Acrobat export absent → Phase 0 AI T0
OGC GeoPDF (OGC 08-139r3) and Adobe geospatial (/Measure /GEO, /GPTS, /LPTS) georeferenced PDFs GDAL PDF driver (gdalinfo, gdal_translate), QGIS, TerraGo 📋 T4 F-047
PDF portfolios/collections (§12.3.5), /Collection schemas, navigators portfolio PDFs (Acrobat) Acrobat, pdf.js attachments view read ✅; navigator 🚫 (Flash-era)
Rich media (§13.6, /RichMedia, Flash/HTML5), multimedia (§13.2 /Movie, /Sound legacy), 3D (§13.6.5 PRC/U3D) embedded media structural only; veraPDF 4e files 3D headers ✅ structural; media 🚫 playback
Web Capture (§14.10, deprecated), OPI (§14.11.7, deprecated), Trap networks (§14.11.6), Output intents (§14.11.5), Prepress boxes (§14.11.2), DPart (§14.12) prepress qpdf --json, gs, Cal Poly ✅ except OPI (deprecated, read-only)

B. Compression and image codecs (all via RUSSL/CODECS)

Standard Filter / use Oracle Status Tier
RFC 1950/1951 (zlib/Deflate) /FlateDecode, predictors (PNG RFC 2083 §6, TIFF 6.0 §14) CPython zlib (infcover 33/38), pypng, libtiff, gs ✅ (predictors partial: sub-byte edge cases)
RFC 7932 Brotli, RFC 9841 (large window) /BrotliDecode (PDFa extension) brotli(1) 1.2 partial (large window in russl-brotli) T3
RFC 8878 Zstandard not a PDF filter today — candidate extension zstd(1) 📋 propose via ASKL prefix (07 §6) T6
LZW (TIFF 6.0 §13, EarlyChange), ASCII85/ASCIIHex, RunLength (§7.4) legacy filters qpdf, mutool
ITU-T T.4 (1D/2D MH/MR), T.6 (MMR/G4) /CCITTFaxDecode libtiff fax2tiff/tiffcp, poppler, mupdf ✅ (surpasses poppler/mupdf on testfax4)
ITU-T T.81 / ISO/IEC 10918-1 (JPEG baseline, extended, progressive, arithmetic, 12-bit), Adobe APP14 (YCCK/CMYK), JFIF, EXIF /DCTDecode libjpeg-turbo djpeg + djcmyk.c, pdfimages ✅ decode; truncated-DCT prefix painting 📋; encoder quality ladder 📋 T0/T4
ISO/IEC 15444-1 (JPEG 2000 Part 1), 15444-2 (Part 2 extensions used inside JPX: MCT, arbitrary wavelets — rarely), 15444-4 (conformance), 15444-15 HTJ2K (High-Throughput, 2019) /JPXDecode, JP2/JPX boxes, SMaskInData, palettes, cdef OpenJPEG opj_decompress, Kakadu (commercial, if available), 15444-4 codestreams ✅ 23/23 Part 1; Part 2 features and HTJ2K 📋 upstream T4
ITU-T T.88 / ISO/IEC 14492 (JBIG2), generic/refinement/symbol/text/halftone/MMR, Huffman B.1–B.15, embedded (Annex D.4) vs file organisation /JBIG2Decode, /JBIG2Globals jbig2dec, pdf.js jbig2.wasm, UBC suite, ITU vectors, author PBMs ✅ 96/96; encoder (generic + symbol) 📋 for MRC T4 F-046
ISO/IEC 18181 JPEG XL candidate future filter (no registered extension yet) libjxl djxl 📋 track; propose extension via ASKL prefix T6
PNG (ISO/IEC 15948) via predictors, TIFF 6.0 / TIFF/IT (ISO 12639) / TIFF-FX (RFC 3949) as import sources, PDF/raster 1.0 (PDF Association) image import/export libtiff, pypng, gs tiffsep import ✅ (PNG/TIFF/JPEG in writer); PDF/raster absent T3 F-037
Inline images (§8.9.7), image masks, stencil masks, /SMask, /Matte, /Decode, 16-bit, /Interpolate, /Alternates image model pdftoppm, mutool, gs ✅ (Interpolate as viewers: bilinear)
