IT Audit Factory · Evidence-first audit operationsFree · Professional · MSP
C31-R1 development candidate · acceptance pending

SLSA — Software supply chain

23 scoped review items and 23 evidence objectives.

Evidence preparation

Professional and MSP include scoped programs, evidence guidance, templates, readiness work queues and exports. Free keeps its ISO-only assessment scope and shared design.

Edition and coverage

1.2. Build and Source tracks require independent target-level assessment. Provenance inspection and artifact digest matching alone do not establish a SLSA level. Trusted builder identity, signature verification, platform controls and source policy need review. SLSA v1.2, OpenSSF SLSA contributors. Community Specification License 1.0; pre-existing portions retain Apache 2.0 terms as stated in the upstream license. ITAF original evidence actions and identifiers added. No endorsement.

Native supporting observations, external tool results and manual evidence are reported separately. Missing results require review. An imported pass does not set an assessor decision.

Official source

C31-R1 is an installable development candidate. Clean installation and live environment acceptance remain pending. This website patch has not been deployed.