# Certification levels

> The three inspect.software certification levels — Certified (A), Certified with Excellence (AA), and Certified AAA — how each maps to the calibrated health index, what a level asserts, and how levels change.


A repository whose latest inspection places it in one of the top three
[rating bands](/wiki/scoring-bands) holds an inspect.software
**certification level**. The level is nothing more — and nothing less — than
the band the published evidence supports, stated in the vocabulary of a
certification mark:

| Level | Grade | Band | Health index |
| ----- | ----- | ---- | ------------ |
| **Certified AAA** | AAA | Exceptional | 93–100 |
| **Certified with Excellence** | AA | Excellent | 80–92 |
| **Certified** | A | Good | 65–79 |

Repositories below the *Good* band hold no certification level; their reports
state a diagnosis — [Moderate, Weak, At Risk, or Critical](/wiki/scoring-bands)
— not an award. The [calibration of the index](/wiki/health-index) gives each
level percentile meaning across the public record: *Certified AAA* marks
roughly the top 5% of inspected open source.

## What a level asserts

A certification level asserts exactly what the report behind it asserts:
measured, publicly visible engineering, maintenance, security, and governance
practice under a [versioned methodology](/methodology) — nothing more. It is
not a code audit, not a security guarantee, and not an endorsement — see
[signals, not warranties](/wiki/signals-not-warranties). The full evidence for
any level is one click away in the repository's public report.

## How a level is earned

Every inspection — free public-interest coverage or
[on-demand certification](/pricing) — runs the identical methodology, and the
level follows mechanically from the resulting band. Payment buys an
inspection; it cannot buy a level, and no commercial relationship can move a
published result.

## How a level changes

Levels track the latest published inspection. A re-inspection that moves the
index across a band boundary moves the level with it, in either direction —
a certification that could not be lost would assert nothing. Because band
thresholds and the calibration curve are part of the versioned methodology,
any change that could move levels is dated and documented in
[methodology versions](/wiki/methodology-versions).

## Badges

The embeddable [GitHub badge](/badges) always shows the current index and
band color, so a certified repository's badge already reflects its level.
Visually distinct badge marks per certification level are being introduced;
until they ship, the standard badge is the certification mark.