Halftones (§10.6, PostScript LanguageLevel 3 types 1/5/6/10/16), transfer functions (§10.5), flatness/smoothness device-level rendering parameters gs (only oracle that applies them) /HT read, not applied (screen rendering); RIP mode 📋 T4 F-041

C. Fonts, text, internationalisation

Standard Governs Oracle Status Tier
ISO/IEC 14496-22:2019 (OpenType / OFF), TrueType (Apple/MS), cmap formats 0/2/4/6/12/13/14 (8/10 rare), post, hmtx/vmtx, OS/2, glyf/loca, CFF/CFF2, GSUB/GPOS (shaping), COLR/CPAL/SVG/sbix/CBDT (colour fonts), fvar (variable) embedded and system fonts fontTools/ttx (1.4 M advances, 516 k cmap entries identical), FreeType (rendering), HarfBuzz (hb-shape) for shaping ✅ parsing/metrics/glyphs; shaping for writing 📋 (ADR); colour fonts → flatten 📋; variable → instance 📋 T3 F-030
Adobe Type 1 (T1 spec, PFA/PFB, eexec, seac), CFF (TN #5176), Type 2 charstrings (TN #5177), CID-keyed fonts (TN #5014), Type 3 (§9.6.4), Multiple Master (deprecated) embedded font programs fontTools T2CharStringPen, FreeType ✅ incl. seac, FontMatrix, damaged loca (FreeType rule), PFB cut
CMaps (TN #5099), predefined CMaps (§9.7.5.2 Table 116), Adobe-Japan1/GB1/CNS1/KR (Korea1 → KR), Identity, usecmap, ToUnicode (TN #5411), UCS2 CMaps (cmap-resources, mapping-resources-pdf) composite fonts, CJK legacy encodings (Shift-JIS, EUC-JP, GBK/GB18030, Big5, EUC-KR, UHC) pdftotext, mutool, pdf.js, cmap-resources
Standard 14 fonts and AFM metrics (Adobe Core 14), URW Base 35 / Core 35 (OFL 1.1 read at source), font substitution flags (§9.8.2) non-embedded Latin fonts AFM widths (4 107/4 172 equal, 53 listed), pdftoppm/mutool with the same URW files ✅ shipped (apdf-fonts-std14)
CJK fallback: Noto CJK / Source Han (OFL), Adobe collections' ordering → Unicode non-embedded CJK (17 docs in corpus) pdftoppm with system Noto 🧭 D-3 T4
Unicode: UAX #9 (bidi), UAX #14 (line breaking), UAX #29 (segmentation), UAX #24 (scripts), UAX #15 (normalisation), UTS #46 (IDNA, for URIs), CLDR (hyphenation exceptions, locale line-break tailoring), TR9-51 (UCD 17.0) text extraction and writing UCD BidiTest/BidiCharacterTest (100 %), fribidi, ICU (icu4c ubrk), LibreOffice/TeX hyphenation patterns (Hunspell hyph_*.dic, LGPL/MIT per language — licence per file) bidi ✅; UAX #14/#29 📋 (writer); hyphenation ADR pending T3
Encodings: StandardEncoding, WinAnsiEncoding, MacRomanEncoding, MacExpertEncoding, PDFDocEncoding, Symbol, ZapfDingbats (Annex D), AGL (4 281 names) + AGLFN, glyph-name grammar (uniXXXX, uXXXXX, gNN, cidNN) simple fonts CPython codecs, fontTools agl (4 681/4 681)
Text strings: PDFDocEncoding, UTF-16BE BOM, UTF-8 BOM (2.0), escapes, /Lang (BCP 47), /ActualText, /Alt, /E (expansion) strings and structure text qpdf --json, pdf.js
Vertical writing (WMode 1, /W2, /DW2), ruby (RB/RT/RP structure), Mongolian/Uighur vertical, Japanese tate-chū-yoko (layout) CJK layout pdftoppm (vertical_text.pdf 401/407 px) ✅ render; writer 📋 T3
