OpenChainGraph Suite · DORA / NIS2 / ICT Resilience

Customer Security Controls Attestation Cycle

Two-step annual attestation cycle over a declared architecture type and component inventory. Step 1 derives the applicable mandatory and advisory control set from the policy-supplied control-framework version, scores declared implementation status, and returns coverage figures, a gap list keyed by published control number, an evidence index aligned to the framework's own supporting-evidence column, and an explicit not-applicable set with stated reasons so an omission cannot read as a pass. Step 2 tests assessor eligibility: assessment route, claimed certifications against the required set, independence from the implementer by distinct-identity counting, and assessment-date validity against the attestation deadline. Step 1 is gated hold while any mandatory control gap remains. Step 2 is gated reject, a terminal human rejection, when the assessor is ineligible, and the failing predicate is carried as the reason code. Release of the attestation bundle is a dual-control act with the assessor bound as reviewer and the attesting officer as approver; an examiner role binding grants inspection only and never an approval path. The framework's annual 31 December attestation deadline is a fact about the regime. This surface produces the firm's own evidence: it is not a Swift endorsement, not an assessor accreditation, and does not satisfy a KYC-SA submission.

OpenChainGraph · 2 Steps compliance mandate Hash-Anchored §4 chain_depth:2 Client-Side · Zero PII
Chain Topology: Control Applicability → Assessor Independence
§4 Execution Hash · Chain Definition Anchor
execution_hash:computing…
Chain Stages · 2 Steps
1 ROOT node hold
Control Applicability art-486-cscf-control-applicability
Applicable control set, coverage figures, gap list and evidence index keyed by control number feed the assessor-eligibility stage
§27 Human Accountability gate: an outstanding mandatory-control gap puts the cycle on hold until the gap is closed or explicitly dispositioned.
MCP Call · check_cscf_control_applicability
{
  "jsonrpc": "2.0",
  "method": "tools/call",
  "params": {
    "name": "check_cscf_control_applicability",
    "arguments": {}
  },
  "id": 1
}
2 TERMINAL node reject
Assessor Independence art-487-assessor-independence-check
Eligible or ineligible with the failing predicate named, closing the attestation evidence bundle. Final stage.
§27 Human Accountability gate: an ineligible assessor is a terminal reject, carrying the failing predicate as the reason code. Attestation release is a dual-control act with the assessor bound as reviewer and the attesting officer as approver; an examiner role binding grants inspection only, never an approval path.
MCP Call · check_assessor_independence
{
  "jsonrpc": "2.0",
  "method": "tools/call",
  "params": {
    "name": "check_assessor_independence",
    "arguments": {}
  },
  "id": 1
}
Export Artifacts
Download the §4 chain definition artifact (hash-anchored composite JSON) or the §13.11 W3C Verifiable Credentials view. Both derive from the chain definition; no new hash is minted. Available after hash computation.