{
  "schema": "article14-ready/24h-dry-run-v1.0.0",
  "productVersion": "1.0.2",
  "generator": {
    "name": "Article 14 Ready — 24h Dry Run",
    "version": "1.0.2",
    "url": "https://article14ready.com"
  },
  "savedAt": "2026-09-09T12:00:00.000Z",
  "elapsedSeconds": 2040,
  "fields": {
    "organisation": "Example Device Labs (fictional)",
    "product": "Atlas Gateway 4.x",
    "delivery": "Connected hardware / IoT",
    "participants": "Product Security Lead, Regulatory Operations Lead, Engineering On-call, Release Engineering Lead, Compliance Reviewer, Customer Communications Lead",
    "notes": "Fictional worked example, not a customer assessment. One EU-facing connected-product team; releases 4.0–4.2.1; Germany, France and the Netherlands. Ratings represent hypothetical preparation gaps. No live customer data, incidents or credentials were used.",
    "role-security": "Product Security Lead",
    "role-ar": "Regulatory Operations Lead",
    "role-backup": "Engineering On-call",
    "role-engineering": "Release Engineering Lead",
    "role-legal": "Compliance Reviewer",
    "role-comms": "Customer Communications Lead"
  },
  "answers": {
    "24-awareness": "ready",
    "24-trigger": "partial",
    "24-srp": "gap",
    "24-csirt": "ready",
    "24-product": "ready",
    "24-countries": "partial",
    "24-summary": "gap",
    "24-cover": "partial",
    "72-evidence": "partial",
    "72-assessment": "partial",
    "72-measures": "gap",
    "72-versions": "gap",
    "72-sensitive": "partial",
    "72-legal": "gap",
    "72-comms": "ready",
    "final-fix": "ready",
    "final-severity": "partial",
    "final-impact": "partial",
    "final-cause": "partial",
    "final-close": "gap"
  },
  "result": {
    "s24": 67,
    "s72": 36,
    "sFinal": 50,
    "total": 54,
    "band": "Not ready",
    "roles": {
      "completed": 6,
      "score": 100
    },
    "answered": 20
  },
  "report": {
    "version": "1.0.2",
    "generator": {
      "name": "Article 14 Ready — 24h Dry Run",
      "url": "https://article14ready.com"
    },
    "score": {
      "s24": 67,
      "s72": 36,
      "sFinal": 50,
      "total": 54,
      "band": "Not ready",
      "roles": {
        "completed": 6,
        "score": 100
      },
      "answered": 20
    },
    "values": {
      "organisation": "Example Device Labs (fictional)",
      "product": "Atlas Gateway 4.x",
      "delivery": "Connected hardware / IoT",
      "participants": "Product Security Lead, Regulatory Operations Lead, Engineering On-call, Release Engineering Lead, Compliance Reviewer, Customer Communications Lead",
      "notes": "Fictional worked example, not a customer assessment. One EU-facing connected-product team; releases 4.0–4.2.1; Germany, France and the Netherlands. Ratings represent hypothetical preparation gaps. No live customer data, incidents or credentials were used.",
      "role-security": "Product Security Lead",
      "role-ar": "Regulatory Operations Lead",
      "role-backup": "Engineering On-call",
      "role-engineering": "Release Engineering Lead",
      "role-legal": "Compliance Reviewer",
      "role-comms": "Customer Communications Lead"
    },
    "roles": [
      {
        "key": "role-security",
        "label": "Product-security case owner",
        "responsibility": "Own the case, awareness record, trigger decision and evidence trail.",
        "owner": "Product Security Lead"
      },
      {
        "key": "role-ar",
        "label": "Primary SRP submitter",
        "responsibility": "Maintain authorised submission access and retain submission records.",
        "owner": "Regulatory Operations Lead"
      },
      {
        "key": "role-backup",
        "label": "Backup SRP submitter",
        "responsibility": "Cover absence and prove that the reporting handover works.",
        "owner": "Engineering On-call"
      },
      {
        "key": "role-engineering",
        "label": "Engineering remediation lead",
        "responsibility": "Maintain affected-release, technical-impact and corrective-measure evidence.",
        "owner": "Release Engineering Lead"
      },
      {
        "key": "role-legal",
        "label": "Regulatory review owner",
        "responsibility": "Review the reporting position and sensitive-content decisions within the agreed review window.",
        "owner": "Compliance Reviewer"
      },
      {
        "key": "role-comms",
        "label": "User communications owner",
        "responsibility": "Keep product-availability records and approved user instructions consistent.",
        "owner": "Customer Communications Lead"
      }
    ],
    "counts": {
      "ready": 5,
      "partial": 9,
      "gap": 6,
      "na": 0,
      "unanswered": 0
    },
    "findings": [
      {
        "id": "24-awareness",
        "title": "Awareness time is captured and defensible",
        "why": "The statutory clock starts at awareness; the team can point to a timestamp and supporting record.",
        "action": "Add one timestamped intake step and define who can declare the organisation aware.",
        "phase": "24",
        "answer": "ready",
        "status": "Ready",
        "ownerRole": "Product-security case owner",
        "owner": "Product Security Lead",
        "evidence": "A dated intake record identifies the awareness time in UTC, the source evidence and the person who recorded it. A second reviewer can reconstruct the starting point.",
        "priority": "P1",
        "target": "Days 1–7 of preparation"
      },
      {
        "id": "24-trigger",
        "title": "Reportability can be decided without waiting for root cause",
        "why": "The owner can distinguish an actively exploited vulnerability from a severe incident and record uncertainty.",
        "action": "Approve a one-page trigger decision record with escalation criteria and a named decision owner.",
        "phase": "24",
        "answer": "partial",
