Skip to content

KYD® One-Page Summary

KYD® Device Trust Standard — One-Page Summary

Section titled “KYD® Device Trust Standard — One-Page Summary”

Version 1.0 — For Auditors, Insurers, and Procurement Teams


KYD® (Know Your Devices) is a normative standard defining the minimum requirements for establishing and maintaining continuous device trust.

  • Published: January 2026
  • Status: Final v1.0
  • Authority: knowyourdevices.org
  • Trademark: UK Registered (UK00004274651), US/EU Pending

KYD® specifies five core requirements for device trust evaluation:

RequirementPurpose
Device IdentityPersistent identification across operational conditions
Baseline FormationEvidence-based establishment of expected behavior
Device DriftDetection and evaluation of behavioral deviation
Trust EvaluationContinuous derivation of trust states from evidence
Proof RetentionAuditable historical records (minimum 90 days)

KYD® does NOT:

  • ❌ Prevent threats (it evaluates trust)
  • ❌ Replace security tools (it complements them)
  • ❌ Guarantee security outcomes (it provides evidence)
  • ❌ Require specific hardware (implementation-agnostic)

  • Provides verifiable evidence of device trustworthiness
  • Enables risk-based premium adjustments
  • Creates auditable proof of trust over time
  • Addresses device trust gaps in existing frameworks
  • Provides 90+ day historical records
  • Explainable trust decisions with full traceability
  • Clear conformance requirements
  • Vendor-neutral standard (multiple implementations possible)
  • Testable requirements (not subjective claims)

Implementation-Agnostic: KYD® can be implemented in software, hardware, or hybrid architectures.

Reference Implementation: VerifiedDevice (verifieddevice.com) demonstrates the standard in practice.

Conformance: Implementations claiming “KYD®-compatible” must satisfy all normative requirements in the specification.


Evidence-Based: Trust derived from observation, not assumption
Continuous: Evaluation over time, not once at connection
Auditable: Historical records with explainable decisions
Verifiable: Testable requirements, not marketing claims
Open: Multiple implementations allowed, not vendor lock-in


  • Financial Services: High-value transaction devices (ATMs, POS, trading terminals)
  • Healthcare: Medical devices, diagnostic equipment, patient monitoring
  • Industrial: SCADA, PLCs, manufacturing equipment, robotics
  • Critical Infrastructure: Power grid, water systems, transportation
  • Enterprise IT: Corporate devices, remote workers, BYOD environments

“The system shall evaluate device trust in accordance with KYD® Specification v1.0. The implementation must demonstrate conformance with all normative requirements, including persistent device identity, evidence-based baseline formation, drift detection, continuous trust evaluation, and proof retention of at least 90 days.”


KYD® complements (does not replace):

  • ISO 27001 — Information security management
  • NIST CSF — Cybersecurity framework
  • PCI DSS — Payment card security
  • HIPAA — Healthcare data protection
  • SOC 2 — Service organization controls

Website: knowyourdevices.org

Documents Available:

  • KYD® Specification v1.0 (normative)
  • Governance & Versioning Policy (normative)
  • Compatibility & Usage Guidelines (normative)
  • Implementation Guide (non-normative)
  • Reference Architecture (non-normative)

Specification Questions: [email protected]
Trademark & Usage: [email protected]
Implementation Guidance: [email protected]
Commercial Implementation: VerifiedDevice


KYD® is a registered trademark (UK00004274651). US and EU registration pending.

Use of the KYD® name requires adherence to the Compatibility & Usage Guidelines.

The standard is governed independently of any specific implementation or vendor.


This document may be printed, shared, or attached to procurement requirements.

For the complete specification, visit: knowyourdevices.org


KYD® — The Device Trust Standard

Proof, not assumptions.