Customer profiles
How the Meridian Medical Systems profile resolves into 174 effective obligations for PRJ-2026-0042.
Effective obligations
174
against FR-2026.1
Resolution layers
6
core to exceptions
Profile additions
2
approved, additive
Active exceptions
1
EXC-0009 expires 31 Dec
Obligation composition
| Segment | Count | Share |
|---|---|---|
| Core PSLF baseline | 148 | 85% |
| Market profile | 14 | 8% |
| Customer profile | 8 | 5% |
| Product-family profile | 4 | 2% |
| Product ecosystem profile | 1 | 1% |
Resolution order
- Core PSLF baselineFR-2026.1+148 obligations
Nine phases, gates G0-G8, canonical registry, core obligations, risk method v1.2
Core framework release FR-2026.1 · owner Framework Governance Board
- Market profileMP-US-FDA+14 obligations
Premarket submission evidence set, SBOM expectations, labeling and disclosure obligations
United States market profile (FDA) · owner Regulatory Intelligence
- Customer profileCFP-0001+8 obligations
ADD-0001 pentest cadence, ADD-0002 Clinical Safety G6 approver, customer evidence templates
Meridian Medical Systems customer profile · owner Ravi Patel (Customer Framework Administrator)
- Product-family profilePFAM-INF-01+4 obligations
Dosing-integrity control baseline, pump-specific misuse cases, clinical-workflow validation set
Infusion systems product family · owner Dana Whitfield (Product Owner)
- Product ecosystem profilePFP-2026-0042+1 obligation
Instantiated phase tasks, deliverable identifiers, gate dates, role assignments
NimbusPump NP-200 ecosystem profile · owner Dana Whitfield + Marcus Chen
- Approved exceptionsEXC-0009-1 obligation (deviated)
OBL-0043 deviated for hardware rev A with compensating controls; expires 31 Dec 2026
Time-bound exception EXC-0009 (hardware root of trust) · owner Dr. Lena Fischer (Risk Acceptance Authority)
Effective result
- Resolved profile
- PFP-2026-0042
- Product ecosystem
- NimbusPump NP-200 Program (PRJ-2026-0042)
- Resolved against
- FR-2026.1
- Resolved at
- 06 Mar 2026, 14:05 UTC
- Market profiles
- MP-US-FDA (United States, FDA) · MP-EU-MDR (European Union, MDR)
- Administrator
- Ravi Patel · Customer Framework Administrator
Profile additions (2)
Independent penetration test each major release
ADD-0001Gate rigorPSLF-04 / G4Approved
Clinical Safety co-approval at release for dosing products
ADD-0002Added approverPSLF-06 / G6Approved
Deviates from for PRJ-2026-0042 — NimbusPump NP-200, hardware revision A only.
- Requested (passed)
- Under review (passed)
- Approved (passed)
- Active (current)
- Expiring (pending)
- Closed (pending)
- Requested by
- Priya Raman · Security Architect
- Approver
- Dr. Lena Fischer · Risk Acceptance Authority
- Effective from
- 06 Mar 2026
- Review cadence
- Quarterly review; re-evaluation on any related vulnerability signal
Permitted (additive, approved, auditable)
- Add market, customer, contractual, privacy, safety, or organizational requirements.
- Increase gate rigor, add approvers, change due-date rules, add deliverables, or select an approved risk method.
- Rename customer-facing labels while retaining canonical IDs and exports.
- Define product families, inheritance, reusable control baselines, evidence templates, and automation connectors.
Restricted (enforced by the platform)
- Core objectives and audit history cannot be edited in place.
- A required item may be marked not applicable only with documented rationale, evidence, authorized approval, and re-evaluation triggers.
- Customer profiles cannot silently downgrade access controls, separation of duties, record integrity, or mandatory regulatory obligations.
- Profile changes must be impact-assessed before they affect active product ecosystems.
- Framework Governance Board
- Framework release and high-impact mapping changes
- Regulatory Intelligence
- Regulatory content approval
- Customer Framework Administrator
- Customer additions; cannot alter immutable core
- Product Owner
- Gate approval within delegated authority
- Security Lead
- Technical approval; cannot self-approve independent retest
- System Architect
- Architecture approval
- Implementer
- Cannot approve own verification where independence is required
- Security Reviewer
- Accept/reject security evidence
- Quality / Regulatory
- Required gate approvals by profile
- Clinical Safety / Risk Authority
- Risk acceptance
- Operations / Incident Response
- Operational readiness and incident closure