MathML 3/4 (ISO/IEC 40314) in tagged PDF 2.0 (/Math namespace http://www.w3.org/1998/Math/MathML), /AF MathML source accessible mathematics veraPDF ua2 files, LaTeX+tagpdf output read ✅ (structure namespaces); write 📋 T3

D. Colour

Standard Governs Oracle Status Tier
ICC.1:2022 (ISO 15076-1, v4.4), ICC v2, iccMAX (ISO 20677) /ICCBased, output intents, shipped profiles LittleCMS transicc (804 conversions max Δ1), gs, colord profiles (CC0) ✅ v2/v4; iccMAX 🚫 (no PDF use)
IEC 61966-2-1 (sRGB) (preview only), Adobe RGB (1998) (compatible CC0 profile shipped), Display P3, Rec.709/2020 (BT.709 profile shipped) RGB working spaces transicc
ISO 12647-2/-3/-4/-6 (offset, newspaper, gravure, flexo — previews only), FOGRA characterisation data (FOGRA27–59), SWOP/GRACoL (CGATS TR001–TR006), Japan Color 2011 (X-Rite licence — excluded), China: GB/T 7705 / CGATS-like national data (to survey) CMYK printing conditions colord CC0 profiles (36), ECI free profiles (17); FOGRA39L default at Δ1 of ISOcoated_v2 ✅ shipped; ECI ISOcoated_v2/PSOcoated_v3 🧭 D-4
CIE spaces (§8.6.5: CalGray, CalRGB, Lab with /Range), /Indexed, /Separation, /DeviceN (+ /NChannel, /Colorants, /Process), /Pattern colour model transicc, gs, mutool ✅ (gs decodes Lab images on ±100 regardless of /Range — documented)
Rendering intents, black-point compensation (ISO 18619, AN001, /UseBlackPtComp), /DefaultGray|RGB|CMYK (§8.6.5.6), overprint (/OP, /op, /OPM), knockout groups, transparency (§11) blending in group colour space colour appearance gs, mutool, poppler (each with documented deviations) ✅ (group-space blending CMYK/Gray; ICC-RGB groups still sRGB)
Spot colour libraries: Pantone (proprietary — names only), HKS, Toyo, DIC, RAL; CxF/X-4 (ISO 17972-4 spectral data), N-colorant (nCLR) profiles, extended gamut (ECG 7-colour) prepress spot handling Esko/Pantone Live (commercial), CxF sample files names ✅; CxF read 📋; nCLR 📋 (no free profile → PDF/X-5n/6n absent) T4
Ink coverage / TAC, separations (tiffsep), trapping (§14.11.6), screening (§10.6) RIP outputs gs tiffsep, -dUsePDFX3Profile separations ✅; TAC/trapping 📋 T4 F-041

E. Encryption, permissions, DRM handlers

Standard Governs Oracle Status Tier
ISO 32000-2 §7.6: standard security handler R2/R3/R4/R5/R6 (RC4 40/128, AES-128 CBC, AES-256, Unicode passwords via SASLprep RFC 4013 / stringprep RFC 3454), /EFF (attachments only), /EncryptMetadata, permissions /P (R6 bit 10 semantics confirmed by qpdf) password encryption qpdf, mutool, pdf.js, CPython stringprep
ISO/TS 32003 (AES-256-GCM, /AESV4?) — as published authenticated encryption pyHanko
Public-key security handler (§7.6.5, /Adobe.PubSec), CMS EnvelopedData (RFC 5652), KeyTransRecipientInfo (RSA PKCS#1 v1.5 / OAEP RFC 8017), KeyAgreeRecipientInfo (ECDH, RFC 5753), content ciphers AES/3DES/RC2, PKCS#12 (RFC 7292: PBES1 RC2-40/3DES, PBES2 RFC 8018), PKCS#8 certificate encryption pyHanko, OpenSSL cms -decrypt, pkcs12 -legacy, keytool ✅ RSA + AES; ECDH and 3DES/RC2 content 📋 (upstream russl-cms) T3
