CNCF Project Maturity & Graduation
Every project underneath this course's nine tracks — Argo, Backstage, Cilium, Istio, Kyverno, OpenTelemetry, Prometheus — sits somewhere on a three-rung ladder the CNCF maintains for exactly this reason: Sandbox, Incubating, Graduated. Each cert's own blueprint page tells you what's on the exam. None of them tell you why the CNCF bothers ranking the projects underneath those exams at all, what actually gets checked at each rung, or why a project climbing — or conspicuously not climbing — is a signal worth reading on its own, independent of whatever this quarter's blueprint says. This page covers the ladder itself: what each tier actually certifies about a project's governance and adoption (not its code quality), how the Technical Oversight Committee reviews and votes on a promotion, and — the part with the most direct payoff for someone working this course's certification ladder — how maturity does and doesn't decide which projects get their own exam in the first place.
Think of a small business, not a school grade. Sandbox is a garage startup: anyone can open one, the only real requirement is agreeing to a basic code of conduct, and nobody's auditing your books yet. Incubating is a business with real, paying customers and more than one person signing checks — enough of a track record that a bank takes it seriously. Graduated is the public company: independently audited financial statements, a board that isn't just the founder's family, and a legal requirement to publish who your customers actually are. Nothing about "garage startup" versus "public company" tells you which one makes the better product — plenty of garage startups build things a public company never could. What it tells you is how much outside scrutiny the business has survived, and how much could go wrong before someone besides the founder notices. The CNCF's three-tier ladder measures the exact same thing about an open-source project.
Three rungs, one ladder: Sandbox, Incubating, Graduated
☺ Like you're 10: Garage startup, funded startup with real customers, public company with auditors — three tiers, nothing fancier underneath.
The CNCF has organized every project it hosts into exactly three maturity tiers since its early years under the Linux Foundation, borrowing the general shape — a lightweight entry stage that graduates into progressively stricter ones — from the older Apache Software Foundation incubator model. Sandbox is the entry tier: a project that's cloud-native in scope, has adopted the CNCF's Code of Conduct, and carries an OSI-approved open-source license can apply, with no requirement yet that it be vendor-neutral, widely adopted, or even particularly stable. Incubating is the middle tier, reserved for projects that have started proving themselves: real production adoption, and — critically — committers drawn from more than one organization, so the project's continued existence doesn't depend on a single company's goodwill. Graduated is the top tier, reserved for projects that have cleared a strict, published bar on governance, security, and breadth of adoption. Kubernetes was the first project to reach Graduated, in 2018; Prometheus and Envoy followed the same year as the second and third. Every project this course's nine certifications sit on top of has climbed this same ladder, at its own pace, on its own schedule.
What actually gets checked at each gate
☺ Like you're 10: None of these questions are "is the code good?" — they're all "who else is depending on this, and who's watching the books?"
It's worth naming plainly what the criteria are not asking, because it's easy to assume otherwise: nothing in the CNCF's published graduation criteria scores test coverage, API stability, documentation quality, or how clever the architecture is. Every criterion is either an adoption question — is anyone besides the maintainers actually running this in production, and can they say so publicly — or a governance question — is any one company able to unilaterally kill or capture this project, and has anyone independent checked its security posture. Moving from Sandbox to Incubating is mostly the first adoption checkpoint: committers from at least two organizations (so the project survives one company losing interest), a documented pace of releases, and at least a handful of production adopters willing to be named. Moving from Incubating to Graduated raises both bars sharply: a maintained OpenSSF Best Practices Badge, an explicit and public governance document spelling out how decisions and committer promotions actually happen, a completed and published independent security audit, and a public adopter list broad and diverse enough to show the project isn't one company's internal tool wearing an open-source license.
## Graduation criteria checklist — condensed shape of a real ## CNCF TOC graduation review issue (per-project details vary) - [x] Committers from at least 2 organizations - [x] Achieved and actively maintains an OpenSSF Best Practices Badge - [x] Publicly documented, formal project governance - [x] Publicly documented, formal committer process - [x] Completed an independent, published security audit - [x] Public adopters list — diverse use cases, named production users - [ ] TOC sponsor confirmed - [ ] Public comment period closed, no unresolved objections - [ ] 2/3 supermajority TOC vote scheduled
The bar gets harder to fake as you climb, on purpose. A project can claim "we have production users" in a README with zero verification. A published, independent security audit and a maintained OpenSSF badge are both externally checkable — someone other than the maintainers has to actually do the work, and the result is public. Graduated status is expensive specifically because self-reported claims don't count for it.
The TOC, a sponsor, and a vote — how a promotion actually happens
☺ Like you're 10: A project can't just declare itself grown-up — someone already on the inside has to vouch for it, in public, where anyone can object.
