Purpose

Record the formal acceptance and release decision for a tested COTS product or update.

Scope

This procedure applies to release readiness, approval by management or delegated authority, and documentation of any outstanding risk.

Steps

#ActionDetailsEvidence
1Confirm test completionConfirm all planned tests are complete and performance, integration, compliance and security acceptance criteria are met.Test completion record
2Confirm defects and vulnerabilities closedConfirm critical defects are closed and residual vulnerabilities are within approved risk appetite.Defect and vulnerability closure record
3Obtain CORF and dual sign-offObtain CORF confirmation before production release and the required dual or delegated release sign-off.CORF and release sign-off
4Record acceptance decisionRecord the accepted product version, release scope, decision, approvers, date and any conditions or accepted residual risks.Approval record
5Retain decision in repositoryRetain the signed decision with the complete test package in the COTS Acceptance Repository.Repository entry
6Block incomplete releasesBlock and escalate release when evidence, approval or acceptance criteria are incomplete.Escalation or block record

Evidence

  • approval record
  • release register entry
  • accepted version record

Relationships

Implementation

  • Implementation state: current under the approved COTS Acceptance and Testing Manual version 1.0
  • Execution evidence: retained for each release decision

History

  • 2026-07-26: Added the evidence-system relationship required for Hermes assessment mapping.
  • 2026-07-26: Created from the approved COTS manual and mapped to CBCS-derived IT requirements.