Legacy/proprietary handlers to detect and name (never circumvent): Adobe LiveCycle Rights Management (/Adobe.APS), FileOpen (/FOPN_foweb, /FOPN_fLock), Adobe ADEPT (/EBX_HANDLER), Microsoft IRM/MIP (/MicrosoftIRMServices, .ppdf), Locklizard, Vitrium, IBM/Xerox handlers, /Adobe.PPKMS, /Entrust.PPKEF DRM vendor SDKs only 📋 detection + diagnostics (apdf info names the handler, apdf lint explains) T2
Microsoft Information Protection labels in XMP (MSIP_Label_<GUID>_Enabled/SiteId/Owner/SetDate/Name/ContentBits/Method) and custom document properties enterprise DLP labelling Acrobat/Foxit/Edge display; Purview 📋 read/write (F-025) T2
Redaction (§12.5.6.23 /Redact, /RO, /OverlayText), true content removal, NSA "Redacting with Confidence", NIST/DoJ guidance, PCI DSS PAN masking provable redaction qpdf --json + pdftotext after (nothing left), pdfimages annotation ✅; apply-redaction with destruction report 📋 T2/T4 F-045
Sanitisation: NSA "Inspection and Sanitization Guidance for PDF" (IAD), NCSC "Safely importing data", CDR vendors' claims cross-domain safety UNSAFE-DOCS corpus, VirusTotal samples (internal) 📋 apdf scrub --rebuild T2 F-025
Attack literature: PDFex (CCS 2019: direct exfiltration, CBC gadgets), Shadow Attacks (NDSS 2021: hide/replace/hide-and-replace after signing), USF/ISA/SWA signature bypasses (S&P/NDSS 2019), "Processing Dangerous Paths" (2021), JS sandbox escapes, FORCEDENTRY JBIG2 (CVE-2021-30860), Ghostscript -dSAFER history, pdfium/poppler CVE streams threat model published PoCs (pdf-insecurity.org), CVE PoCs 📋 hardening report replays each class (F-025) T2
FIPS 140-3 (crypto modules), ETSI TS 119 312 (algorithms and key sizes), SOG-IS agreed mechanisms, ANSSI RGS B1, BSI TR-02102, NIST SP 800-131A (transitions), CNSA 2.0 (PQC timeline) algorithm policy policy tables 📋 apdf sign --policy sogis|nist|cnsa2 selecting allowed suites; RUSSL provides primitives T3

F. Digital signatures and trust regimes (worldwide)

F.1 Signature formats inside PDF

Format Spec Oracle Status
adbe.x509.rsa_sha1 (PKCS#1, legacy), adbe.pkcs7.sha1, adbe.pkcs7.detached (CMS RFC 5652) ISO 32000-2 §12.8.3 pdfsig, pyHanko, Acrobat
ETSI.CAdES.detached (PAdES: ETSI EN 319 142-1/-2, CAdES EN 319 122-1/-2), levels B-B/B-T/B-LT/B-LTA, /DSS, /VRI, /DocTimeStamp (ETSI.RFC3161), RFC 3161/5816 TSA PAdES pyHanko, DSS, pdfsig ✅ B-B…B-LTA; DSS oracle to add
Signature handlers /Filter: Adobe.PPKLite, Adobe.PPKMS, Entrust.PPKEF, CICI.SignIt, VeriSign.PPKVS (§12.8.1) handler names corpus ✅ read; write PPKLite
MDP: certification (/DocMDP P=1/2/3), FieldMDP (/Lock, /SV), UR3 usage rights (/UR3, Reader extensions — Adobe proprietary), /Reference transforms modification detection pyHanko, Acrobat ✅ DocMDP/FieldMDP; UR3 read-only (Adobe key)
Seed values (/SV: /Cert, /Reasons, /MDP, /TimeStamp, /LegalAttestation, /DigestMethod, /AddRevInfo), legal content attestations (§12.8.5 /Legal) signing constraints pyHanko (crashes on /DigestMethod [/SHA256] 0.37) ✅ except /Cert
Long-term: ERS (RFC 4998 / RFC 6283 XML), ETSI TS 119 511/512 (preservation services), BSI TR-ESOR (TR-03125) evidence records for archives DSS, TR-ESOR test suite (BSI) 📋 T4 F-042
