M9 — Hardening and Compliance¶
SOW Deliverable(s): D5e — Deployment Package ⚠️ unlike M4/M6/M8, Appendix 2 doesn't define a numbered beta release (v0.4 etc.) for this milestone's output — confirm with Curo whether D5e ships as part of the M10 production deployment or needs its own separate release step Requirement source: SOW Appendix 1 — NFR3 (Security, Privacy, Compliance); NFR1 (Scalability/Recoverability); NFR2 (Accessibility); Appendix 6 Security/Operational Requirements
Tasks¶
Two substantial existing audit docs matched this milestone directly and were moved here; the rest are new task files.
| ID | Task | SOW Ref | Requirement Clarity | Dev Status | Task File |
|---|---|---|---|---|---|
| M9-00 | (reference) Security & Encryption Audit | NFR3 | ✅ | 🟡 | M9-00-security-encryption-audit.md — moved from existing doc |
| M9-01 | GDPR — right to erasure / data disposal | NFR3 | ✅ | ❌ Not started | M9-01-gdpr-right-to-erasure.md |
| M9-01b | (reference) Logging & Tracking Reconciliation | FR8, NFR3 | ✅ | 🟡 | M9-01b-logging-tracking-reconciliation.md — moved from existing doc |
| M9-02 | GDPR — subject access request handling | NFR3 | ✅ | ❌ Not started | M9-02-gdpr-subject-access-requests.md |
| M9-03 | GDPR — consent management | NFR3 | ✅ | ❌ Not started | M9-03-gdpr-consent-management.md |
| M9-04 | Security hardening — DDoS protection | NFR3, Appendix 6 | 🟡 Confirm still required — see task file | ❌ Not started | M9-04-ddos-protection.md |
| M9-05 | Security hardening — WAF | NFR3, Appendix 6 | ✅ | ❌ Not started | M9-05-waf-configuration.md |
| M9-06 | Security hardening — key rotation | NFR3, Appendix 6 | ✅ | 🟡 | M9-06-key-rotation.md |
| M9-07 | Account/profile management finishing | FR6, FR7 | ✅ | 🟡 | M9-07-account-profile-management-finishing.md |
| M9-08 | Performance & load testing (1000–2000 tx/hr, 1000 concurrent users, 100 registrations/min) | NFR1 | ✅ | ❌ Not started | M9-08-performance-load-testing.md |
| M9-09 | Accessibility (WCAG 2.1 AA) compliance pass, incl. mobile-responsive UI check | NFR1, NFR2 | ✅ | ❌ Not started | M9-09-accessibility-compliance.md |
| M9-10 | Backup, disaster-recovery & failover validation | NFR1 | 🟡 Confirm retention/geo-distribution — see task file | ❌ Not started | M9-10-backup-dr-failover-validation.md |
| M9-11 | Independent penetration test facilitation & remediation | NFR3 | ✅ | ⚪ Not yet scheduled | M9-11-penetration-test-facilitation.md |
| M9-12 | Additional identity/transport protocol support — SAML 2.0, TLS 1.3 | NFR3, Appendix 6 | ✅ | ❌ Not started | M9-12-saml2-tls13-protocol-support.md |
| M9-13 | Regulatory & industry compliance — UKDIATF, CCPA, SOC2, UK data retention | NFR3 | 🟡 Each item needs scope clarification — see task file | ❌ Not started | M9-13-regulatory-industry-compliance.md |
| M9-14 | Production monitoring & alerting | Appendix 6, OR3 | ✅ | ❌ Not started | M9-14-production-monitoring-alerting.md |
| M9-15 | JSON/XML data export & exchange support | NFR4 | ✅ | ❌ Not started | M9-15-json-xml-data-export-exchange.md |
Notes¶
This milestone is where most of the "paper compliance" promises (GDPR, WCAG, uptime SLAs) actually get tested for real, and right now none of it has started. The regulatory items in M9-13 (UKDIATF, CCPA, SOC2) are each under-specified in the SOW itself — flagged rather than guessed at.