Consolidated Milestone Summary — Verified Digital Credentials Platform (M1–M10)¶
As of: 13 Aug 2026 — kickoff held, POC demo delivered, client satisfied. Full task breakdown audited line-by-line against SOW Appendix 1 (Requirements Specification) and Appendix 2 (Deliverables/Milestones) on 13 Aug 2026. Source: SOW v0.3 (10 Aug 2026) Appendix 1 & 2, cross-checked against the earlier v3 High-Level Requirements document and the current POC codebase.
Overall picture¶
| Milestone | Feature Area | Requirement Clarity | Build Status |
|---|---|---|---|
| M1 | Planning & onboarding | ⚠️ 12 open items below | ⚪ Process milestone |
| M2 | Platform & client admin | 🟡 1 open item (KYB phasing) | 🟢 Largely built in POC |
| M3 | Issuing functionality | ✅ clear | 🟢 Best-covered area, demoed today |
| M4 | v0.1 Beta release | ✅ clear | ❌ Blocked on AWS hosting decision |
| M5 | Disclosure & Verification | ⚠️ 3 open items | ❌ Not started |
| M6 | v0.2 Beta release | ✅ clear | ❌ Depends on M5 |
| M7 | Reclaim Protocol | ⚠️ new scope, needs sign-off | ❌ Not started |
| M8 | v0.3 Beta release | ✅ clear | ❌ Depends on M7 |
| M9 | Hardening & Compliance | 🟡 4 open items | ❌ Not started |
| M10 | Go-live & Handover | ⚠️ acceptance-sequencing ambiguity | ❌ Not started |
The open requirement items that matter most¶
- M7 — Reclaim Protocol scope. Not in the original requirements doc at all; internal notes show a client-confirmation request may still be unanswered. This is the single largest block of unscoped work in the plan.
- M10 — Go-live vs. Final Acceptance definition. As written, it's unclear whether "go-live" at M10 refers to the same event as "Final Acceptance," which is separately defined to only occur after the Beta Programme completes.
- M5 — Disclosure policy configuration depth. Original doc deferred this to post-MVP with a default-only policy; SOW reads as full configuration in scope.
- M5 — Credits/vouchers mechanism. Referenced as a milestone line item but never fully specified in the SOW's Requirements Specification.
- M5 — General payment/invoicing capability (NFR5). A distinct requirement from item 4 above — confirm whether manual invoicing is acceptable for MVP; if so, this item may need no development at all.
- M4 — AWS hosting target. Needs deciding before M4, not M10, since the CI/CD pipeline's deploy step and several other tasks (backups, WAF, IaC, monitoring) all depend on it.
- M2 — KYB MVP-vs-Beta phasing. SOW text implies the in-platform KYB web form may only be required by "full Beta release," not the MVP milestone — the current task breakdown builds it outright with no phasing distinction.
- M9 — Regulatory compliance scope (UKDIATF, CCPA, SOC2, UK data retention). Each is named once in NFR3 with no further specification of what compliance activity is actually expected within this SOW.
- M9 — SAML 2.0. Listed as a supported standard in Appendix 6 but not otherwise referenced — confirm it's genuinely required for MVP.
- M9 — D5e release packaging. Unlike M4/M6/M8, M9 has no defined beta version number for its own deployment package.
- M10 — SOW-internal D7/D8 numbering inconsistency. Appendix 3 references a "D8" deliverable that Appendix 2's Deliverables table never defines.
- M2/M9 — Minor dropped specifics. Passkey support, SMS gateway integration, Zendesk-specific help tooling, backup retention/geo-distribution detail, and standalone DDoS requirement status all quietly disappeared between the original doc and the SOW.
Coverage note¶
Every FR (FR1–FR8), NFR (NFR1–NFR6), Other Requirement (OR1–OR3), Integration (INT1–INT8), and Deliverable (D1–D7, plus the D8 inconsistency noted above) in the SOW's Appendix 1 and Appendix 2 has a corresponding task file under one of the ten milestones — including the Functional/Technical Design and Test Evidence deliverables (D2a–d, D4a–d), which were missing from the first pass of this breakdown and have since been added to M2, M3, M5 and M7. Where the SOW itself doesn't give enough detail to define a task with confidence, that's recorded as an open item above and in the relevant task file, rather than filled in with an assumption.
Where effort is genuinely already banked¶
M2 and M3 (platform admin + credential issuing) are in good shape — most of their sub-features already have a working prototype from the POC, which is exactly what was demonstrated today.
Where nothing has been built yet¶
M5 through M10 — six of the ten milestones — have no code today, and most of those milestones also carry open requirement questions listed above. Resolving those questions early is the cheapest way to remove ambiguity before build work starts on them.