Post-quantum: RFC 9882 (ML-DSA in CMS, FIPS 204), SLH-DSA in CMS (RFC 9814?), composite ML-DSA (IETF LAMPS drafts draft-ietf-lamps-pq-composite-sigs), ETSI TR 119 619 (PQC migration for AdES, in progress), NIST IR 8547 timeline PQ signatures in PAdES OpenSSL 3.5 (ML-DSA), Bouncy Castle 1.79+, liboqs 📋 first mover (F-033) — via RUSSL only
National crypto suites: GOST R 34.10-2012 / 34.11-2012 (RFC 7091/7836; CryptoPro PDF plugin, adbe.pkcs7.detached with GOST OIDs), SM2/SM3 (GM/T 0003/0004, RFC 8998 for TLS; GM/T 0010 SM2 CMS; GB/T 38540-2020 electronic seal, GM/T 0031), DSTU 4145 (Ukraine), KCDSA/EC-KCDSA (Korea), ECGDSA (Germany BSI), Brainpool (RFC 5639, common in EU eIDs) non-NIST algorithms CryptoPro test tools, GmSSL (gmssl CLI), Ukrainian IIT tools, KISA test vectors Brainpool ✅ (russl-brainpool); GOST/SM2/DSTU/KCDSA 🧭 upstream RUSSL availability to measure
Visible signatures: appearance streams, /n0/n2 layers (Adobe legacy), QR verification codes, seals (Japan 電子印鑑, China e-seal image + signature per GB/T 38540, Korea 전자인감) appearance Acrobat rendering, national viewers ✅ appearance; seal profiles 📋
Jurisdiction Legal basis / profile National PKI & tokens Oracle / test material Take
EU/EEA eIDAS Reg. 910/2014 + eIDAS 2.0 Reg. 2024/1183 (EUDI Wallet), CID 2015/1506 (AdES formats), ETSI EN 319 102/122/132/142/162/172, TS 119 182 (JAdES), EUTL/LOTL national eIDs (below), QSCD per CEN EN 419211, remote QSCD EN 419241, CSC API DSS (reference validator), ETSI plugtests (Remote signature/PAdES interop events), LOTL = full AdES, LOTL trust store, DSS oracle, CSC client
Germany VDG (Vertrauensdienstegesetz), BSI TR-03110 (eID), TR-03112 (eCard-API), TR-03116, TR-03125 (TR-ESOR), TR-03138 (RESISCAN), GoBD (tax record keeping) nPA (AusweisApp, no signature by default), D-Trust/Bundesdruckerei sign-me, Telesec, HBA/SMC-B (gematik TI), ELSTER certificates (.pfx) AusweisApp SDK, gematik Konnektor sample, BSI TR-ESOR test suite = PKCS#11/PC-SC generic; ELSTER pfx (PKCS#12) ✅
France Code civil 1366–1367, Décret 2017-1416, RGS v2 (, *), ANSSI qualifications, RGI, NF Z42-013 / Z42-020, référentiel Pro Santé Connect ANTS CNIe/France Identité, CPS/CPE/e-CPS (IAS-ECC), Certigna/Certinomis/Docaposte/ChamberSign libcps-rs (ASKLERA), Cryptolib CPS, ANTS test cards, DSS = IAS-ECC profile module; CPS as one module
Italy CAD (D.Lgs. 82/2005), AgID rules, PAdES-BES/T with /Filter /Adobe.PPKLite + ETSI.CAdES.detached, firma digitale remota, SPID/CIE 3.0, TS-CNS (health card = smartcard), conservazione (UNI 11386 SInCRO), FatturaPA Aruba, InfoCert, Namirial, Actalis; CIE 3.0 middleware, TS-CNS AgID verifier (verificafirma), DSS = CNS/CIE modules, SInCRO metadata (§I)
Spain Ley 6/2020, ENI (Esquema Nacional de Interoperabilidad: NTI documento/expediente electrónico — PDF/A mandated, XAdES/PAdES), Cl@ve, DNIe 3.0/4.0, FNMT-RCM DNIe (PKCS#11 via OpenSC/official), FNMT @firma/AutoFirma (open source, oracle!), VALIDe = DNIe module; ENI metadata XML (§I)
