K05 assurance architecture
Readiness Evidence Model
Direct answer
The readiness record contains twenty-nine evidence fields. Missing required fields are not silently ignored; they force a qualified, degraded, unavailable, stale, or suspended state according to the affected claim.
Evidence boundary. These records describe architecture, control relationships, test requirements, and legal-source status. They do not certify a facility, authorize a mission, prove deployment, or replace current facility-specific engineering and legal review.
Field model
- Stable capability ID
- capabilityId
- Required
- Yes
- Evidence
- Canonical identifier independent of marketing name.
- Readiness state
- readinessState
- Required
- Yes
- Evidence
- DESCRIBED, ARCHITECTED, PROTOTYPED, IMPLEMENTED, TESTED, INTEGRATED, DEPLOYED, OPERATING, DEGRADED, SUSPENDED, RETIRED, UNKNOWN, UNAVAILABLE, or STALE.
- Software release
- releaseVersion
- Required
- Yes
- Evidence
- Exact version and release identity.
- Source commit or release hash
- sourceCommit
- Required
- Yes
- Evidence
- Cryptographic link to governed source.
- Reproducible-build result
- reproducibleBuild
- Required
- Yes
- Evidence
- Independent rebuild status and variance.
- Artifact hashes
- artifactHashes
- Required
- Yes
- Evidence
- Hashes for binaries, containers, models, policies, datasets, and configuration bundles.
- SBOM
- sbom
- Required
- Yes
- Evidence
- Machine-readable component inventory and generator/version.
- Known-vulnerability status
- vulnerabilityStatus
- Required
- Yes
- Evidence
- Scan time, databases, exceptions, exploitability and remediation state.
- Test coverage
- testCoverage
- Required
- Yes
- Evidence
- Requirements, code, scenario, fault, environment and safety coverage, not one aggregate percentage.
- Test environment identity
- testEnvironment
- Required
- Yes
- Evidence
- Range, simulator, HIL, staging or field environment and fidelity limits.
- Model provenance
- modelProvenance
- Required
- Conditional
- Evidence
- Model identity, weights hash, architecture, policy, evaluation and approval when a model is used.
- Data provenance
- dataProvenance
- Required
- Conditional
- Evidence
- Training, tuning, evaluation, retrieval and telemetry sources with integrity and use authority.
- Decision policy version
- decisionPolicyVersion
- Required
- Conditional
- Evidence
- Exact action rules, thresholds, overrides and change history.
- Authority record
- authorityRecord
- Required
- Yes
- Evidence
- Competent authority, scope, allowed effects, prohibited outcomes, expiry and revocation.
- Configuration identity
- configurationIdentity
- Required
- Yes
- Evidence
- Facility- and deployment-specific configuration, dependencies and deviations.
- Failure and uncertainty thresholds
- failureThresholds
- Required
- Yes
- Evidence
- Conditions for degrade, stop, safe state, human/federal review, and readiness downgrade.
- Open assurance defeaters
- openDefeaters
- Required
- Yes
- Evidence
- Material challenges that can invalidate or weaken claims.
- Defect register
- defectRegister
- Required
- Yes
- Evidence
- Severity, affected release, disposition, waiver authority, expiry and residual consequence.
- Known incidents
- incidentRecords
- Required
- Yes
- Evidence
- Security, safety, availability, model, data, identity and recovery incidents with correction state.
- Deployment identity
- deploymentIdentity
- Required
- Conditional
- Evidence
- Site, tenant or protected pseudonymous deployment ID, install time, operator and exact artifacts.
- Uptime window
- uptimeWindow
- Required
- Conditional
- Evidence
- Defined observation period, exclusions, degradations and data source.
- Last state transition
- lastStateTransition
- Required
- Yes
- Evidence
- Signed or otherwise integrity-protected readiness-state change and reason.
- Last signed action
- lastSignedAction
- Required
- Conditional
- Evidence
- Most recent decision/action receipt, not proof of correctness.
- Last restoration exercise
- lastRestorationExercise
- Required
- Yes
- Evidence
- Scenario, result, time, data loss, defects and re-attestation.
- Independent verification state
- independentVerificationState
- Required
- Yes
- Evidence
- NOT REQUESTED, INTERNAL ONLY, INDEPENDENTLY REVIEWED, INDEPENDENTLY REPRODUCED, DISPUTED, FAILED, UNAVAILABLE, or STALE.
- Independent verifier
- independentVerifier
- Required
- Conditional
- Evidence
- Verifier identity or protected reference, scope, conflicts and method.
- Last verification time
- lastVerificationTime
- Required
- Yes
- Evidence
- Timestamp and currentness window.
- Unavailable fields
- unavailableFields
- Required
- Yes
- Evidence
- Required fields not available and their consequence for readiness.
- Machine-readable record URL
- machineRecordUrl
- Required
- Yes
- Evidence
- Stable public or authorized machine record.
Independent verification states
NOT REQUESTED · INTERNAL ONLY · INDEPENDENTLY REVIEWED · INDEPENDENTLY REPRODUCED · DISPUTED · FAILED · UNAVAILABLE · STALE