TRA Studio
All example documents

Fictitious example. ACME Embedded GmbH, its products, records and document IDs are invented for illustration. Use this as a structural model, not as a template to adopt unchanged — and not as legal advice.

SDL-REC-002 — Internal SDL Conformity Review 2026

Document IDSDL-REC-002 (annual record)
Period covered2025-07 – 2026-06
Prepared byQA Engineer (Verification Lead), 2026-07-06
Reviewed byProduct Security Lead
Approved byManaging Director, 2026-07-10
PurposeDocumented evidence of internal conformity with SDL-POL-001 in the absence of external certification (CRA Annex I Part I)

1. Context

ACME Embedded GmbH does not hold IEC 62443-4-1 or ISO/IEC 27001 certification. Conformity of our development processes with the documented SDL (SDL-POL-001 rev. 2.1) is therefore demonstrated through internal records and this annual review. This record is part of the quality records and is referenced by the technical documentation of all products released in the period.

2. Scope of the review

Releases sampled (all CRA-relevant releases in the period):

ReleaseProductTypeDossier
FW 3.4.0SensorNode S200Major (new TLS stack)REL-DOS-2025-014
FW 3.4.2SensorNode S200Minor (bugfix)REL-DOS-2026-003
FW 1.0.0Gateway G50New productREL-DOS-2026-007

3. Checks performed and results

Security requirements & threat modeling. Security Requirements Sheets present for S200 3.4.0 and G50 1.0.0; delta assessment (signed) present for 3.4.2. Threat model for G50 reviewed and approved by PSL on 2026-02-11. Conform.

Implementation controls. Sample of 20 merge requests across the three releases: all show mandatory peer review; 4 security-relevant MRs additionally show PSL approval as required. SBOMs generated in CI for all releases. Conform.

Verification. SAST and dependency scans present in all three release pipelines. Fuzzing evidence present for S200 3.4.0 (update parser) and G50 1.0.0 (Modbus handler). Finding F-2026-01: fuzzing was skipped for release 3.4.2 without a documented waiver, although tailoring rules would have permitted one. Minor nonconformity (documentation gap, not a technical gap).

Release gate. Signed Release Gate Records present in all three dossiers; secure-defaults checklist SDL-CHK-030 completed in each. Conform.

Vulnerability management. PSM-PROC-002 operated throughout the period: 3 external reports received via security@, all acknowledged within 48 h; 1 actively exploited vulnerability candidate assessed — determined not exploited, no ENISA early-warning obligation triggered (assessment record VM-2026-002). Conform.

4. Findings and corrective actions

IDFindingCorrective actionOwnerDue
F-2026-01Missing tailoring waiver for skipped fuzzing (rel. 3.4.2)Add waiver step to minor-release checklist; retroactive waiver filedVerification LeadDone 2026-07-08
O-2026-01Observation: SBOM not yet delivered in machine-readable form with tech docsAttach CycloneDX SBOM to each release dossierDevOps Lead2026-09

5. Conclusion

Development activities in the review period conform to SDL-POL-001 with one minor documentation nonconformity, corrected. The SDL is assessed as implemented and effective. This record, together with the per-release conformity dossiers listed above, constitutes the evidence of internal conformity per CRA Annex I Part I.


Annex A — Standard structure of a release conformity dossier (REL-DOS-*)

Each release dossier is a folder in the QM repository containing:

  1. Security Requirements Sheet or delta assessment (signed)
  2. Threat model / threat model review record
  3. Merge-request review evidence (export of approvals)
  4. CI reports: SAST, dependency/CVE scan, fuzzing (or waiver)
  5. Completed secure-defaults checklist SDL-CHK-030
  6. Signed Release Gate Record incl. support-period statement
  7. SBOM (CycloneDX)
  8. Firmware signature/build provenance record

This structure allows the complete evidence package for any release to be handed to a market surveillance authority as-is.