Belgium eID (BELPIC, PKCS#11 beid-pkcs11), itsme (remote) BEID middleware (open source) eID test cards, DSS = BELPIC module
Netherlands PKIoverheid, DigiD, UZI-pas (healthcare smartcard), NEN 2082/7513 UZI (PKCS#11) UZI test cards = UZI module
Estonia / Latvia / Lithuania ASiC-E/BDOC/ADOC containers (EN 319 162), Web eID, DigiDoc4/libdigidocpp, Smart-ID (remote) EstEID (PKCS#11 via OpenSC), eParaksts libdigidocpp (LGPL, oracle), Smart-ID demo = ASiC containers wrapping PDF (§F.3); EstEID module
Austria ID Austria/Handy-Signatur (remote, A-Trust), Bürgerkarte (legacy), ELGA e-card A-Trust MOA-SP/SS (open source, oracle) =
Switzerland ZertES, SuisseID (legacy), Swisscom AIS (remote, CSC-like), swisssign SwissSign Swisscom AIS sandbox = remote client
UK eIDAS (retained, UK trust list), Electronic Communications Act 2000, NHS Care Identity smartcards NHS smartcards (Oberthur/IDEMIA PKCS#11) = generic PKCS#11
Nordics BankID (SE/NO — remote, not cards), MitID (DK), FINeID (FI, PKCS#11 mPollux), Buypass (NO cards) FINeID, Buypass Finnish DVV test cards =
Poland / Czechia / Slovakia / Hungary / Romania / Bulgaria / Croatia / Slovenia national qualified CAs (KIR, Certum, PostSignum, I.CA, Disig, NetLock, certSIGN, B-Trust, Fina, SIGEN-CA), national eIDs (e-Dowód, eObčanka, eID SK) PKCS#11 middlewares DSS + national validators (e.g. Polish "weryfikator") = generic
Portugal Cartão de Cidadão (pteid, PKCS#11), Chave Móvel Digital (remote), ATCUD/QR on invoices pteid middleware (open source, oracle) pteid SDK =
Luxembourg LuxTrust (cards + remote) LuxTrust middleware =
Ukraine / Kazakhstan / Russia / Belarus DSTU 4145 (UA), Diia; NCA RK (KZ GOST/KZ); GOST (RU, CryptoPro/ViPNet, Federal Law 63-FZ); STB (BY) national CSPs IIT (UA), NCA test tools, CryptoPro test 🧭 algorithms upstream; sanctions/compliance review before RU support
Turkey Law 5070, KamuSM/TÜBİTAK, e-imza, e-Fatura (UBL-TR) e-imza tokens (PKCS#11) KamuSM test =
USA ESIGN Act, UETA, 21 CFR Part 11 (pharma/FDA: audit trails, signature manifestations), FIPS 201-3 (PIV), DoD CAC, NIST SP 800-63-3/-4, HIPAA, NARA, court CM/ECF PDF/A rules, FHFA/Fannie eNote (MISMO SMART Doc), AATL (Adobe Approved Trust List) PIV/PIV-I/CAC (PKCS#11 via OpenSC/ActivClient, CNG minidriver), DigiCert/IdenTrust/Entrust (AATL) OpenSC PIV, piv-tool, NIST PIV test cards (SP 800-85A), Acrobat AATL validation = PIV/CAC module, Part 11 manifestation profile, AATL trust store
Canada PIPEDA, Secure Electronic Signature Regulations, GC PKI Entrust GC cards = generic
Brazil MP 2.200-2/2001, Lei 14.063/2020, ICP-Brasil DOC-ICP-15 (PAdES-BR profiles AD-RB/RT/RC/RV/RA), e-CPF/e-CNPJ A1 (PKCS#12) / A3 (tokens), Gov.br assinatura Serpro/Certisign/Soluti tokens (PKCS#11) ITI Verificador de Conformidade (official validator, oracle), Assinador SERPRO = PAdES-BR policy attributes (signature-policy-identifier OIDs)
Mexico NOM-151-SCFI-2016 (constancia de conservación: timestamped hash), FIEL/e.firma (SAT, PKCS#12 .cer/.key), CFDI 4.0 (XML + PDF representation) SAT e.firma SAT validators = NOM-151 timestamp profile; CFDI PDF rep (§H)