The CNCF's Technical Oversight Committee (TOC) — an elected body that oversees the technical direction of the entire CNCF project portfolio, landscape, and maturity process — is who actually moves a project between tiers, and it does not do it quietly. A project moving from Incubating to Graduated needs a sitting TOC member willing to sponsor it: put their own standing behind a public review issue vouching that the project meets the criteria. That review issue sits open for a public comment period — genuinely public, on GitHub, where any maintainer, end user, or competitor can raise an objection on the record before a vote happens. Only after that window closes does the TOC actually vote, and the bar rises with the tier: Sandbox admission today is largely a staff-and-community screening process against the published entry criteria, while Incubating and Graduated moves require the TOC itself to vote, with Graduated specifically requiring a two-thirds supermajority — not a simple majority — reflecting how much more is being vouched for. Sandbox isn't a permanent parking spot, either: the TOC conducts an annual health review of Sandbox projects, and ones that show no meaningful activity get archived and dropped from the CNCF landscape rather than left to linger indefinitely.
Pick any one project this course examines — Cilium, Istio, Kyverno, whichever you're studying next — and find its actual entry in the CNCF landscape. Note its current tier, then look up when it last moved. If it's Incubating, that move date tells you roughly how long it's been sitting there — which is itself informative: a project that's been Incubating for five years and shows no graduation review in flight is a different situation than one that joined eighteen months ago and is already under TOC sponsorship for the next step.
Reading graduation as a signal, not a rubric
☺ Like you're 10: "Graduated" tells you the company survived an audit. It doesn't tell you their product is the one you should buy.
The honest read of this ladder is narrower than it sounds. Graduated status is strong evidence that a project is vendor-neutral, well-governed, and adopted widely enough that betting a career or a production stack on it carries low political risk — no single company can quietly kill it, and an outside auditor has looked at its security posture. It is not evidence that the project is technically superior to an Incubating or Sandbox alternative, that its roadmap is more ambitious, or that it fits your specific use case better. Plenty of heavily used, actively developed, genuinely excellent projects sit in Incubating for years — not because they're unstable, but because the adoption-breadth and audit bar for Graduated is genuinely expensive to clear, and clearing it takes calendar time even for a project with no technical gaps at all. Treating "Incubating" as a synonym for "early access" or "not ready" is the single most common misreading of this ladder, and it's worth actively unlearning.
A project can be Incubating and running in thousands of production clusters; a project can be Graduated and still be the wrong tool for what you're building. The ladder measures governance maturity and adoption breadth — not fit, not technical quality, not how recently a feature shipped. Use it to gauge organizational risk, not to shortlist tools.
"I once talked a team out of a genuinely better-fit tool because it was 'only Sandbox' and picked the Graduated alternative instead — and the Graduated one turned out to be a worse match for what we were actually building. Graduated bought us procurement approval in about a day instead of a month of security review. It didn't buy us the right architecture. I conflate those two things less now."
Where this course's nine certifications sit on the ladder
☺ Like you're 10: Nine exams, nine projects — and they are deliberately not all standing on the same rung.
Read against the ladder, this course's own certification lineup turns out to be a genuine mix of rungs, not a curated list of only-Graduated projects — which is itself informative about how the CNCF and the wider Linux Foundation actually decide to build a certification, covered in the next section. The CGOA and LFCS rows below are the two genuine exceptions to "one exam, one project," and are worth reading closely rather than skimming past.
| Track | Underlying project(s) | Tier at time of writing | Note |
|---|---|---|---|
| CGOA | GitOps practice — Argo CD & Flux | Graduated (both) | Not one project's maturity — a practice-level exam the CNCF's GitOps working group sponsors across two separately Graduated projects |
| CAPA | The Argo project family | Graduated (Dec 2022) | All four Argo siblings graduated together as one umbrella |
| CBA | Backstage | Incubating | Widely adopted as a developer-portal foundation well before any graduation review |
| CCA | Cilium | Graduated (Oct 2023) | Also underlies the default CNI on several managed Kubernetes offerings |
| ICA | Istio | Graduated (Jul 2023) | Service mesh — one of the older projects to reach Graduated status |
| KCA | Kyverno | Incubating | Its exam launched while the project was still Incubating, not after it graduated |
| OTCA | OpenTelemetry | Incubating | One of the most widely adopted CNCF projects by instrumentation volume regardless of tier |
| PCA | Prometheus | Graduated (2018) | The CNCF's second-ever graduated project, alongside Envoy |
| LFCS | Linux itself | Not applicable | A Linux Foundation professional certification, not a CNCF project — never on this ladder at all |
Maturity tiers are not permanent facts — a project sitting at Incubating today can graduate next quarter, and this table reflects a snapshot as of when this page was written. Before you repeat a tier claim in an interview, a design doc, or anywhere it needs to be current, check the live CNCF landscape yourself. The same instinct applies to anything in this course touching exam price, format, or pass mark — always verify officially before relying on it.
Does maturity decide which projects get their own exam?
☺ Like you're 10: Getting your own exam is more like getting popular enough that people start asking for one — not a prize handed out for reaching the top rung.
