Background
Depending on final delivery form and procurement requirements, TrustDB or bundled cryptographic components may require product certification or vendor interoperability qualification.
Scope
In scope:
- Confirm whether the delivery falls within a commercial cryptography product certification catalogue or customer procurement catalogue.
- Execute required testing/certification or document reliance on separately certified HSM, KMS, gateway, certificate, and platform products.
- Complete vendor interoperability reports for the supported domestic OS, CPU, database, HSM/SDF, KMS, TLCP, and BCOS stack.
Out of scope:
- Inferring TrustDB product certification from a certified third-party component.
Proof, storage, and compatibility impact
- Phase: Formal Qualification
- Workstream: Compliance
- Risk: High
- Changes must preserve TrustDB evidence semantics, durable publication boundaries, bounded large-data behavior, and explicit trust roots.
Acceptance criteria
Validation plan
- Certificate/report authenticity and scope review.
- Annual renewal, vulnerability, and configuration-change process tabletop.
Dependencies
Schedule
- Start: 2027-01-11
- Target: 2027-04-30
Background
Depending on final delivery form and procurement requirements, TrustDB or bundled cryptographic components may require product certification or vendor interoperability qualification.
Scope
In scope:
Out of scope:
Proof, storage, and compatibility impact
Acceptance criteria
Validation plan
Dependencies
Schedule