Argentina / Chile / Colombia / Peru / Uruguay Ley 25.506 (AR), Ley 19.799 (CL), Ley 527/1999 + Decreto 2364 (CO), Ley 27.269 (PE); national CAs (ONTI, SII, ONAC/Certicámara, INDECOPI) tokens (PKCS#11) national validators = generic + e-invoice reps (§H)
India IT Act 2000 (Sch. II eSign), CCA India, Aadhaar eSign (ASP/ESP API), DSC Class 3 tokens (ePass 2003, ProxKey), DigiLocker issued docs, GST e-invoice IRN QR CCA-licensed CAs (eMudhra, Sify, (n)Code) eSign sandbox (CDAC), DSC test tokens, NIC validator = Aadhaar eSign client (hash → CMS), IRN QR
China Electronic Signature Law (2004/2019), GB/T 38540-2020 e-seal, GM/T 0031, GM/T 0010, OFD (GB/T 33190), CFCA, UKey (PKCS#11 via SKF — GM/T 0016 SKF API, not PKCS#11!) UKeys (SKF), CFCA certs GmSSL, national e-seal verifiers = SKF API adapter (GM/T 0016) beside PKCS#11; SM2 upstream 🧭; OFD ↔ PDF (§S)
Japan Act on Electronic Signatures (2000), JPKI (My Number Card), 電子帳簿保存法 (e-Books Preservation Act: timestamps on scanned docs, JIIMA certification), 電子印鑑 JPKI (PKCS#11 via JPKI client), Cybertrust/SECOM/GlobalSign JP JPKI test env, JIIMA test = JPKI module, e-Books timestamp profile (RFC 3161 + Japanese TSA policy)
Korea Digital Signature Act (2020 reform: 공동인증서), KISA, 전자문서 및 전자거래 기본법 (certified e-document authority) NPKI certs (PKCS#12 .p12/NPKI folder format), HSM tokens KISA test tools = NPKI import
Taiwan / Hong Kong / Singapore / Malaysia MOICA Citizen Digital Certificate (TW, PKCS#11), Hong Kong ETO + Smart ID, Singapore ETA + SingPass/Sign with SingPass (remote), Malaysia DSA 1997 + MyKad/Pos Digicert PKCS#11 / remote APIs national test =
Middle East / Africa UAE Federal Decree 46/2021 + UAE PASS (remote), Saudi Digital Signature Law + Nafath + ZATCA cryptographic stamps (§H), Israel Electronic Signature Law 2001, Egypt ITIDA, South Africa ECTA 2002 (SAPO), Kenya, Nigeria NITDA, Morocco Loi 43-20 (Barid eSign) tokens / remote ZATCA SDK (open source), UAE PASS sandbox = remote clients; ZATCA stamp (ECDSA secp256k1 in CMS — verify)
Australia / NZ Electronic Transactions Act 1999, myGovID/Digital ID Act 2024, Gatekeeper PKI; NZ ETA 2002, RealMe Gatekeeper certs = generic
International UNCITRAL Model Law (1996/2001), HCCH e-Apostille (e-APP): apostilles as digitally signed PDFs with e-Register national apostille authorities sample e-Apostilles (HCCH) = e-Apostille profile (§M)
Format Spec Take
ASiC-S/ASiC-E (ETSI EN 319 162-1/-2), BDOC 2.1 (EE), ADOC (LT), eDoc (LV), .p7m (CAdES enveloping, Italy), .sig detached signed containers wrapping PDFs = create/verify containers (libdigidocpp, DSS oracles)
XAdES (EN 319 132) for XML attachments (Factur-X XML, ENI, FatturaPA), JAdES (TS 119 182) for JSON (EUDI) non-PDF payloads carried by PDFs = XAdES via RUSSL (russl-xades? 🧭 measure)
S/MIME (RFC 8551) for PDFs in mail, REM/PEC (ETSI EN 319 522, Italy PEC) mail transport asklera-mail synergy
C2PA 2.4 (manifest as associated file, data.hash exclusions for coexistence with PAdES) content provenance = F-032, oracle c2patool