        "status": "Partial",
        "ownerRole": "Product-security case owner",
        "owner": "Product Security Lead",
        "evidence": "A completed decision record separates confirmed facts, assumptions and unresolved questions, names the decision owner and records the reason for the reporting decision.",
        "priority": "P1",
        "target": "Days 1–7 of preparation"
      },
      {
        "id": "24-srp",
        "title": "A working EU Login and assigned representative exist",
        "why": "At launch, submission is through the SRP interface rather than an API.",
        "action": "Validate the primary and backup representatives' EU Login and SRP access during an out-of-hours drill.",
        "phase": "24",
        "answer": "gap",
        "status": "Gap",
        "ownerRole": "Primary SRP submitter",
        "owner": "Regulatory Operations Lead",
        "evidence": "The primary and backup submitters each complete an authorised access check for the correct manufacturer. Record the date and outcome, without storing passwords or credentials.",
        "priority": "P1",
        "target": "Days 1–7 of preparation"
      },
      {
        "id": "24-csirt",
        "title": "The coordinating CSIRT is pre-identified",
        "why": "The coordinating CSIRT is normally determined from the manufacturer's main EU establishment; the team has recorded the correct route and fallback.",
        "action": "Record the Article 14(7) coordinator-selection route and fallback rationale in the product runbook.",
        "phase": "24",
        "answer": "ready",
        "status": "Ready",
        "ownerRole": "Product-security case owner",
        "owner": "Product Security Lead",
        "evidence": "The runbook identifies the coordinating authority, the route-selection rationale, a fallback and the reviewer. The submitter can locate that record without asking another team.",
        "priority": "P1",
        "target": "Days 1–7 of preparation"
      },
      {
        "id": "24-product",
        "title": "Product name and affected version range are available in under four hours",
        "why": "Both are required in the early warning and should match controlled product records.",
        "action": "Create a maintained product/release inventory with one owner and an emergency lookup path.",
        "phase": "24",
        "answer": "ready",
        "status": "Ready",
        "ownerRole": "Engineering remediation lead",
        "owner": "Release Engineering Lead",
        "evidence": "A timed lookup produces the controlled product name and affected release range, including the source record and its owner, within the team's four-hour exercise target.",
        "priority": "P1",
        "target": "Days 1–7 of preparation"
      },
      {
        "id": "24-countries",
        "title": "Member States of product availability can be identified",
        "why": "The SRP uses known product availability to determine concerned CSIRTs.",
        "action": "Map sales/distribution data to an exportable country list per supported product family.",
        "phase": "24",
        "answer": "partial",
        "status": "Partial",
        "ownerRole": "User communications owner",
        "owner": "Customer Communications Lead",
        "evidence": "A reproducible product-availability extract names the relevant countries, source system, coverage limits, update date and maintenance owner.",
        "priority": "P1",
        "target": "Days 1–7 of preparation"
      },
      {
        "id": "24-summary",
        "title": "A concise, factual early-warning summary can be approved",
        "why": "The team can state known facts without adding speculative attribution or unnecessary sensitive detail.",
        "action": "Pre-approve an early-warning skeleton and a four-hour review service level.",
        "phase": "24",
        "answer": "gap",
        "status": "Gap",
        "ownerRole": "Regulatory review owner",
        "owner": "Compliance Reviewer",
        "evidence": "A factual draft is reviewed and approved within the team's agreed internal target. It distinguishes what is known from what remains under investigation and records the approver and time.",
        "priority": "P1",
        "target": "Days 1–7 of preparation"
      },
      {
        "id": "24-cover",
        "title": "A backup owner can act outside business hours",
        "why": "The clock does not pause for leave, weekends or internal approval queues.",
        "action": "Name a backup submitter and test one handover outside ordinary office hours.",
        "phase": "24",
        "answer": "partial",
        "status": "Partial",
        "ownerRole": "Backup SRP submitter",
        "owner": "Engineering On-call",
        "evidence": "With the primary person unavailable, the backup finds the case, current draft, review contacts and authorised submission route. Keep the timed handover result and unresolved access issues.",
        "priority": "P1",
        "target": "Days 1–7 of preparation"
      },
      {
        "id": "72-evidence",
        "title": "Technical evidence is assembled into one case",
        "why": "Affected versions, exploitation evidence, mitigations and unresolved questions remain traceable.",
        "action": "Define a single incident case record and mandatory links to logs, the software bill of materials (SBOM), release records and remediation evidence.",
        "phase": "72",
        "answer": "partial",
        "status": "Partial",
        "ownerRole": "Product-security case owner",
        "owner": "Product Security Lead",
        "evidence": "One case index links the exploitation evidence, component inventory, release records and mitigation record. An authorised colleague can open those links and identify the latest version.",
        "priority": "P2",
        "target": "Days 8–14 of preparation"
      },
      {
        "id": "72-assessment",