The table above already answers this in practice: no, not directly. Kyverno and OpenTelemetry both got dedicated certifications while sitting in Incubating, and Backstage's exam exists at the same tier today. If Graduated status were a prerequisite for a certification to exist, none of those three would have one yet. What actually drives the decision to build an exam around a project is closer to a demand signal than a maturity gate: a large enough End User community asking for a hiring credential, a training and certification ecosystem (the Linux Foundation's own training arm, third-party bootcamps, employers) willing to invest in building and maintaining exam content, and — this part does connect back to the ladder — a project whose surface area is stable enough that a certification built around it this year is still accurate two years from now. That last condition is where maturity quietly matters after all: the same criteria that earn a project Graduated status — multiple independent committer organizations, a documented governance process, real production adoption — are also a decent proxy for "this project's API and CLI aren't about to be rewritten out from under an exam blueprint." It's not that graduation unlocks a certification; it's that the qualities graduation measures are close cousins of the qualities that make a certification worth building and safe to maintain.
This is also the cleanest way to understand why CGOA and LFCS don't fit the "one exam, one project" pattern at all. CGOA exists because GitOps as a practice had enough cross-project demand — Argo CD and Flux users alike wanted a vendor-neutral way to signal the underlying skill — that the CNCF built a practice-level exam sitting above both projects rather than picking one. LFCS predates the CNCF's maturity ladder entirely: it's a Linux Foundation professional certification about operating a Linux system, with no CNCF project, no TOC review, and no landscape entry behind it at all — a useful reminder that not everything in a "cloud native" study plan is CNCF-governed just because it shares a jacket and a badge wall with things that are. Multi-Project Platform Thinking picks up this same "compose, don't assume one governance model" instinct at the platform-architecture level rather than the certification level.
Foxy: So if I'm choosing which cert to chase next, I should just filter for "Graduated," right? Skip the Incubating ones?
Gizmo: Obviously! Graduated means grown-up, Incubating means baby project, still figuring itself out. Only chase the gold stars! 😈
Nutty: That's not what my inventory says, Gizmo. Kyverno's KCA and OpenTelemetry's OTCA are both Incubating right now and both are running in production everywhere. Skipping them on tier alone would mean skipping two very real, very employable skills.
Timmy: Right. The tier tells you about governance risk and audit history — whether one company could kill the project tomorrow. It doesn't tell you whether the skill is in demand, or whether the tool is any good.
Foxy: Okay, so what should actually decide the order?
Nutty: The same thing that decides everything else on this ladder — what's already in the order of attack: your existing stack, your job market, and the prerequisite chain. Maturity tier is context you read alongside that, not a filter you apply instead of it.
Gizmo: Fine, fine. Still would've been a much shorter page if the answer were just "chase gold stars."
1. Name the CNCF's three maturity tiers in order, and describe in one sentence what each one is actually checking. 2. What role does a sitting TOC member's sponsorship play in a project's promotion, and why does the public comment period matter as much as the sponsor does? 3. What's the difference between the vote threshold for Sandbox admission and the vote threshold for Graduated status? 4. Give one concrete reason a project might stay Incubating for years without that meaning it's unstable or poorly adopted. 5. Name two of this course's nine certifications whose underlying project was Incubating, not Graduated, when its exam launched. 6. Why don't CGOA and LFCS fit the "one exam, one project, one tier" pattern the other seven tracks follow?
Check your answers
- Sandbox (entry tier — checks license, Code of Conduct, and basic cloud-native scope, with no adoption bar yet), Incubating (checks multi-organization committers and documented production adoption), Graduated (checks published governance, an independent security audit, an OpenSSF Best Practices Badge, and a diverse public list of production adopters).
- A sponsor is a sitting TOC member willing to publicly vouch that a project meets the next tier's criteria, opening a public review issue. The comment period matters equally because it's what makes the review an external, adversarial check rather than the project (or even just its sponsor) grading its own homework — anyone can raise an objection on the record before a vote happens.
- Sandbox admission today is largely a staff-and-community screening process against the published entry criteria; Incubating and Graduated both require an actual TOC vote, with Graduated specifically requiring a two-thirds supermajority rather than a simple majority.
- Clearing the Graduated bar — a published governance process, an independent security audit, a broad diverse public adopter list — takes real calendar time and organizational effort to assemble, even for a project with no technical gaps at all; being Incubating for years can simply mean nobody has yet done that paperwork, not that the project is unstable.
- Any two of: KCA (Kyverno), CBA (Backstage), OTCA (OpenTelemetry) — all three launched their certification while their underlying project was Incubating rather than Graduated.
- CGOA certifies GitOps as a cross-project practice sponsored jointly across Argo CD and Flux rather than testing one project's own surface area, so it doesn't map to a single project's tier at all. LFCS is a Linux Foundation professional certification about Linux system administration with no underlying CNCF project, no TOC review, and no CNCF landscape entry — it was never on this ladder to begin with.