REG-{{YYYYMMDD}}-{{short-id}} — {{Asset short title}}

Per docs/legal/regulatory-asset-intake.mdFilename regex: REG-\d{8}-[a-z0-9-]+\.md (no other characters). Records are append-only. To revoke, open a successor and add a “Superseded by” row at the bottom of this file.

Asset metadata

FieldValue
RegimeeIDAS / DORA-IR / DORA-RoI / CRA / Other
Vendor / regulatore.g. EBA, OASIS, named QTSP
Version pin (canonical)exact regulator-published string, no abbreviation
Source URLsone per line
Transitive referencesURLs of any embedded schemas/standards
Candidate SHA-256sha256:<lowercase hex> of the candidate archive
Candidate bytessize in bytes
Source dateYYYY-MM-DD of the regulator publication

Proposed local path

docs/contracts/schemas/eu/<regime>/<vendor>/<version>/

(If a new top-level path is required, list the YAML inventory amendment needed first; that amendment is part of Gate 2.)

Runtime use

Gate 1 — Engineering candidacy

FieldValue
Engineername + sprint role
Date submittedYYYY-MM-DD
Outcomepass (record proceeds to Gate 2)
Notesany unresolved questions for downstream gates

Gate 2 — Schema-governance review

FieldValue
Reviewermaintainer-of-record or named alternate
DateYYYY-MM-DD
Re-computed SHA-256sha256:<hex> (must match the candidate digest above)
Outcomepass / reject
Notespath-namespacing decisions, partial-vendor concerns, transitive completeness
FieldValue
Reviewernamed legal reviewer
DateYYYY-MM-DD
BUSL-1.1 compatibilitycompatible / compatible-with-notice / reference-only / incompatible
Distribution licenseSPDX expression or full text reference
Determinationapproved-vendor / approved-with-notice / reference-only-no-vendoring / rejected
Attribution texttext that will go into NOTICE.md (may be a multi-line block here)
third-party-licenses/ filenamenew file path, if any
Notesreasoning, restrictions, expiry conditions

Gate 4 — Compliance / Vendor Integration

(Required only for vendor-qualified packages; skip for regulator-published-only assets.)

FieldValue
Reviewernamed compliance / vendor-integration owner
DateYYYY-MM-DD
Vendor agreement referencecontract id or document path
Jurisdictione.g. EU/DE
Profilee.g. RFC 3161 + CAdES-LTA
Expiry / renewal dateYYYY-MM-DD
Verdict fixturespath to the accepted/rejected verdict pairs that prove the validator wires correctly
Outcomepass / reject

Gate 5 — Vendoring + sprint update

(Filled in at merge time.)

FieldValue
Implementername
Date vendoredYYYY-MM-DD
Local pathfull path under docs/contracts/schemas/eu/.../
YAML inventory entryinline diff or anchor to the entry under assets:
NOTICE.md changeline range / commit
THIRD-PARTY-DEPENDENCIES.md changeline range / commit
Originating sprint Execution Log entrysprint filename + date
Outcomepass

Linked artefacts

Supersedes / superseded-by

(Append-only history. Empty on first publication.)