01 · Questionnaire

Questionnaire

Answer per control. Each answer feeds the evaluation and the traceability chain Actor → Vector → Component → Effect → Audit.

C-5.1 · L5
Critical

Right to audit

Do contracts grant the buyer enforceable right to audit suppliers and sub-suppliers?

Evidence required:Contract clauses, audit schedule.
Why it matters ▾

Without an enforceable right-to-audit clause that flows down to sub-suppliers, security claims are unverifiable. The clause must allow on-site visits, document inspection and follow-up audits, not just self-attestations.

C-5.2 · L5
High

Evidence delivery obligation

Are vendors contractually required to deliver SBOMs, test reports and attestations?

Evidence required:Evidence register, delivery acceptance records.
Why it matters ▾

If suppliers are not contractually required to deliver SBOMs, test reports and attestations at defined milestones, you will not receive them. The evidence register lists exactly what is due, by when, and the acceptance criteria.

C-5.3 · L5
High

Sovereignty & substitution plan

Is there a substitution / second-source plan for components from high-risk jurisdictions?

Evidence required:Component origin matrix, substitution roadmap.
Why it matters ▾

If a critical component comes from a jurisdiction that becomes hostile (export ban, sanction, sabotage risk), the platform is grounded unless a substitution plan exists. The plan names alternatives, qualification effort and lead-time per component.

C-5.4 · L5
High

Right to patch & re-flash

Does the buyer retain technical and legal rights to patch firmware independently?

Evidence required:Escrow agreement, signing key custody plan.
Why it matters ▾

If only the original vendor can sign firmware, and that vendor disappears or refuses to patch a vulnerability, the buyer is stuck. Source escrow plus custody of signing keys (or a co-signing arrangement) preserves the buyer's ability to patch.

C-5.5 · L5
High

Flow-down to sub-suppliers

Are security clauses contractually flowed down to all relevant Tier-2/3 sub-suppliers?

Evidence required:Flow-down clause, sub-supplier acknowledgements.
Why it matters ▾

Security clauses written between the buyer and Tier-1 do nothing if Tier-1's contracts with Tier-2/3 are silent. Mandatory flow-down with sub-supplier acknowledgements is the only way to extend the security regime to the actual risk locations.

C-5.6 · L5
High

Source code & key escrow

Is critical source code, build toolchain and signing key material held in escrow with defined release triggers?

Evidence required:Escrow agreement, release-trigger list.
Why it matters ▾

Source code escrow without the build toolchain and signing keys is often useless — you cannot reproduce the binary the device accepts. Escrow must cover all three, with documented release triggers (vendor bankruptcy, refusal to patch, etc.).

C-5.7 · L5
High

Incident disclosure obligation

Are suppliers contractually obliged to disclose security incidents and vulnerabilities within a defined window?

Evidence required:Disclosure clause, notification log.
Why it matters ▾

Suppliers learn about incidents and vulnerabilities affecting their products before customers do. A contractual disclosure window (e.g. 72 hours for incidents, defined CVE disclosure rules) ensures the buyer can act before exploitation spreads.

C-5.8 · L5
Medium

End-of-life and component obsolescence

Is there a contractual EOL / obsolescence plan including last-time-buy, re-design and security-patch tail?

Evidence required:EOL plan, obsolescence register.
Why it matters ▾

Electronics have shorter lifecycles than platforms. Without a contractual EOL plan (last-time-buy notice, re-design support, security-patch tail beyond active production), the platform becomes unmaintainable and insecure mid-life.