Skip to content

[Task] Complete required product certification and domestic vendor qualification #488

Description

@ryan-wong-coder

Background

Depending on final delivery form and procurement requirements, TrustDB or bundled cryptographic components may require product certification or vendor interoperability qualification.

Scope

In scope:

  • Confirm whether the delivery falls within a commercial cryptography product certification catalogue or customer procurement catalogue.
  • Execute required testing/certification or document reliance on separately certified HSM, KMS, gateway, certificate, and platform products.
  • Complete vendor interoperability reports for the supported domestic OS, CPU, database, HSM/SDF, KMS, TLCP, and BCOS stack.

Out of scope:

  • Inferring TrustDB product certification from a certified third-party component.

Proof, storage, and compatibility impact

  • Phase: Formal Qualification
  • Workstream: Compliance
  • Risk: High
  • Changes must preserve TrustDB evidence semantics, durable publication boundaries, bounded large-data behavior, and explicit trust roots.

Acceptance criteria

  • Applicability decisions are documented with authoritative basis and external advice where needed.
  • Required certificates and interoperability reports identify exact models, versions, configurations, and expiry/maintenance obligations.
  • Unsupported combinations are removed from claims and production templates.

Validation plan

  • Certificate/report authenticity and scope review.
  • Annual renewal, vulnerability, and configuration-change process tabletop.

Dependencies

Schedule

  • Start: 2027-01-11
  • Target: 2027-04-30

Metadata

Metadata

Labels

assessmentMLPS, commercial cryptography assessment, and external evidencechina-complianceChina compliance engineering and assessment readinessoperationsDeployment, operations, resilience, and platform qualificationtaskEngineering, documentation, CI, release, or repository maintenance work

Type

No type

Projects

Status
Todo

Relationships

None yet

Development

No branches or pull requests

Issue actions