        "title": "An initial severity and impact assessment can be produced",
        "why": "The 72-hour notification needs an initial assessment that separates confirmed findings from investigation.",
        "action": "Adopt a short severity/impact template with confirmed, suspected and unknown sections.",
        "phase": "72",
        "answer": "partial",
        "status": "Partial",
        "ownerRole": "Product-security case owner",
        "owner": "Product Security Lead",
        "evidence": "A dated initial assessment separates confirmed, suspected and unknown impact, references its supporting evidence and identifies who reviews the next update.",
        "priority": "P2",
        "target": "Days 8–14 of preparation"
      },
      {
        "id": "72-measures",
        "title": "Completed mitigation and user measures are documented",
        "why": "Corrective measures taken and measures users can take are required at the notification stage.",
        "action": "Make mitigation timestamps and user-facing instructions required fields in the response workflow.",
        "phase": "72",
        "answer": "gap",
        "status": "Gap",
        "ownerRole": "Engineering remediation lead",
        "owner": "Release Engineering Lead",
        "evidence": "The case records each completed measure, its timestamp and evidence, plus the exact approved steps users can take. Support can retrieve the current instructions.",
        "priority": "P2",
        "target": "Days 8–14 of preparation"
      },
      {
        "id": "72-versions",
        "title": "Third-party component exposure maps to supported and legacy releases",
        "why": "A component vulnerability can affect the final product manufacturer and older products may still be in scope for reporting.",
        "action": "Link component-inventory records to shipped releases and support status, including legacy versions.",
        "phase": "72",
        "answer": "gap",
        "status": "Gap",
        "ownerRole": "Engineering remediation lead",
        "owner": "Release Engineering Lead",
        "evidence": "An exposure matrix links the component and version to shipped product releases and support status. Unresolved coverage is labelled explicitly rather than treated as unaffected.",
        "priority": "P2",
        "target": "Days 8–14 of preparation"
      },
      {
        "id": "72-sensitive",
        "title": "Sensitive information has a specific handling decision",
        "why": "A generic confidentiality label is not enough; identify the sensitive detail and the harm from premature or wider disclosure.",
        "action": "Define who can approve sensitivity statements and when a separate Article 16(2) PEC review is escalated to counsel.",
        "phase": "72",
        "answer": "partial",
        "status": "Partial",
        "ownerRole": "Regulatory review owner",
        "owner": "Compliance Reviewer",
        "evidence": "A reviewed disclosure note identifies the specific sensitive information, the stated harm, the handling decision and the next review point. An unqualified confidentiality label is insufficient.",
        "priority": "P2",
        "target": "Days 8–14 of preparation"
      },
      {
        "id": "72-legal",
        "title": "Legal or regulatory review fits inside the remaining clock",
        "why": "A review queue that takes days makes the reporting procedure unusable.",
        "action": "Set and rehearse an incident-review SLA measured in hours, with a documented bypass for unavailability.",
        "phase": "72",
        "answer": "gap",
        "status": "Gap",
        "ownerRole": "Regulatory review owner",
        "owner": "Compliance Reviewer",
        "evidence": "A timed review demonstrates that the primary or designated backup reviewer can return a decision within the agreed internal window. Record escalation and unresolved blockers.",
        "priority": "P2",
        "target": "Days 8–14 of preparation"
      },
      {
        "id": "72-comms",
        "title": "User communications and customer support share one approved message",
        "why": "Mitigation instructions should be consistent across SRP fields, advisories and support responses.",
        "action": "Create one source-of-truth advisory and route all customer channels to it.",
        "phase": "72",
        "answer": "ready",
        "status": "Ready",
        "ownerRole": "User communications owner",
        "owner": "Customer Communications Lead",
        "evidence": "One versioned advisory is approved and used by the reporting, customer-support and communications owners. Workaround wording and known limitations agree across copies.",
        "priority": "P2",
        "target": "Days 8–14 of preparation"
      },
      {
        "id": "final-fix",
        "title": "Corrective-measure availability time is recorded",
        "why": "For an actively exploited vulnerability, this timestamp anchors the 14-day final-report deadline.",
        "action": "Record the first externally available mitigation or fix time as a controlled incident milestone.",
        "phase": "final",
        "answer": "ready",
        "status": "Ready",
        "ownerRole": "Engineering remediation lead",
        "owner": "Release Engineering Lead",
        "evidence": "A controlled milestone records when the corrective or mitigating measure first became available externally, with a UTC timestamp and supporting release or publication record.",
        "priority": "P3",
        "target": "Days 15–30 of preparation"
      },
      {
        "id": "final-severity",
        "title": "Final severity rationale is evidence-backed",
        "why": "The final report needs more than a rating; it needs classification and supporting factors.",
        "action": "Attach the final severity calculation, affected versions and reviewer approval to the case.",
        "phase": "final",
        "answer": "partial",
        "status": "Partial",
