Skip to main content

Server Certification Procedure: End-to-End FIDO Certification Workflow in CyberPass

This guide provides Vendors with a comprehensive walkthrough of the entire product certification lifecycle inside CyberPass. By following these step-by-step instructions, you will seamlessly manage cross-functional workflows between your team and the Certification Secretariat to complete functional assessments and secure official FIDO Server Certification.

Prerequisites

  • Active CyberPass account with user access to your company workspace.

  • A registered Product (e.g., Secure Gateway Hub SGH-200) created in your workspace under Products prior to initiating the procedure.

For specific questions regarding FIDO Alliance policies, technical specifications, or certification requirements, please contact the FIDO team at: [email protected]

For questions related to CyberPass usability and features, please reach out to CyberPass Support Team at:[email protected]

Note: The screenshots provided in this article are for demonstrative purposes only and do not represent live production data.

Step-by-Step Instructions

Step 1 — Navigate to Workspace Procedures

Log in to CyberPass and ensure you're in your selected your company workspace (e.g., Nexus Sphere). Click the sidebar menu icon () in the top-left corner and click Procedures.

Step 2 — Initiate a New Procedure

On the Procedures dashboard, click New Procedure in the top-right corner above the procedure list.

Step 3 — Select FIDO Server Certification

In the Start Procedure modal, choose FIDO Server Certification from the Procedure dropdown menu, then click Start.

Step 4 — Review Certification Scope and Specifications

Review the overview panel detailing the FIDO Functional Certification program, variant types (Functional Testing), and feature coverage.

Step 5 — Assign Product and Certification Secretariat

Scroll to the bottom of the overview page. Select your pre-configured product under Choose Product and choose FIDO Certification Secretariat under Choose Certification Secretariat. Click Submit to generate the procedure workflow.

Step 6 — The Procedure Roadmap

Once initiated, your procedure sidebar will populate with the full workflow. This roadmap guides you from the Application Form through Conformance and Interoperability testing, ending at the Results phase.

Step 7 — Understand User Roles (Vendor vs. Certification Secretariat)

The platform manages tasks via role-based access:

  • Editor (Blue Dot): Indicates the actor (e.g., Nexus Sphere) is currently responsible for taking action on the step. Users in this role can fill out fields, upload documents, and click Submit.

  • Viewer (No Blue Dot): Indicates a read-only role for the step. The user can view all submitted data, but fields are non-editable and the step remains "locked" until the designated Editor submits their portion.


Step 8 — Fill and Submit the Application Form

As the Vendor (Editor), fill in the information required in every section of the Application Form. Ensure the information entered for Legal Entity, Implementation Class, Implementation Name and all other fields are accurate in the Application Form. Once completed, accept the terms and click Submit.

Step 9 — Application Review (Secretariat Action)

Once submitted, the status shifts to Application Review.

  • Vendor Experience: Displays a lock icon indicating the step is pending completion by the Certification Secretariat.

  • Secretariat Action: The Secretariat accesses the attached Application Form via Related Forms, evaluates accuracy, sets the Verdict to Pass (or Inconclusive if corrections are needed), and submits.

Step 10 — Log Conformance Testing Details

Execute the official FIDO Conformance Test Tool externally. Once completed, navigate to Conformance Test in CyberPass, select the Date of Conformance Test submission, check the confirmation box, and click Submit.

Step 11 — Conformance Test Review (Secretariat Action)

The Certification Secretariat will verify your evidence and pass a verdict. The Secretariat may also upload the Conformance Results JSON.

Step 12 — Register and Log Interoperability Testing

Register and participate in Interoperability Testing via the external FIDO Alliance portal. Under the Interoperability Test step in CyberPass, enter your scheduled test date, check the completion box, and click Submit.

Step 13 — Interoperability Test Review (Secretariat Action)

The Certification Secretariat accesses Interoperability Test Review, uploads the official test report, logs the Interoperability Testing Date, assigns a Pass verdict, and clicks Submit.

Step 14 — Payment Record Verification (Secretariat Action)

The Certification Secretariat acts as the Editor to finalize the financial phase. They will provide the Purchase Code and upload the Invoices required to conclude the certification.

Professional Tip: These codes are generated internally by the Secretariat within CyberPass. Contact FIDO team if you have questions regarding payment status.

Step 15 — Vendor Verification of Implementation Name

Under Vendor Verification, verify or modify the Initial Implementation Name (e.g., Secure Gateway Hub SGH-200). This name will be permanently hardcoded into the final FIDO Certificate. Click Submit.

Step 16 — CS Final Review and Name Approval

The Certification Secretariat opens CS Review:

  • Selects Approved under New Name Approval.

  • Note: If the Secretariat rejects the proposed branding name, they will explicitly enter the binding Final Implementation Name into the provided field before clicking Submit.

Step 17 — View Procedure Finalization

Upon completion of all administrative and technical reviews, the stage screen displays Procedure Finalized!. Click the See Results button.

Step 18 — Access Final Certification Results & Badge

Clicking See Results redirects you to the official Procedure Result dashboard. Here you can inspect your FIDO Server Certification details, view the official FIDO2 Certified Logo, and click Open Certificate to download or view your digital certificate.

Step 19 — Manage Issued Certificates in CyberPass

To access and view all official FIDO certifications at any time, open the top-left sidebar menu and select Certificates.

For detailed information on viewing and managing FIDO certificate records, please check out this article from CyberPass Help Center.

5. Key Notes

  • Role Segregation: Vendor users submit testing dates, forms, and name verifications. Evaluation reviews, JSON/PDF report uploads, purchase code entries, and verdict assignments are strictly restricted to the Certification Secretariat.

  • External Execution: Conformance testing and Interoperability event scheduling occur on external FIDO tools/portals. CyberPass acts as the central compliance, tracking, and audit vault.

  • Naming Corrections: If the Secretariat disapproves a name edit submitted during Vendor Verification, they will supply the approved Final Implementation Name directly during CS Review.

6. Troubleshooting

Issue

Cause

Solution

Target product is missing from the dropdown during creation

Product profile was not added prior to procedure initiation.

Navigate to CyberPass sidebar menu > Products, create your product entry, and then restart the procedure setup.

Workflow step shows a lock icon

Stage requires action from the Certification Secretariat (you are in Viewer mode).

Check the status message and header actor indicators. Vendor actions cannot proceed until the Secretariat completes their corresponding review and submits a Pass verdict.

Did this answer your question?