Zum Hauptinhalt springen

Document metadata

Status
Maintained
Approval
Approved
Version
1.0
Classification
PUBLIC
Owner
Lightning IT Documentation Maintainers
Approver
Lightning IT Product Owners
Audience
product and system owners, delivery teams, customers and technical reviewers
Last reviewed
Next review
(Annual)

Deliverables and acceptance

A concrete engagement selects only the deliverables required by its agreed scope. This page defines possible categories, not a package, price, service level, technology, or promise that every category is always delivered.

Bounded deliverable categories

  • defined scope, assessment targets, assumptions, and exclusions;
  • control profile and applicable requirement relationships;
  • roles, responsibilities, baseline, and check plan;
  • an evidence register containing only authorized references or records;
  • assessment, finding, deviation, and residual-risk records;
  • agreed documentation and handover artifacts; and
  • review, approval, lifecycle, and optional reassessment procedures.

The concrete contract identifies the exact artifacts, formats, owners, retention rules, and acceptance roles. Optional recurring checks or views are included only when explicitly agreed.

Acceptance criteria

A delivery is ready for an acceptance decision only when:

  1. scope, targets, assumptions, exclusions, and responsibilities are explicit;
  2. applicable controls and check methods are defined;
  3. required evidence is present or its absence is recorded as a gap;
  4. results are reproducible and traceable within the stated limitations;
  5. findings, deviations, and residual-risk decisions are documented by their authorized owners;
  6. the agreed artifacts and reports exist at the reviewed versions; and
  7. review and handover are complete.

Acceptance applies only to the agreed scope, artifacts, controls, checks, and evidence. It is not a blanket certification, compliance, conformity, audit, security, or future-performance statement.

Verification and change

The acceptance record identifies the reviewed target, versions, control set, evidence set, open limitations, decision owner, and date. A material target, scope, requirement, control, implementation, or evidence change triggers a new review in proportion to its impact.

Public documentation approval and production publication remain separate from a customer or delivery acceptance decision. See Security and publication boundary.