        "ownerRole": "Product-security case owner",
        "owner": "Product Security Lead",
        "evidence": "The final assessment states the severity method, relevant factors, affected releases, evidence references and reviewer approval. A bare severity label does not close this action.",
        "priority": "P3",
        "target": "Days 15–30 of preparation"
      },
      {
        "id": "final-impact",
        "title": "Actual and potential impact are bounded",
        "why": "The report should identify affected products, data, functions, users and connected systems.",
        "action": "Complete an impact inventory and explicitly document where no evidence was found.",
        "phase": "final",
        "answer": "partial",
        "status": "Partial",
        "ownerRole": "Engineering remediation lead",
        "owner": "Release Engineering Lead",
        "evidence": "An impact record distinguishes actual from potential effects on products, functions, data and users. Statements that no evidence was found include the investigation's coverage limits.",
        "priority": "P3",
        "target": "Days 15–30 of preparation"
      },
      {
        "id": "final-cause",
        "title": "Root cause and actor statements distinguish fact from inference",
        "why": "Unconfirmed attribution should not be presented as fact.",
        "action": "Use confirmed / likely / unknown labels for cause, actor and exploitation narrative.",
        "phase": "final",
        "answer": "partial",
        "status": "Partial",
        "ownerRole": "Engineering remediation lead",
        "owner": "Release Engineering Lead",
        "evidence": "The cause and actor narrative labels statements as confirmed, inferred or unknown and links material factual assertions to evidence. Unsupported attribution is removed.",
        "priority": "P3",
        "target": "Days 15–30 of preparation"
      },
      {
        "id": "final-close",
        "title": "The case preserves filing, remediation and review evidence",
        "why": "A defensible record connects the submission stages to remediation and post-incident improvement.",
        "action": "Archive submission receipts, field versions, approvals, remediation evidence and lessons learned together.",
        "phase": "final",
        "answer": "gap",
        "status": "Gap",
        "ownerRole": "Product-security case owner",
        "owner": "Product Security Lead",
        "evidence": "A colleague can retrieve the submitted versions, receipts, approvals, remediation evidence and lessons learned from one controlled case archive. Retention and access owners are named.",
        "priority": "P3",
        "target": "Days 15–30 of preparation"
      }
    ],
    "actions": [
      {
        "id": "24-srp",
        "title": "A working EU Login and assigned representative exist",
        "why": "At launch, submission is through the SRP interface rather than an API.",
        "action": "Validate the primary and backup representatives' EU Login and SRP access during an out-of-hours drill.",
        "phase": "24",
        "answer": "gap",
        "status": "Gap",
        "ownerRole": "Primary SRP submitter",
        "owner": "Regulatory Operations Lead",
        "evidence": "The primary and backup submitters each complete an authorised access check for the correct manufacturer. Record the date and outcome, without storing passwords or credentials.",
        "priority": "P1",
        "target": "Days 1–7 of preparation"
      },
      {
        "id": "24-summary",
        "title": "A concise, factual early-warning summary can be approved",
        "why": "The team can state known facts without adding speculative attribution or unnecessary sensitive detail.",
        "action": "Pre-approve an early-warning skeleton and a four-hour review service level.",
        "phase": "24",
        "answer": "gap",
        "status": "Gap",
        "ownerRole": "Regulatory review owner",
        "owner": "Compliance Reviewer",
        "evidence": "A factual draft is reviewed and approved within the team's agreed internal target. It distinguishes what is known from what remains under investigation and records the approver and time.",
        "priority": "P1",
        "target": "Days 1–7 of preparation"
      },
      {
        "id": "24-trigger",
        "title": "Reportability can be decided without waiting for root cause",
        "why": "The owner can distinguish an actively exploited vulnerability from a severe incident and record uncertainty.",
        "action": "Approve a one-page trigger decision record with escalation criteria and a named decision owner.",
        "phase": "24",
        "answer": "partial",
        "status": "Partial",
        "ownerRole": "Product-security case owner",
        "owner": "Product Security Lead",
        "evidence": "A completed decision record separates confirmed facts, assumptions and unresolved questions, names the decision owner and records the reason for the reporting decision.",
        "priority": "P1",
        "target": "Days 1–7 of preparation"
      },
      {
        "id": "24-countries",
        "title": "Member States of product availability can be identified",
        "why": "The SRP uses known product availability to determine concerned CSIRTs.",
        "action": "Map sales/distribution data to an exportable country list per supported product family.",
        "phase": "24",
        "answer": "partial",
        "status": "Partial",
        "ownerRole": "User communications owner",
        "owner": "Customer Communications Lead",
        "evidence": "A reproducible product-availability extract names the relevant countries, source system, coverage limits, update date and maintenance owner.",
        "priority": "P1",
        "target": "Days 1–7 of preparation"
      },
      {
        "id": "24-cover",
        "title": "A backup owner can act outside business hours",
