# Dependency update policy (A1.5)

A short-form policy defining how third-party dependencies are reviewed, updated, and retired. One page is enough.

## Scope

Applies to third-party dependencies, including FOSS components.

## Principle

Dependencies are maintained in a risk-based and lifecycle-oriented manner. Update actions are proportional to criticality, exposure, and impact.

## Update cadence

- **Routine dependency review** (e.g., monthly / quarterly):

Security updates are applied based on risk classification:

- **High risk:** as soon as possible
- **Medium risk:** planned fix within the next release cycle
- **Low risk:** tracked and resolved during normal maintenance

## Decision ownership

- **Dependency upgrade approval owner**:
- **Emergency security fix approval owner**:

## End-of-life dependencies

If a dependency becomes unsupported or end-of-life, we:

- Record the risk
- Evaluate alternatives
- Plan migration or compensating controls
- Document the decision and timeline

---

_Based on OCCTET deliverable D2.3 – CRA Adoption Best Practice Document (v1.0, March 2026), licensed under CC BY 4.0._

<https://occtet.eu/best-practices/checklists-and-templates/>
