# MCP Servers Are Tier-0 Infrastructure

- **Artifact ID:** CHQ-SCA-2026-002
- **Canonical source ID:** CHQ-J-2026-002
- **Version:** v1.0
- **Status:** ISSUED
- **Public record:** https://record.cybersecurityhq.com/assessments/chq-sca-2026-002
- **Machine-record SHA-256:** `d699c1af79bb54b03b23bb70f4e832534ffd8bd9992a985f2c49d13b33b93dd3`

## Complete structured record

```json
{
  "id": "CHQ-J-2026-002",
  "title": "MCP Servers Are Tier-0 Infrastructure",
  "status": "ISSUED",
  "issuance_date": "2026-01-23",
  "version": "v1.0",
  "judgment_type": "ARCHITECTURAL",
  "classification_tag": "Execution Broker Tier-0 Control-Plane Classification",
  "decision_surfaces_safe": [
    "Breach Causality Attribution (Organizational)",
    "Retrospective Control Interpretation Defense",
    "Investment Denial Justification — derivative of control-plane criticality"
  ],
  "decision_surfaces_unsafe": [
    "Individual Accountability Insulation",
    "Sworn Technical Assertion (Personal)",
    "Insurance Coverage Disputes",
    "Transactional Security Representation Defense",
    "Vendor–Operator Liability Boundary",
    "Protocol Correctness and Specification Compliance",
    "Investment Prescription or Duty of Care Thresholds",
    "Comparative Infrastructure Ranking",
    "Criminal Proceedings",
    "Public Communications and Investor Disclosures",
    "Employment and HR Accountability",
    "Environments Without Broker-Mediated Privileged Impact"
  ],
  "load_bearing_assumptions": [
    {
      "id": "A1",
      "label": "Execution Brokerage as Control Plane",
      "type": "LOAD-BEARING",
      "text": "Infrastructure that mediates or authorizes execution across access-controlled resources occupies the control plane regardless of protocol or deployment form."
    },
    {
      "id": "A2",
      "label": "Privileged Impact as Criticality Threshold",
      "type": "LOAD-BEARING",
      "text": "Control-plane criticality is determined by the capability to enable privileged impact across trust boundaries, not by realized harm or operational frequency."
    },
    {
      "id": "A3",
      "label": "Authorization-Centric Attribution",
      "type": "LOAD-BEARING",
      "text": "Breach causality and control adequacy are evaluated based on authorization and mediation roles, not solely on endpoint compromise or tool misuse."
    },
    {
      "id": "A4",
      "label": "Implementation-Agnostic Invariance",
      "type": "CONTEXTUAL",
      "text": "The architectural consequence applies independent of protocol name, vendor implementation, or deployment scope."
    }
  ],
  "core_judgment": "When infrastructure brokers or mediates execution authority that enables autonomous systems to cause or authorize actions with privileged impact across trust boundaries against access-controlled resources, that infrastructure functions as Tier-0 control-plane infrastructure for purposes of breach causality attribution and control adequacy evaluation, irrespective of protocol implementation, deployment scope, or vendor classification.",
  "observability_conditions": [
    {
      "number": 1,
      "title": "Execution Brokerage Evidence",
      "text": "Infrastructure is treated as brokering or mediating execution authority where it:\n• Receives requests from autonomous systems and translates, routes, or authorizes those requests to downstream resources, or\n• Holds, issues, manages, or applies credentials, tokens, entitlements, or scopes used by autonomous systems, or\n• Makes authorization decisions that determine whether autonomous system requests proceed.\n\nMediation of authorization is sufficient; direct execution is not required.\nInfrastructure providing only static configuration, read-only context, or non-actionable data without participating in authorization or permission application does not meet the brokerage threshold."
    },
    {
      "number": 2,
      "title": "Privileged Impact Evidence",
      "text": "Actions are treated as having privileged impact across trust boundaries where, based on effective permissions, scopes, or entitlements in force at the time, brokered authority enables an autonomous system to:\n• Modify, create, delete, or reconfigure data, services, identities, or infrastructure beyond its native execution context, or\n• Trigger operations with security, financial, operational, or compliance consequences in downstream systems, or\n• Traverse authentication, authorization, or network boundaries that would otherwise constrain it absent the brokered authority.\n\nPrivileged impact is assessed by configured capability, not by realized harm.\nCapability must be demonstrable from deployed configurations and authorization artifacts, not inferred from hypothetical exploit chains."
    },
    {
      "number": 3,
      "title": "Access Control Governance Evidence",
      "text": "Resources are treated as access-controlled where:\n• Access is mediated by authentication, authorization, identity verification, or entitlement mechanisms, or\n• Access policies restrict availability based on principal identity or attributes, or\n• Access events are logged or audited in a manner that attributes activity to a principal.\n\nAny identity-mediated access boundary is sufficient.\nResources lacking identity mediation, access restriction, and principal-attributed logging are outside scope."
    }
  ],
  "boundary_of_safe_citation": "This judgment establishes architectural classification of execution-broker infrastructure for purposes of causality attribution and control adequacy evaluation.\n\nIt must not be cited to:\n• Assign or deflect vendor or operator commercial liability\n• Prescribe specific security controls, budgets, or investments\n• Establish negligence, duty of care, or breach of standard\n• Interpret insurance coverage, exclusions, or claim validity\n• Validate transactional disclosures or representations\n• Assess protocol correctness or standards compliance\n• Rank Tier-0 infrastructure by relative priority\n• Support criminal intent or prosecutorial theories\n• Justify or preclude employment or HR actions\n• Assess materiality or adequacy of public disclosures",
  "retirement_triggers": [
    {
      "number": 1,
      "title": "Execution Brokerage Obsolescence",
      "text": "Widespread production adoption of architectures in which authorization and attribution bind directly to resources, eliminating execution brokerage as a distinct control-plane layer."
    },
    {
      "number": 2,
      "title": "Tier-0 Framework Supersession",
      "text": "Establishment of industry or regulatory frameworks that supersede or fundamentally redefine Tier-0 classification, rendering functional equivalence claims obsolete."
    },
    {
      "number": 3,
      "title": "Systemic Broker Hardening",
      "text": "Adoption of execution broker architectures with cryptographically enforced, non-bypassable authorization such that broker compromise cannot produce privileged impact across trust boundaries, eliminating systemic control-plane failure modes."
    },
    {
      "number": 4,
      "title": "Architectural Agent Capability Constraint",
      "text": "Regulatory or industry standards that make privileged impact across trust boundaries architecturally impossible for autonomous systems, independent of configuration or policy."
    },
    {
      "number": 5,
      "title": "Mandatory Reassessment",
      "text": "Formal reassessment required 24 months after issuance, and at 24-month intervals thereafter, to evaluate whether execution brokerage remains a control-plane critical architectural pattern."
    },
    {
      "number": 6,
      "title": "Architectural Inflection Review",
      "text": "Immediate reassessment upon credible evidence of production adoption of agent-to-resource interaction architectures that eliminate or fundamentally transform execution brokerage, even absent formal obsolescence."
    }
  ]
}
```