        "why": "The clock does not pause for leave, weekends or internal approval queues.",
        "action": "Name a backup submitter and test one handover outside ordinary office hours.",
        "phase": "24",
        "answer": "partial",
        "status": "Partial",
        "ownerRole": "Backup SRP submitter",
        "owner": "Engineering On-call",
        "evidence": "With the primary person unavailable, the backup finds the case, current draft, review contacts and authorised submission route. Keep the timed handover result and unresolved access issues.",
        "priority": "P1",
        "target": "Days 1–7 of preparation"
      },
      {
        "id": "72-measures",
        "title": "Completed mitigation and user measures are documented",
        "why": "Corrective measures taken and measures users can take are required at the notification stage.",
        "action": "Make mitigation timestamps and user-facing instructions required fields in the response workflow.",
        "phase": "72",
        "answer": "gap",
        "status": "Gap",
        "ownerRole": "Engineering remediation lead",
        "owner": "Release Engineering Lead",
        "evidence": "The case records each completed measure, its timestamp and evidence, plus the exact approved steps users can take. Support can retrieve the current instructions.",
        "priority": "P2",
        "target": "Days 8–14 of preparation"
      },
      {
        "id": "72-versions",
        "title": "Third-party component exposure maps to supported and legacy releases",
        "why": "A component vulnerability can affect the final product manufacturer and older products may still be in scope for reporting.",
        "action": "Link component-inventory records to shipped releases and support status, including legacy versions.",
        "phase": "72",
        "answer": "gap",
        "status": "Gap",
        "ownerRole": "Engineering remediation lead",
        "owner": "Release Engineering Lead",
        "evidence": "An exposure matrix links the component and version to shipped product releases and support status. Unresolved coverage is labelled explicitly rather than treated as unaffected.",
        "priority": "P2",
        "target": "Days 8–14 of preparation"
      },
      {
        "id": "72-legal",
        "title": "Legal or regulatory review fits inside the remaining clock",
        "why": "A review queue that takes days makes the reporting procedure unusable.",
        "action": "Set and rehearse an incident-review SLA measured in hours, with a documented bypass for unavailability.",
        "phase": "72",
        "answer": "gap",
        "status": "Gap",
        "ownerRole": "Regulatory review owner",
        "owner": "Compliance Reviewer",
        "evidence": "A timed review demonstrates that the primary or designated backup reviewer can return a decision within the agreed internal window. Record escalation and unresolved blockers.",
        "priority": "P2",
        "target": "Days 8–14 of preparation"
      },
      {
        "id": "72-evidence",
        "title": "Technical evidence is assembled into one case",
        "why": "Affected versions, exploitation evidence, mitigations and unresolved questions remain traceable.",
        "action": "Define a single incident case record and mandatory links to logs, the software bill of materials (SBOM), release records and remediation evidence.",
        "phase": "72",
        "answer": "partial",
        "status": "Partial",
        "ownerRole": "Product-security case owner",
        "owner": "Product Security Lead",
        "evidence": "One case index links the exploitation evidence, component inventory, release records and mitigation record. An authorised colleague can open those links and identify the latest version.",
        "priority": "P2",
        "target": "Days 8–14 of preparation"
      },
      {
        "id": "72-assessment",
        "title": "An initial severity and impact assessment can be produced",
        "why": "The 72-hour notification needs an initial assessment that separates confirmed findings from investigation.",
        "action": "Adopt a short severity/impact template with confirmed, suspected and unknown sections.",
        "phase": "72",
        "answer": "partial",
        "status": "Partial",
        "ownerRole": "Product-security case owner",
        "owner": "Product Security Lead",
        "evidence": "A dated initial assessment separates confirmed, suspected and unknown impact, references its supporting evidence and identifies who reviews the next update.",
        "priority": "P2",
        "target": "Days 8–14 of preparation"
      },
      {
        "id": "72-sensitive",
        "title": "Sensitive information has a specific handling decision",
        "why": "A generic confidentiality label is not enough; identify the sensitive detail and the harm from premature or wider disclosure.",
        "action": "Define who can approve sensitivity statements and when a separate Article 16(2) PEC review is escalated to counsel.",
        "phase": "72",
        "answer": "partial",
        "status": "Partial",
        "ownerRole": "Regulatory review owner",
        "owner": "Compliance Reviewer",
        "evidence": "A reviewed disclosure note identifies the specific sensitive information, the stated harm, the handling decision and the next review point. An unqualified confidentiality label is insufficient.",
        "priority": "P2",
        "target": "Days 8–14 of preparation"
      },
      {
        "id": "final-close",
        "title": "The case preserves filing, remediation and review evidence",
        "why": "A defensible record connects the submission stages to remediation and post-incident improvement.",
        "action": "Archive submission receipts, field versions, approvals, remediation evidence and lessons learned together.",
        "phase": "final",
        "answer": "gap",
        "status": "Gap",
