TLS policies
A policy is a published TLS baseline. NoCert evaluates every certificate and every TLS observation against the policies your organization has active, and tells you which checks fail and on what.
The four policies
Section titled “The four policies”| Policy | Version | Checks |
|---|---|---|
| ANSSI | v1.2 (2020-03-26) | 19 |
| BSI TR-02102-2 | v2026-01 | 13 |
| Mozilla Intermediate (TLSRef) | v6.0 | 15 |
| NIST SP 800-52r2 | Rev. 2, with the SP 800-131Ar2 and FIPS 186-5 transitions | 19 |
These are the only policies available. You cannot write your own, and NoCert does not let you switch individual checks on or off inside one.
Each is pinned to a specific published version. When a standards body issues a new revision, it ships as a new policy rather than changing the meaning of your existing results.
Which ones are active
Section titled “Which ones are active”NoCert picks your starting policies at signup, from the country you signed up from. France, Germany and the United States get their national policy plus the Mozilla baseline. Everywhere else starts on Mozilla alone.
An owner changes the selection in Settings → Compliance, on a Business plan. You can run one or two at once, never zero and never more than two.
Changing the selection re-evaluates your assets right away. On a large estate the compliance filters and the action-plan counts finish catching up in the background. The trend chart reflects the new selection from the next day, since it is built from one snapshot a day.
What you see on Pro
Section titled “What you see on Pro”Pro shows the shape of your compliance posture without the specifics.
You get the severity totals (critical, warnings, recommendations), the number of assets involved, and an Action plan listing the categories of problem you have, such as Cryptographic strength or Certificate trust, each with a count.
What stays behind the Business gate is everything that names something: the exact check that failed, which certificates and endpoints it failed on, the observed evidence, and the remediation text. The certificate and endpoint lists still show a per-asset verdict and a finding count, and a lock where the detail would be.
Pro also cannot see or change which policies are active, though evaluation still runs against them.
If you are a viewer restricted to certain tags, a Pro organization hides the counts too. A small scope plus a precise count would identify the asset. The trend chart is unavailable to a scoped viewer on any plan, since it is an organization-wide aggregate with no per-scope version.
What Business adds
Section titled “What Business adds”- The failing check itself, with its identifier, severity and remediation.
- The certificates and endpoints affected by each one.
- A score per active policy, over certificates and over TLS observations.
- Accept risk on a finding, which moves it into a documented register of exceptions rather than hiding it. Operators and owners can record one.
- A trend chart per policy, once two daily snapshots exist.
- CSV evidence exports.
- Compliance filters on the certificate and endpoint lists.
Evidence exports
Section titled “Evidence exports”Business plans can download the evidence behind the screen as CSV. Three sit together in Audit readiness:
- Certificate inventory
- Protocols & ciphers in use
- Posture & alerting evidence
The other two have their own buttons: the register of exceptions in Accepted risks, and the key-exchange data in the Post-quantum readiness card under Upcoming requirements.
An export stops at 10,000 rows and says so in its last line. The same ceiling applies to the screen itself, where a Partial data chip appears once an estate is large enough to hit it.
Exports follow your access. A tag-restricted viewer exports only their scope.
The trial is a Business trial, so all of this is live during it, and locks when the trial ends. Download what you need before that if you are still deciding.