What evidence should product teams keep for CRA OTA and update-distribution decisions?
Keep evidence that connects the update mechanism to the CRA cybersecurity risk assessment, vulnerability-handling process, and technical documentation.
For an OTA or other update path, the useful record is usually a short architecture description of the update channel, package-signing and verification model, rollback protection, user-notification and postponement flow, support-period statement, release availability policy, and exception rationale for products where automatic updates are not applicable.
For each security update, keep the vulnerability or issue being remediated, severity and exploitability assessment, affected versions, separation analysis for any bundled functionality change, release and advisory text, rollout controls, user-notification evidence, and the reason for any withdrawal, recall, or latest-version-only remediation decision.
Supports technical documentation, vulnerability-handling, user-information, support-period, and secure update-distribution evidence.
Supports practical remediation, user-installation, recall, and security-versus-functionality update considerations.
Supports evidence around secure installation, update checks, authenticity and integrity verification, user notices, and published support periods.