        "ownerRole": "Product-security case owner",
        "owner": "Product Security Lead",
        "evidence": "A colleague can retrieve the submitted versions, receipts, approvals, remediation evidence and lessons learned from one controlled case archive. Retention and access owners are named.",
        "priority": "P3",
        "target": "Days 15–30 of preparation"
      },
      {
        "id": "final-severity",
        "title": "Final severity rationale is evidence-backed",
        "why": "The final report needs more than a rating; it needs classification and supporting factors.",
        "action": "Attach the final severity calculation, affected versions and reviewer approval to the case.",
        "phase": "final",
        "answer": "partial",
        "status": "Partial",
        "ownerRole": "Product-security case owner",
        "owner": "Product Security Lead",
        "evidence": "The final assessment states the severity method, relevant factors, affected releases, evidence references and reviewer approval. A bare severity label does not close this action.",
        "priority": "P3",
        "target": "Days 15–30 of preparation"
      },
      {
        "id": "final-impact",
        "title": "Actual and potential impact are bounded",
        "why": "The report should identify affected products, data, functions, users and connected systems.",
        "action": "Complete an impact inventory and explicitly document where no evidence was found.",
        "phase": "final",
        "answer": "partial",
        "status": "Partial",
        "ownerRole": "Engineering remediation lead",
        "owner": "Release Engineering Lead",
        "evidence": "An impact record distinguishes actual from potential effects on products, functions, data and users. Statements that no evidence was found include the investigation's coverage limits.",
        "priority": "P3",
        "target": "Days 15–30 of preparation"
      },
      {
        "id": "final-cause",
        "title": "Root cause and actor statements distinguish fact from inference",
        "why": "Unconfirmed attribution should not be presented as fact.",
        "action": "Use confirmed / likely / unknown labels for cause, actor and exploitation narrative.",
        "phase": "final",
        "answer": "partial",
        "status": "Partial",
        "ownerRole": "Engineering remediation lead",
        "owner": "Release Engineering Lead",
        "evidence": "The cause and actor narrative labels statements as confirmed, inferred or unknown and links material factual assertions to evidence. Unsupported attribution is removed.",
        "priority": "P3",
        "target": "Days 15–30 of preparation"
      }
    ],
    "gaps": [
      {
        "id": "24-srp",
        "title": "A working EU Login and assigned representative exist",
        "why": "At launch, submission is through the SRP interface rather than an API.",
        "action": "Validate the primary and backup representatives' EU Login and SRP access during an out-of-hours drill.",
        "phase": "24",
        "answer": "gap",
        "status": "Gap",
        "ownerRole": "Primary SRP submitter",
        "owner": "Regulatory Operations Lead",
        "evidence": "The primary and backup submitters each complete an authorised access check for the correct manufacturer. Record the date and outcome, without storing passwords or credentials.",
        "priority": "P1",
        "target": "Days 1–7 of preparation"
      },
      {
        "id": "24-summary",
        "title": "A concise, factual early-warning summary can be approved",
        "why": "The team can state known facts without adding speculative attribution or unnecessary sensitive detail.",
        "action": "Pre-approve an early-warning skeleton and a four-hour review service level.",
        "phase": "24",
        "answer": "gap",
        "status": "Gap",
        "ownerRole": "Regulatory review owner",
        "owner": "Compliance Reviewer",
        "evidence": "A factual draft is reviewed and approved within the team's agreed internal target. It distinguishes what is known from what remains under investigation and records the approver and time.",
        "priority": "P1",
        "target": "Days 1–7 of preparation"
      },
      {
        "id": "24-trigger",
        "title": "Reportability can be decided without waiting for root cause",
        "why": "The owner can distinguish an actively exploited vulnerability from a severe incident and record uncertainty.",
        "action": "Approve a one-page trigger decision record with escalation criteria and a named decision owner.",
        "phase": "24",
        "answer": "partial",
        "status": "Partial",
        "ownerRole": "Product-security case owner",
        "owner": "Product Security Lead",
        "evidence": "A completed decision record separates confirmed facts, assumptions and unresolved questions, names the decision owner and records the reason for the reporting decision.",
        "priority": "P1",
        "target": "Days 1–7 of preparation"
      },
      {
        "id": "24-countries",
        "title": "Member States of product availability can be identified",
        "why": "The SRP uses known product availability to determine concerned CSIRTs.",
        "action": "Map sales/distribution data to an exportable country list per supported product family.",
        "phase": "24",
        "answer": "partial",
        "status": "Partial",
        "ownerRole": "User communications owner",
        "owner": "Customer Communications Lead",
        "evidence": "A reproducible product-availability extract names the relevant countries, source system, coverage limits, update date and maintenance owner.",
        "priority": "P1",
        "target": "Days 1–7 of preparation"
      },
      {
        "id": "24-cover",
        "title": "A backup owner can act outside business hours",
