K07 · evidence-bundled critical-infrastructure assurance
Assurance evidence package
Direct answer
Assemble claim-to-control-to-test-to-evidence traceability, provenance, currentness, signatures, limitations, defects, and decision receipts.
Authority and evidence boundary. K07 publishes knowledge architecture, bounded reference records, procurement structures, local validation tools, signed synthetic fixtures, and point-in-time source review. It does not certify a facility, award a contract, authorize an operation, prove truth, establish deployment, or claim current operation.
Statement of work
Assemble claim-to-control-to-test-to-evidence traceability, provenance, currentness, signatures, limitations, defects, and decision receipts.
| Current package ID | WP-K07-08 |
|---|---|
| Inherited stable ID | WP-K06-08 |
| Period | To be defined by the acquiring authority; no duration is inferred by the public pattern. |
| Dependencies | WP-K06-01; WP-K06-02; WP-K06-03; WP-K06-04; WP-K06-05; WP-K06-06; WP-K06-07 |
Required outcomes
- complete claim-control-test-evidence graph
- signed or checksummed evidence manifest
- defeater and stale-state report
- decision-ready human and machine reports
Owner-furnished information
- all approved work-package artifacts
- source snapshots
- test evidence
- exceptions and incidents
- authority and acceptance records
Contractor deliverables
- machine-readable assurance graph
- human assurance report
- evidence manifest
- defeater status
- readiness recommendation
Performance standards
- Every mandatory dependency resolves or is visibly unavailable
- Every artifact has a digest and provenance record
- Negative, disputed and superseded evidence remains accessible
Quality surveillance
- graph validation
- manifest replay
- independent audit
Exclusions
- no suppression of negative evidence
- no conversion of unavailable evidence into pass
Acceptance matrix
| Criterion | Required result | Assessment | Outcome vocabulary |
|---|---|---|---|
| Completeness | Every mandatory dependency resolves or is visibly unavailable | graph validation | PASS, FAIL, PARTIAL, UNAVAILABLE, or NOT APPLICABLE with rationale |
| Integrity | Every artifact has a digest and provenance record | manifest replay | PASS, FAIL, PARTIAL, UNAVAILABLE, or NOT APPLICABLE with rationale |
| No suppression | Negative, disputed and superseded evidence remains accessible | independent audit | PASS, FAIL, PARTIAL, UNAVAILABLE, or NOT APPLICABLE with rationale |
Bid-evaluation criteria
- evidence architecture
- machine-readable delivery
- signature and custody controls
- correction and supersession workflow
- price realism and schedule credibility
- data-rights and evidence-delivery terms
- subcontractor and supply-chain transparency
Evidence rights
- The acquiring authority receives perpetual access to final reports, schemas, manifests, acceptance evidence, defects, and correction history within the negotiated data-rights regime.
- Contractor proprietary methods may remain protected only when they do not prevent independent replay of required results.
- Source artifacts, hashes, versions, tool outputs, and negative findings required for acceptance cannot be withheld merely because they are unfavorable.
- No clause transfers authority, licensing status, or ownership beyond the signed contract and governing law.
Negative-result clauses
- A failed, partial, stale, disputed, unavailable, or superseded result must be delivered and may not be converted into a pass.
- Discovery of a safety, authority, evidence, or common-cause defect triggers prompt notice and preserves stop authority.
- Acceptance of one deliverable does not waive latent defects, falsified evidence, or later-discovered nonconformance.
- The final package must distinguish work completed, work not performed, evidence unavailable, and owner decisions pending.
Data requirements
- all approved work-package artifacts
- source snapshots
- test evidence
- exceptions and incidents
- authority and acceptance records