{
  "format": "conformops-editorial-walkthrough",
  "version": 1,
  "reviewed": "2026-09-16",
  "fictional": true,
  "source": "https://conformops.eu/resources/see-a-cra-assessment-example",
  "notice": "Fictional teaching example. Not customer evidence, output from an executed assessment, an actual ConformOps export schema, an SBOM or a legal conclusion.",
  "product": "Harbour Notes",
  "release": "1.4",
  "description": "A fictional desktop application with an update service. Legal scope and classification are not determined by this example.",
  "records": [
    {
      "supplied_record": "Security contact policy",
      "observation": "A route for reporting a vulnerability is documented",
      "still_unanswered": "Who monitors it and how the team has tested the process"
    },
    {
      "supplied_record": "Dependency lockfile",
      "observation": "Some component versions are recorded",
      "still_unanswered": "Whether the inventory covers the delivered product"
    },
    {
      "supplied_record": "Release instructions",
      "observation": "The update process is described",
      "still_unanswered": "What testing supports the security of that process"
    },
    {
      "supplied_record": "Product facts",
      "observation": "A support commitment has been proposed",
      "still_unanswered": "Its rationale, approved dates and what users are told"
    }
  ]
}