        "why": "The clock does not pause for leave, weekends or internal approval queues.",
        "action": "Name a backup submitter and test one handover outside ordinary office hours.",
        "phase": "24",
        "answer": "partial",
        "status": "Partial",
        "ownerRole": "Backup SRP submitter",
        "owner": "Engineering On-call",
        "evidence": "With the primary person unavailable, the backup finds the case, current draft, review contacts and authorised submission route. Keep the timed handover result and unresolved access issues.",
        "priority": "P1",
        "target": "Days 1–7 of preparation"
      },
      {
        "id": "72-measures",
        "title": "Completed mitigation and user measures are documented",
        "why": "Corrective measures taken and measures users can take are required at the notification stage.",
        "action": "Make mitigation timestamps and user-facing instructions required fields in the response workflow.",
        "phase": "72",
        "answer": "gap",
        "status": "Gap",
        "ownerRole": "Engineering remediation lead",
        "owner": "Release Engineering Lead",
        "evidence": "The case records each completed measure, its timestamp and evidence, plus the exact approved steps users can take. Support can retrieve the current instructions.",
        "priority": "P2",
        "target": "Days 8–14 of preparation"
      },
      {
        "id": "72-versions",
        "title": "Third-party component exposure maps to supported and legacy releases",
        "why": "A component vulnerability can affect the final product manufacturer and older products may still be in scope for reporting.",
        "action": "Link component-inventory records to shipped releases and support status, including legacy versions.",
        "phase": "72",
        "answer": "gap",
        "status": "Gap",
        "ownerRole": "Engineering remediation lead",
        "owner": "Release Engineering Lead",
        "evidence": "An exposure matrix links the component and version to shipped product releases and support status. Unresolved coverage is labelled explicitly rather than treated as unaffected.",
        "priority": "P2",
        "target": "Days 8–14 of preparation"
      },
      {
        "id": "72-legal",
        "title": "Legal or regulatory review fits inside the remaining clock",
        "why": "A review queue that takes days makes the reporting procedure unusable.",
        "action": "Set and rehearse an incident-review SLA measured in hours, with a documented bypass for unavailability.",
        "phase": "72",
        "answer": "gap",
        "status": "Gap",
        "ownerRole": "Regulatory review owner",
        "owner": "Compliance Reviewer",
        "evidence": "A timed review demonstrates that the primary or designated backup reviewer can return a decision within the agreed internal window. Record escalation and unresolved blockers.",
        "priority": "P2",
        "target": "Days 8–14 of preparation"
      },
      {
        "id": "72-evidence",
        "title": "Technical evidence is assembled into one case",
        "why": "Affected versions, exploitation evidence, mitigations and unresolved questions remain traceable.",
        "action": "Define a single incident case record and mandatory links to logs, the software bill of materials (SBOM), release records and remediation evidence.",
        "phase": "72",
        "answer": "partial",
        "status": "Partial",
        "ownerRole": "Product-security case owner",
        "owner": "Product Security Lead",
        "evidence": "One case index links the exploitation evidence, component inventory, release records and mitigation record. An authorised colleague can open those links and identify the latest version.",
        "priority": "P2",
        "target": "Days 8–14 of preparation"
      },
      {
        "id": "72-assessment",
        "title": "An initial severity and impact assessment can be produced",
        "why": "The 72-hour notification needs an initial assessment that separates confirmed findings from investigation.",
        "action": "Adopt a short severity/impact template with confirmed, suspected and unknown sections.",
        "phase": "72",
        "answer": "partial",
        "status": "Partial",
        "ownerRole": "Product-security case owner",
        "owner": "Product Security Lead",
        "evidence": "A dated initial assessment separates confirmed, suspected and unknown impact, references its supporting evidence and identifies who reviews the next update.",
        "priority": "P2",
        "target": "Days 8–14 of preparation"
      },
      {
        "id": "72-sensitive",
        "title": "Sensitive information has a specific handling decision",
        "why": "A generic confidentiality label is not enough; identify the sensitive detail and the harm from premature or wider disclosure.",
        "action": "Define who can approve sensitivity statements and when a separate Article 16(2) PEC review is escalated to counsel.",
        "phase": "72",
        "answer": "partial",
        "status": "Partial",
        "ownerRole": "Regulatory review owner",
        "owner": "Compliance Reviewer",
        "evidence": "A reviewed disclosure note identifies the specific sensitive information, the stated harm, the handling decision and the next review point. An unqualified confidentiality label is insufficient.",
        "priority": "P2",
        "target": "Days 8–14 of preparation"
      },
      {
        "id": "final-close",
        "title": "The case preserves filing, remediation and review evidence",
        "why": "A defensible record connects the submission stages to remediation and post-incident improvement.",
        "action": "Archive submission receipts, field versions, approvals, remediation evidence and lessons learned together.",
        "phase": "final",
        "answer": "gap",
        "status": "Gap",
        "ownerRole": "Product-security case owner",
