Complete engineering review¶
This is the start-to-finish path for evaluating a software product across its full lifecycle. Complete phases 1–16 in order, then run the existing production-readiness review before release approval.
The integrated corpus contains 10,042 unique controls: 8,621 lifecycle and quality controls with USEQ- IDs plus 1,421 production-readiness controls with PRC- IDs. The import reviewed 25,359 checkbox lines from 215 source documents and removed repeated boilerplate, explicit consolidated copies, mirrored production controls, and exact overlaps.
How to use the sequence¶
- Define the product, lifecycle, organization, release, and evidence boundaries.
- Work through every phase in order; use Not Applicable only with a reviewed rationale.
- Apply every specialized module whose trigger exists.
- Preserve evidence against the stable
USEQ-orPRC-identifier. - Finish with the production no-go screen, release evidence, sign-offs, and deployment verification.
The phases are ordered for navigation, not as a waterfall mandate. Iterative teams can revisit them continuously, but final approval still requires every applicable control to have a disposition.
Why this structure¶
The sequence follows the whole-lifecycle scope of ISO/IEC/IEEE 12207:2026 and groups implementation concerns using the SWEBOK Guide V4.0 knowledge areas. Quality is treated as a set of explicit product attributes using ISO/IEC 25010:2023, while secure development remains outcome- and risk-based in line with the NIST Secure Software Development Framework.
Specialized controls remain in the same journey rather than becoming separate products. Accessibility uses WCAG 2.2, application security maps to OWASP ASVS, and AI risk work is informed by the NIST AI Risk Management Framework. The references page explains scope and interpretation limits.
Lifecycle phases¶
| Phase | Category | Unique controls |
|---|---|---|
| 1 | Governance and foundations | 638 |
| 2 | Product and requirements | 105 |
| 3 | User experience, web, and content | 1,037 |
| 4 | Architecture and design | 241 |
| 5 | Code quality and implementation | 839 |
| 6 | Application services and APIs | 332 |
| 7 | Data and information lifecycle | 778 |
| 8 | Security and cryptography | 916 |
| 9 | Privacy and data protection | 136 |
| 10 | Verification and testing | 636 |
| 11 | Developer experience, platform, and delivery | 752 |
| 12 | Operations, SRE, and support | 581 |
| 13 | Documentation and knowledge | 241 |
| 14 | Trust, safety, and ecosystems | 235 |
| 15 | AI, ML, and AI-assisted development | 632 |
| 16 | Specialized domains and release assurance | 522 |
| Final release review | Production readiness | 1,421 |
Decision rule¶
Completion is not a score. One material failure can block approval regardless of how many unrelated controls pass.
Use the source consolidation manifest to trace each imported source document to its destination and understand what was removed as duplicate or already covered.