The fastest way to verify physical hardware resilience instead of paper checklist compliance. 45-second passive inspections with contractual warranty leverage before final invoice sign-off.
How APCAF replaces passive compliance checklists with adversarial physical assurance.
APCAF is a way to check whether physical security controls can actually resist common attacker bypasses. Instead of asking only "Is there a lock on the door?", APCAF asks "How could an attacker bypass this lock, and does the current physical installation resist that?"
The security team says: "This door is protected." APCAF doesn't stop at the statement:
An integrated family of open-source standards, field audit tools, and executive playbooks designed to make physical security verification actionable and reproducible.
A standardized taxonomy mapped directly to MITRE ATT&CK tactics, specifying deterministic binary verification thresholds.
Offline-capable inspection switchboard that generates executive invoice hold notices during physical site walks.
Focused, step-by-step physical test execution procedures with prerequisites, pass/fail rules, and remediation clauses.
A 4-step contractual strategy for CISOs to hold final contractor milestone payments until latent hardware defects are remediated.
Select observed field states during your site walk. The engine compiles an executive CISO Vendor Warranty Notice formatted for immediate invoice hold enforcement.
An independent APCAF Quality Assurance inspection identified latent hardware installation deficiencies. In accordance with standard contractual warranty terms, final invoice retainage is placed on hold pending zero-cost vendor rectification.
| Control ID | Observed Condition | Engineering Standard | Required Warranty Rectification |
|---|
Pursuant to Section 14 (Warranty of Workmanship & Fitness for Security Purpose), all identified deficiencies must be rectified by the contractor at zero client budget. Upon written notice of vendor completion, a 45-second verification re-test will be performed to release held retainage funds.
De-identified audit log from a 120,000 sq ft enterprise facility pre-handover assessment.
Pre-handover commissioning walk across 4 main access portals, staging rooms, and server suites prior to tenant sign-off.
125 kHz unencrypted Prox cards handed over; 4.5mm door gap on Suite 4B (exceeding NFPA 80 3.2mm limit); active unauthenticated lobby drop.
CISO delivered standard APCAF Non-Conformance Notice to General Contractor holding final 10% milestone retainage payment.
GC installed continuous stainless steel astragals and DESFire EV3 smartcards at contractor expense. 100% verified 14 days later.
How security executives convert physical QA findings into zero-cost contractor repairs before final invoice clearance.
Add the 1-sentence passive testing authorization to engagement letters to establish explicit non-invasive scope consent.
Auditor inspects RFID encryption, door margins, and link pulses without disrupting site operations.
Regulator gets the compliance PASS. CISO gets the technical Warranty Defect Punch List.
CISO holds contractor retainage payment until hardware is upgraded under warranty at $0 client budget.
Direct mapping between APCAF hardware specifications and global compliance standards.
| APCAF ID | Attack Vector | Hardened Specification | Building / Security Code | ISO 27001:2022 | PCI DSS v4 |
|---|---|---|---|---|---|
| PHY-T1001 | Unencrypted RFID Harvesting | AES-128 / DESFire EV3 Smartcards | ISO/IEC 14443-4 | Control A.7.2 (Physical Entry) | Req 9.2.1 (Access Controls) |
| PHY-T1002 | Mechanical Latch Manipulation | Continuous Steel Astragal (Gap ≤ 3.2mm) | NFPA 80 §6.3.1.7.1 / ANSI SDI A250.8 | Control A.7.4 (Monitoring) | Req 9.1.1 (Perimeter Security) |
| PHY-T1003 | REX Sensor Blind Activation | Directional PIR Deflector Shrouds | NFPA 101 §7.2.1.6.2 / UL 294 | Control A.7.4 (Monitoring) | Req 9.1.1 (Perimeter Security) |
| PHY-T1004 | Unauthenticated Network Tap | Port Shutdown / 802.1X NAC | IEEE 802.1X / NIST PE-3 | Control A.7.4 & A.8.20 | Req 9.1.2 (Network Drops) |
Zero lockpicks, zero destructive tools. The entire APCAF kit fits in a pocket.
Dual-frequency reader to verify whether credentials transmit encrypted AES containers or unencrypted UIDs.
Pocket gauge to measure door frame gaps and verify NFPA 80 §6.3.1.7.1 tolerances (≤ 3.2mm / 1/8" margins).
Non-packet-transmitting dongle to verify whether perimeter network drops broadcast active link states.
APCAF is maintained as an open, vendor-neutral standard by the APCAF Working Group.
Maintained by Zoe Cyber & community contributors. Open working group collaboration via GitHub Issues & Discussions.
Submit new 45-second physical assessment techniques, building code citations, and YAML schemas via GitHub pull requests.
Specification and taxonomy text is licensed under Creative Commons Attribution 4.0 (CC BY 4.0). Interactive tools are licensed under MIT.