        "owner": "Product Security Lead",
        "evidence": "A colleague can retrieve the submitted versions, receipts, approvals, remediation evidence and lessons learned from one controlled case archive. Retention and access owners are named.",
        "priority": "P3",
        "target": "Days 15–30 of preparation"
      },
      {
        "id": "final-severity",
        "title": "Final severity rationale is evidence-backed",
        "why": "The final report needs more than a rating; it needs classification and supporting factors.",
        "action": "Attach the final severity calculation, affected versions and reviewer approval to the case.",
        "phase": "final",
        "answer": "partial",
        "status": "Partial",
        "ownerRole": "Product-security case owner",
        "owner": "Product Security Lead",
        "evidence": "The final assessment states the severity method, relevant factors, affected releases, evidence references and reviewer approval. A bare severity label does not close this action.",
        "priority": "P3",
        "target": "Days 15–30 of preparation"
      },
      {
        "id": "final-impact",
        "title": "Actual and potential impact are bounded",
        "why": "The report should identify affected products, data, functions, users and connected systems.",
        "action": "Complete an impact inventory and explicitly document where no evidence was found.",
        "phase": "final",
        "answer": "partial",
        "status": "Partial",
        "ownerRole": "Engineering remediation lead",
        "owner": "Release Engineering Lead",
        "evidence": "An impact record distinguishes actual from potential effects on products, functions, data and users. Statements that no evidence was found include the investigation's coverage limits.",
        "priority": "P3",
        "target": "Days 15–30 of preparation"
      },
      {
        "id": "final-cause",
        "title": "Root cause and actor statements distinguish fact from inference",
        "why": "Unconfirmed attribution should not be presented as fact.",
        "action": "Use confirmed / likely / unknown labels for cause, actor and exploitation narrative.",
        "phase": "final",
        "answer": "partial",
        "status": "Partial",
        "ownerRole": "Engineering remediation lead",
        "owner": "Release Engineering Lead",
        "evidence": "The cause and actor narrative labels statements as confirmed, inferred or unknown and links material factual assertions to evidence. Unsupported attribution is removed.",
        "priority": "P3",
        "target": "Days 15–30 of preparation"
      }
    ],
    "verdictText": "Example Device Labs (fictional) scored 54/100 for Atlas Gateway 4.x. The reported workflow is not ready to rely on during a reportable event. 15 of 20 checks need follow-up; 0 are marked not applicable.",
    "scenario": [
      {
        "stage": "24-hour stage",
        "time": "T+00:00",
        "facts": "At 09:10 UTC, two customers and a trusted source report malicious exploitation of an authentication bypass in a component embedded in fictional Atlas Gateway 4.0–4.2.1. The product is available in Germany, France and the Netherlands. No patch exists; a network-isolation workaround appears viable.",
        "challenge": "Can the team establish the clock, record the reporting decision, identify the product and route, approve the known facts and cover an absent submitter?"
      },
      {
        "stage": "72-hour stage",
        "time": "T+30 hours",
        "facts": "A vulnerability identifier is assigned. Two supported releases and one legacy release are exposed. Exploitation attempts are visible; the number of successful compromises remains under investigation. A patch candidate is being tested.",
        "challenge": "Can the team produce one evidence-backed case, a bounded initial assessment and consistent mitigation instructions while facts are still changing?"
      },
      {
        "stage": "Final-report stage",
        "time": "Day 5",
        "facts": "Fictional release 4.2.2 removes the vulnerable path. Three customer instances show unauthorised access affecting configuration integrity. The scenario has no evidence of broader data extraction.",
        "challenge": "Can the team preserve the externally available fix milestone, support its final impact and cause statements, and retrieve the complete case record?"
      }
    ],
    "method": "Ready = 2; Partial = 1; Gap or unanswered = 0; N/A is excluded from the stage denominator. The 24-hour score is 75% capability score and 25% named-role coverage. Overall weighting: 24-hour 50%, 72-hour 32%, final 18%. Stage values are rounded before aggregation. If every check in a stage is N/A, that stage scores zero. Bands: below 60 Not ready; 60–79 At risk; 80–100 Operationally ready. No answers means Not assessed. These are self-reported indicators, not independent verification or proof of compliance.",
    "retest": [
      "Assign any missing owner before accepting an action. Confirm the proposed preparation targets with the team; they are not incident-reporting deadlines.",
      "For each open action, retain the evidence described in its closure criterion in your own controlled case or runbook. This tool does not collect or verify that evidence.",
      "Have a second authorised person repeat the relevant lookup, approval or handover. Record the date, elapsed time, outcome and remaining limitation.",
      "Change a rating to Ready only when the capability, named owner and current evidence can be demonstrated. A higher aggregate score must not conceal an unresolved reporting blocker.",
      "Save the dated exercise JSON and report. Re-run the scenario after material product, staffing or process changes and compare the open action IDs."
    ],
    "elapsed": "00:34:00",
    "missingRoles": []
  },
  "illustrativeSample": true
}
