Evidence-centric certification maintenance under continuous system change

Security certification becomes difficult to maintain when digital systems evolve through software releases, configuration updates, dependency changes, credential rotation, and infrastructure modifications. Although certification schemes provide rigorous procedures for evaluating a defined system state, maintaining the evidence supporting that assessment becomes more difficult when the evaluated baseline changes. This paper presents an evidence-centric approach to certification maintenance under controlled system change. Certification-relevant evidence is organised into versioned baselines, while an explicit requirement–evidence obligation model defines the evidence and verification activities expected for each requirement. A typed traceability graph materialises dependencies among requirements, controls, components, evidence artefacts, verification activities, results, baselines, and change events. A material-change policy then applies direction-specific traversal rules to derive bounded reassessment packages containing the requirements, evidence refreshes, repeated verification activities, and invalidated or superseded results associated with a recorded change. The approach supports reassessment without automating certification judgement or assuming that the resulting scope is globally minimal. The approach is implemented and evaluated in a controlled ESP32-PICO pilot combining mTLS-protected MQTT communications with signed OTA artefacts. The experimental baseline contains 39 physical repository files, 38 evidence items, and 28 verification activities across a 26-requirement assurance profile. Baseline assessment identifies 2 supported and 24 partially supported requirements, retaining unavailable evidence and non-executable verification activities as explicit coverage gaps. Across eight controlled change scenarios, 94.87–97.44% of the physical repository files remain reusable while the material-change policy produces distinct policy-reachable requirement sets. Mean end-to-end processing time is 192.12 ms for the reference baseline and remains below one second at 5,000 physical files in the synthetic scalability experiment. These results show that versioned evidence baselines, explicit evidence and verification obligations, and policy-directed traceability can provide a reproducible basis for bounded reassessment under controlled system change. The evaluation establishes the feasibility of the approach within the declared experimental profile; it does not establish certification compliance, global minimality of reassessment, or reductions in assessor effort.

Authors

Institutions

Publication Details

Journal
Scientific Reports
Published
2026-10-05
DOI
https://doi.org/10.1038/s41598-026-72663-z
Primary Topic
Safety Systems Engineering in Autonomy
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
OCT
article

Evidence-centric certification maintenance under continuous system change

Antonio Muñoz, Sergio López-Flores
Scientific Reports
Safety Systems Engineering in Autonomy
article

Evidence-centric certification maintenance under continuous system change

Antonio Muñoz, Sergio López-Flores
article en

Abstract

Security certification becomes difficult to maintain when digital systems evolve through software releases, configuration updates, dependency changes, credential rotation, and infrastructure modifications. Although certification schemes provide rigorous procedures for evaluating a defined system state, maintaining the evidence supporting that assessment becomes more difficult when the evaluated baseline changes. This paper presents an evidence-centric approach to certification maintenance under controlled system change. Certification-relevant evidence is organised into versioned baselines, while an explicit requirement–evidence obligation model defines the evidence and verification activities expected for each requirement. A typed traceability graph materialises dependencies among requirements, controls, components, evidence artefacts, verification activities, results, baselines, and change events. A material-change policy then applies direction-specific traversal rules to derive bounded reassessment packages containing the requirements, evidence refreshes, repeated verification activities, and invalidated or superseded results associated with a recorded change. The approach supports reassessment without automating certification judgement or assuming that the resulting scope is globally minimal. The approach is implemented and evaluated in a controlled ESP32-PICO pilot combining mTLS-protected MQTT communications with signed OTA artefacts. The experimental baseline contains 39 physical repository files, 38 evidence items, and 28 verification activities across a 26-requirement assurance profile. Baseline assessment identifies 2 supported and 24 partially supported requirements, retaining unavailable evidence and non-executable verification activities as explicit coverage gaps. Across eight controlled change scenarios, 94.87–97.44% of the physical repository files remain reusable while the material-change policy produces distinct policy-reachable requirement sets. Mean end-to-end processing time is 192.12 ms for the reference baseline and remains below one second at 5,000 physical files in the synthetic scalability experiment. These results show that versioned evidence baselines, explicit evidence and verification obligations, and policy-directed traceability can provide a reproducible basis for bounded reassessment under controlled system change. The evaluation establishes the feasibility of the approach within the declared experimental profile; it does not establish certification compliance, global minimality of reassessment, or reductions in assessor effort.

Scientific Reports
Universidad de Málaga (ES)
Openalex Percentile: Top 11%
Safety Systems Engineering in Autonomy
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.