The specifications, conformance tools, and schemas that make up the Suite, published openly. Every claim in the Suite is meant to be checked against a document anyone can read, which is the standard it holds everyone else to.
What is published
The whole of it, out in the open.
The specifications
Each standard, published in full.
Every standard states its obligations, not an implementation, and is written so that conformance can be assessed from the artifact alone, without access to the process that produced it. A reader with the relevant knowledge can tell from the published document what it requires and what would count as failing it.
Conformance tools
Check an artifact against the standard.
Validators, machine-readable schemas, and reference servers that take a configuration or a document and report where it meets each obligation and where it does not. Published alongside the specifications, so the check is as open as the standard.
Licensing
Free to adopt, no string back to the author.
CSIS is Apache 2.0; the rest are CC0. Every standard is built to be implemented by anyone without further dependency on its author. The specification, the tools, and the schemas are the whole of what you need.
Start with the faces.
Each standard is one face of the solid. Browse them by what they make checkable, then read the one you need.