SPC / SPC-04
Security assurance case and accreditation support
Assemble evidence and decisions enabling a competent authority to accept a system’s risks within a defined framework. The provider prepares the case; it does not replace the decision-maker or grant accreditation merely by delivering a service.

WHEN IT HELPS
A focused response
to a defined need.
System requiring accreditation, public-sector or sensitive project, production release needing a security case or renewal of an existing decision.
SCOPE & OUTCOMES
What the engagement covers.
Scope
- Applicable framework
- authority
- scope
- risk assessment
- requirements
- architecture
- audit evidence
- treatment plan
- residual risks
- operating and review conditions
Deliverables
- Structured case
- requirements/evidence matrix
- risk assessment
- action plan
- residual-risk summary
- decision-board support
- review schedule
Acceptance evidence
The case is complete for the agreed scope; evidence is traceable; conditions and risks are honestly presented; the authority retains the decision; case maintenance is organised.
DELIVERY
How the work is structured.
Approach
Verify expertise and authorisation; scope constraints; collect without unapproved risk; assess and propose; validate with competent owners.
Prerequisites & responsibilities
Customer: decision authority, operators, control engineers or transaction leads as applicable. Provider: validated expertise; specialist partners where needed and approved.
Scope factors
Sites, systems, safety, evidence access, independence and qualification requirements. Bespoke engagement; effort and subcontracting confirmed before proposal.
Questions to clarify
Which authority decides and under what framework? Which evidence is required? Which changes trigger review and which conditions are acceptable?
IMPORTANT BOUNDARIES
Any required assessor qualification, independence or framework-specific condition is established before engagement. The work supports an assurance decision; it does not guarantee a favourable outcome.
Delivery is conditional on the specialist resources, authorisations and framework requirements established during scoping. Formal qualifications and clearance are confirmed where required.
IN PRACTICE
Illustrative situations.
These examples describe possible engagements and target outcomes. They are not customer references or achieved results.
Scenario 01
An organisation prepares a sensitive new portal. Project: organise risks, architecture and test results into one case. Target outcome: a decision based on coherent evidence, with explicit conditions where controls remain unfinished.
Scenario 02
A system changes after initial approval. Project: assess changes and update affected evidence. Target outcome: proportionate reassessment; the old decision is not presented as automatically covering the new architecture.
Technology and reference context
References: ANSSI accreditation approach and applicable risk assessment; document and evidence-tracking tools.
The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.
CONNECTED SERVICES
Build the next step.
These services can complement the engagement. They are not automatically included.
START A CONVERSATION
Make the scope clear.
We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.
