Technical checklist

The technical counterpart to the legal checklist. To be completed before the conformity review and attached to the file.

Product: ______________________ Exact version: ______________________

Date: ____________ Owner: ______________________


Bill of materials

  • 1. The SBOM is generated automatically by the build chain, with no manual step. → Generating SBOMs
  • 2. The format and version match the company decision and are identical to those of other products. → Formats
  • 3. Transitive depth is covered, and completeness is declared honestly in the document.
  • 4. The quality score is above the threshold, and the gap between build SBOM and analysed SBOM is within limits. → Quality
  • 5. The SBOM is signed and accompanied by a provenance attestation. → Signing
  • 6. The SBOM is published to the steering platform and archived with indexing by hash.

Build chain

  • 7. Blocking policies are active in CI: critical vulnerabilities, prohibited licences, missing SBOM. → CI/CD integration
  • 8. Current waivers are documented and every one carries an expiry date.

Vulnerabilities

  • 9. Continuous monitoring is active on this product, across all shipped versions. → Continuous monitoring
  • 10. Uncorrected alerts carry a VEX with a standardised justification. → VEX
  • 11. Security advisories are published for fixed vulnerabilities, in a machine-readable format.

Product security

  • 12. The risk assessment is current for this version, and the Annex I traceability matrix is complete. → Secure by design
  • 13. The security tests in the plan have been run and their reports archived.
  • 14. The update mechanism is described, tested — including failure and rollback — and security fixes are separable from functional changes. → Secure updates

Response

  • 15. The CVD channel is live for this product, security.txt is valid and not expired, and the reporting procedure has been tested within the last twelve months. → Disclosure policy · 24-hour procedure

Reservations (open points, with owner and deadline):


CISO opinion: favourable ☐ favourable with reservations ☐ unfavourable ☐

Name, signature, date: ______________________