A written response is required for each applicable input; “none” is valid when a requirement does not apply.
- OS bases and versions
- List each distribution or base, version, architecture, support channel, and lifecycle status.
- Artifact targets
- List every required output format and target, such as ISO, PXE, AMI, QCOW2, VDI, bootc, or appliance media.
- Cloud, region, account, and publishing scope
- Identify every destination cloud, region, account, registry, promotion channel, and customer handoff path.
- Compliance controls and evidence
- Name the control baselines, requested claim term, evidence artifacts, assessors, and retention requirements; use none when not applicable.
- Runtime validation depth
- Define smoke, boot, integration, security, performance, and application tests plus the environments in which they must run.
- Maintenance and release cadence
- State scheduled rebuild and release frequency, maintenance windows, blackout periods, and release-notice expectations.
- CVE trigger thresholds and response SLA
- Define severity source, score or advisory thresholds, affected-component rules, triage timer, rebuild deadline, emergency path, and exceptions.
- Customer-private software and license entitlements
- Identify private packages, entitlement owner, permitted sources, redistribution constraints, and controlled access method. Do not include credential or license-secret values.
- Marketplace listing or private-offer requirements
- Identify marketplace, listing owner, seller account, regions, pricing model, metering, support terms, legal review, and private-offer needs; use none when not applicable.