Assurance Scope Model

This page defines the evidence-ownership and software-estate boundary for every Assurance pack: which evidence Stella Ops can produce or help package, and whose responsibility each evidence lane remains. It is the guardrail that keeps an Assurance pack from drifting into a blanket “compliant” claim. Read it alongside the Assurance Runtime architecture and the product-level Assurance and Compliance Packs entry point.

Stella Ops is a release control plane and DevOps vulnerability scanner, not a broad compliance suite. Assurance packs describe what evidence Stella can produce or help package, and whose responsibility each evidence lane remains.

Scope Lanes

ScopeOwnerUsed for
stella-productStellaCRA product-security publication, CVD, support lifecycle, signed releases, SBOM/VEX, and product advisory evidence.
stella-supplierStella as supplier or ICT third partySigned releases, SBOM/VEX, build attestations, advisory/CVD posture, security contact, lifecycle, and incident notification evidence reused by an operator.
operator-observed-estateOperator, observed through StellaContainer images, release bundles, services, integrations, plugins, runtime host agents, asset registry entries, reachability, policy gates, and evidence bundles Stella deploys, scans, observes, or controls.
operator-suppliedOperator or product manufacturerLegal entity facts, regulatory classification, governance policies, HR/training, physical security, contracts, subcontracting beyond direct integrations, risk acceptance, filing approvals, and competent-authority details.

Pack Application

PackPrimary scopeNotes
NIS2 Evidence Packoperator-observed-estateStella can support software-estate evidence for Article 21-style control mapping, SoA exports, incident timelines, and effectiveness metrics. Entity classification, governance ownership, physical security, HR, and process evidence remains operator-supplied.
DORA Operational Resilience Packoperator-observed-estateStella can support ICT software evidence, RoI local-contract projection for observed integrations/assets, major-incident handoff facts, TLPT evidence packaging, retention, and Article 45 sharing batches. Financial-entity identity, contracts, outsourcing decisions, subcontracting beyond direct integrations, and filings remain operator-supplied.
CRA Product Security Packstella-productStella owns this product/security publication evidence for Stella itself.
CRA Technical Documentation Packoperator-suppliedStella assembles signed dossiers for a manufacturer; the product manufacturer supplies product identity, intended purpose, conformity route, and non-Stella product evidence.

Implementation Rules

Software Estate Boundary

For NIS2/DORA, “software Stella can monitor or deploy” means:

Anything outside that boundary is either operator-supplied or out of scope for Stella evidence.