Applicability & tailoring
Establish why the framework applies and which controlled profile governs the product.
PSLF-00G0Scope acceptedPhase 1 of 9
Gate
G0
Passed
Scope accepted
Decision date
22 Jan 2026
Baseline PSAA-0042 v1.0 / FAR-0042 v1.0
Open blockers
0
none at decision
Approvers
2
Dana Whitfield, Sam Okafor
Scope the product, markets, connectivity, data, suppliers, legacy status, and required framework profile.
- No product proceeds without a recorded applicability decision.
- Tailoring cannot weaken a mandatory outcome without an approved exception.
- Product concept or change request
- Customer framework profile
- Target markets and intended use
- 1Classify product and cyber-device applicability
- 2Assess connectivity, data classes, clinical impact, deployment model, suppliers, AI/ML use, and legacy constraints
- 3Select mandatory standards and regulatory profiles
- 4Record applicable, non-applicable, and deferred obligations with rationale
- Product Security Applicability Assessment
- Framework Applicability Record
- Initial ecosystem and role assignment
- Scope owner and Security Lead assignedMet
- Markets and product types confirmedMet
- All non-applicability decisions approvedMet
- Required lifecycle deliverables instantiatedMet
- Accountable
- Product Owner accountable
- Supporting
- Regulatory, Quality, and Security consulted
- Customer (pending)
- Portfolio (pending)
- Product family (pending)
- Ecosystem (pending)
- Profile (pending)
- Exception (pending)
- Applicability completed before planning
- Open or expired exceptions