Skip to content

M9 — Hardening and Compliance

SOW Deliverable(s): D5e — Deployment Package ⚠️ unlike M4/M6/M8, Appendix 2 doesn't define a numbered beta release (v0.4 etc.) for this milestone's output — confirm with Curo whether D5e ships as part of the M10 production deployment or needs its own separate release step Requirement source: SOW Appendix 1 — NFR3 (Security, Privacy, Compliance); NFR1 (Scalability/Recoverability); NFR2 (Accessibility); Appendix 6 Security/Operational Requirements

Tasks

Two substantial existing audit docs matched this milestone directly and were moved here; the rest are new task files.

ID Task SOW Ref Requirement Clarity Dev Status Task File
M9-00 (reference) Security & Encryption Audit NFR3 🟡 M9-00-security-encryption-audit.md — moved from existing doc
M9-01 GDPR — right to erasure / data disposal NFR3 ❌ Not started M9-01-gdpr-right-to-erasure.md
M9-01b (reference) Logging & Tracking Reconciliation FR8, NFR3 🟡 M9-01b-logging-tracking-reconciliation.md — moved from existing doc
M9-02 GDPR — subject access request handling NFR3 ❌ Not started M9-02-gdpr-subject-access-requests.md
M9-03 GDPR — consent management NFR3 ❌ Not started M9-03-gdpr-consent-management.md
M9-04 Security hardening — DDoS protection NFR3, Appendix 6 🟡 Confirm still required — see task file ❌ Not started M9-04-ddos-protection.md
M9-05 Security hardening — WAF NFR3, Appendix 6 ❌ Not started M9-05-waf-configuration.md
M9-06 Security hardening — key rotation NFR3, Appendix 6 🟡 M9-06-key-rotation.md
M9-07 Account/profile management finishing FR6, FR7 🟡 M9-07-account-profile-management-finishing.md
M9-08 Performance & load testing (1000–2000 tx/hr, 1000 concurrent users, 100 registrations/min) NFR1 ❌ Not started M9-08-performance-load-testing.md
M9-09 Accessibility (WCAG 2.1 AA) compliance pass, incl. mobile-responsive UI check NFR1, NFR2 ❌ Not started M9-09-accessibility-compliance.md
M9-10 Backup, disaster-recovery & failover validation NFR1 🟡 Confirm retention/geo-distribution — see task file ❌ Not started M9-10-backup-dr-failover-validation.md
M9-11 Independent penetration test facilitation & remediation NFR3 ⚪ Not yet scheduled M9-11-penetration-test-facilitation.md
M9-12 Additional identity/transport protocol support — SAML 2.0, TLS 1.3 NFR3, Appendix 6 ❌ Not started M9-12-saml2-tls13-protocol-support.md
M9-13 Regulatory & industry compliance — UKDIATF, CCPA, SOC2, UK data retention NFR3 🟡 Each item needs scope clarification — see task file ❌ Not started M9-13-regulatory-industry-compliance.md
M9-14 Production monitoring & alerting Appendix 6, OR3 ❌ Not started M9-14-production-monitoring-alerting.md
M9-15 JSON/XML data export & exchange support NFR4 ❌ Not started M9-15-json-xml-data-export-exchange.md

Notes

This milestone is where most of the "paper compliance" promises (GDPR, WCAG, uptime SLAs) actually get tested for real, and right now none of it has started. The regulatory items in M9-13 (UKDIATF, CCPA, SOC2) are each under-specified in the SOW itself — flagged rather than guessed at.