Where documentation fails review
The deficiencies we see most often in Additional Information letters aren't about missing documents. They're about documents that don't agree with each other.
- A threat model that doesn't match the architecture views, so the reviewer can't trace a threat to a data flow
- Controls listed without rationale, so there's no way to tell which threat each one addresses
- An SBOM with no vulnerability analysis and no level-of-support statement
- Open anomalies with no assessment of security impact
- No post-market plan, or one with no owner, no timelines, and no disclosure process
- Test results that don't connect back to the risk assessment they were supposed to verify