{
  "acceptanceEvidence": [
    "source artifacts",
    "versioned diagrams",
    "finding reproducibility",
    "owner and due date"
  ],
  "acceptanceMatrix": [
    {
      "acceptanceState": "PASS, FAIL, PARTIAL, UNAVAILABLE, or NOT APPLICABLE with rationale",
      "assessmentMethod": "finding replay",
      "criterion": "Reproducibility",
      "requiredResult": "Every finding cites a versioned source artifact"
    },
    {
      "acceptanceState": "PASS, FAIL, PARTIAL, UNAVAILABLE, or NOT APPLICABLE with rationale",
      "assessmentMethod": "coverage matrix",
      "criterion": "Boundary coverage",
      "requiredResult": "IT, OT, power, cooling, physical, timing, model and recovery planes are assessed"
    },
    {
      "acceptanceState": "PASS, FAIL, PARTIAL, UNAVAILABLE, or NOT APPLICABLE with rationale",
      "assessmentMethod": "activity log review",
      "criterion": "No uncontrolled scanning",
      "requiredResult": "Fragile OT is not actively scanned without site approval"
    }
  ],
  "bidEvaluationCriteria": [
    "cyber-physical architecture depth",
    "OT-safe assessment method",
    "evidence provenance tooling",
    "independence from product resale incentives",
    "price realism and schedule credibility",
    "data-rights and evidence-delivery terms",
    "subcontractor and supply-chain transparency"
  ],
  "canonicalUrl": "https://xn--mwe.com/procurement/work-packages/architecture-assessment/",
  "dataRequirements": [
    "logical and physical diagrams",
    "configuration baselines",
    "identity and key architecture",
    "power and cooling controls",
    "OT and timing interfaces"
  ],
  "deliverables": [
    "architecture findings",
    "trust-zone model",
    "critical-interface register",
    "defeater register",
    "remediation roadmap"
  ],
  "dependencies": [
    "WP-K06-01",
    "WP-K06-02"
  ],
  "evidenceRights": [
    "The acquiring authority receives perpetual access to final reports, schemas, manifests, acceptance evidence, defects, and correction history within the negotiated data-rights regime.",
    "Contractor proprietary methods may remain protected only when they do not prevent independent replay of required results.",
    "Source artifacts, hashes, versions, tool outputs, and negative findings required for acceptance cannot be withheld merely because they are unfavorable.",
    "No clause transfers authority, licensing status, or ownership beyond the signed contract and governing law."
  ],
  "exclusions": [
    "no certification claim",
    "no uncontrolled active scanning of fragile OT"
  ],
  "id": "WP-K06-03",
  "inputs": [
    "CCE outputs",
    "logical and physical architecture",
    "configuration baselines",
    "trust relationships"
  ],
  "k07Id": "WP-K07-03",
  "name": "Cyber-physical architecture assessment",
  "negativeResultClauses": [
    "A failed, partial, stale, disputed, unavailable, or superseded result must be delivered and may not be converted into a pass.",
    "Discovery of a safety, authority, evidence, or common-cause defect triggers prompt notice and preserves stop authority.",
    "Acceptance of one deliverable does not waive latent defects, falsified evidence, or later-discovered nonconformance.",
    "The final package must distinguish work completed, work not performed, evidence unavailable, and owner decisions pending."
  ],
  "objective": "Assess separation, identity, management planes, OT, power, cooling, timing, physical sensing, autonomy, evidence, and recovery against the consequence model.",
  "releaseId": "K12-2026-08-16",
  "slug": "architecture-assessment",
  "statementOfWork": {
    "contractorDeliverables": [
      "architecture findings",
      "trust-zone model",
      "critical-interface register",
      "defeater register",
      "remediation roadmap"
    ],
    "dependencies": [
      "WP-K06-01",
      "WP-K06-02"
    ],
    "exclusions": [
      "no certification claim",
      "no uncontrolled active scanning of fragile OT"
    ],
    "governmentOrOwnerFurnishedInformation": [
      "logical and physical diagrams",
      "configuration baselines",
      "identity and key architecture",
      "power and cooling controls",
      "OT and timing interfaces"
    ],
    "performanceOutcomes": [
      "versioned architecture baseline",
      "trust and management-plane analysis",
      "defeater and common-cause register",
      "prioritized remediation roadmap"
    ],
    "performanceStandards": [
      "Every finding cites a versioned source artifact",
      "IT, OT, power, cooling, physical, timing, model and recovery planes are assessed",
      "Fragile OT is not actively scanned without site approval"
    ],
    "periodOfPerformance": "To be defined by the acquiring authority; no duration is inferred by the public pattern.",
    "purpose": "Assess separation, identity, management planes, OT, power, cooling, timing, physical sensing, autonomy, evidence, and recovery against the consequence model.",
    "qualitySurveillance": [
      "finding replay",
      "coverage matrix",
      "activity log review"
    ]
  }
}
