# Open source component record (A1.3)

For medium and high criticality components, or any publicly exposed component. It complements the component register by documenting why the component was selected and what monitoring is in place.

## Component

- **Component name**:
- **Version / range used**:
- **Repository / reference link** (optional):
- **Used in** (module / feature):
- **Functional criticality** (Low / Medium / High):
- **Exposure** (Internal / Limited / Public):
- **License**:

## Selection rationale — Why this component?

- **Why was it chosen?** (e.g., feature fit, stability, performance, ecosystem)
- **Alternatives considered** (if any):

## Basic due diligence performed

- [ ] Maintainer activity reviewed
- [ ] Vulnerability history reviewed
- [ ] Security contact / disclosure method available (if applicable)
- [ ] License compatibility confirmed
- [ ] Included in SBOM

## Known risks / notes

- **Known limitations / concerns**:
- **Dependency depth concerns** (if relevant):

## Monitoring and ownership

- **Update owner / responsible person**:
- **Vulnerability monitoring source(s)** (e.g., advisories, CVE feeds, repository alerts):
- **Review frequency** (e.g., monthly + urgent alerts as needed):
- **Last review date**:
- **Next planned review date**:

---

_Based on OCCTET deliverable D2.3 – CRA Adoption Best Practice Document (v1.0, March 2026), licensed under CC BY 4.0._

<https://occtet.eu/best-practices/checklists-and-templates/>
