Assessment

Assessment process

Defined roles, a content-addressed evidence bundle, and a five-step assessor procedure establish a claim independently of the implementer.

Assessment verifies that a claimed assurance level holds for an exact release. The implementer assembles the evidence; the assessor reproduces the results and walks the requirement set; the outcome is an assessment attestation bound to the release identity.

Roles

Five roles with bounded responsibilities.

  • Implementer — builds and ships the system, operates the conformance pipeline.
  • Scheme owner — maintains the family profile: manifest, vocabulary, required axes.
  • Assessor — evaluates the evidence; independent of the implementer at CAL-3 and above.
  • Relying institution — consumes claims and reports within its own risk and regulatory controls.
  • Framework maintainer — maintains the specification, requirement identifiers, and core corpus.

Evidence bundle

Per assessed release: the claim string, the full report set including Indeterminate results, counterexample packs, family manifests, adapter golden vectors, the obligation registry with its coverage-audit output, maturity-promotion records, crypto registries at CAL-4, and audit artifacts at CAL-5. Every item is content-addressed and referenced from the attestation summary.

Assessor procedure

Five steps, each producing a recorded result.

  • Replay. Re-run the pipeline or replay reports and packs from the bundle; confirm identical verdicts.
  • Seeded violation. Introduce a controlled violation on a required axis; confirm the pipeline blocks with a valid counterexample pack.
  • Requirement walkthrough. Verify each requirement by its tagged method — test, inspect, or analyze.
  • Level criteria. Confirm every criterion of the target level and all levels below it.
  • Claim wording. Confirm external claims use the permitted forms and carry the scope statement.

Assessment attestation

The attestation names the target level, the exact release — VCS commit and build configuration — the claim string, the evidence-bundle root, findings, and the surveillance condition. An attestation binds to a release; product-level statements derive from the set of attested releases.