G. Smartcards, tokens, HSMs, remote signers (generic-first architecture)

Layer Standard / API Coverage target Oracle
Card transport PC/SC (winscard.h; pcsc-lite on Linux/macOS), ISO/IEC 7816-3/-4 (APDU, T=0/T=1), CCID (USB), NFC (ISO 14443, for eIDs) one transport crate (ADR: pcsc crate or RUSSL equivalent) opensc-tool -a, pcsc_scan
Card applications ISO/IEC 7816-15 / PKCS#15 (object discovery), IAS-ECC v1.0.1 (FR/EU eIDs, CPS), CEN EN 14890-1/-2 (SSCD application interface), NIST SP 800-73-4/-5 (PIV), DoD CAC (NIST + DMDC), BSI TR-03110 (eID EAC/PACE), ICAO 9303 (ePassport, read-only), OpenPGP card 3.4, FIDO2/CTAP (auth only), GlobalPlatform (management, out of scope), Java Card applets (vendor) profile modules on top of the transport: piv, cac, ias-ecc (CPS = configuration), pkcs15-generic, estonia, belpic, dnie, cns, jpki, openpgp OpenSC drivers as behavioural oracle (pkcs15-tool --list-keys, pkcs11-tool --sign)
Middleware APIs PKCS#11 v2.40/v3.1 (OASIS) — the universal path (OpenSC, SafeNet, YubiKey, HSMs, Cryptolib CPS, gematik, BEID…), Microsoft CNG KSP / CryptoAPI CSP / smart card minidriver, Apple CryptoTokenKit, Linux p11-kit, GM/T 0016 SKF (China UKeys), Java KeyStore/JCE (via JVM binding), Android Keystore/StrongBox, iOS Secure Enclave, TPM 2.0 (tpm2-pkcs11) apdf-sign external signer trait: sign_hash(algorithm, digest) -> signature, certificates(), pin callbacks; adapters: PKCS#11 (first), CNG, CTK, SKF, PC/SC-native profiles, cloud KMS, CSC pyHanko --p11-module, pkcs11-tool, SoftHSM2 (oracle without hardware), YubiKey PIV, NIST PIV test cards
HSM / KMS PKCS#11 (Thales Luna, nShield, Utimaco, AWS CloudHSM, YubiHSM), AWS KMS / Azure Key Vault & Managed HSM / GCP Cloud KMS (REST, sign-digest), HashiCorp Vault Transit, Fortanix DSM adapters through the same trait SoftHSM2, LocalStack KMS, Azure emulator (none) → real sandboxes
Remote / cloud signing CSC API v2.2 (OAuth2, credentials/info, signatures/signHash), EUDI Wallet ARF (QES via wallet), Swisscom AIS, Adobe Sign/DocuSign APIs (platform signatures, not ours), Aadhaar eSign (IN), Sign with SingPass (SG), UAE PASS, Gov.br csc adapter + wallet flows CSC sandbox providers (Namirial, InfoCert, Intesi), DSS
Trust stores EU LOTL/TSL (ETSI TS 119 612), AATL (Adobe), Microsoft/Apple/Mozilla roots (for TLS-style validation), national lists (ICP-Brasil AC-Raiz, CCA India, KamuSM, JPKI), CA/B Forum, OCSP (RFC 6960) / CRL (RFC 5280) / SCVP configurable trust policies, offline bundles with provenance DSS, openssl verify, pdfsig -trust
Health-card family (as one profile family, not a French special case) CPS (FR, IAS-ECC), HBA/SMC-B (DE, gematik), UZI (NL), TS-CNS (IT), NHS (UK), e-card (AT), HIN (CH), HPI (AU) — all PKCS#11 or IAS-ECC/PKCS#15 covered by generic modules + per-card configuration files (AIDs, PIN policies, certificate slots) vendor test cards; libcps-rs for CPS internals
Source: docs/roadmap/03a-standards-atlas-core.md · big-1 · 2026-09-14 18:00 UTC