# Quick due diligence checklist (§5.4.5)

Twelve questions to ask before integrating a FOSS component. It does not replace a structured risk assessment, but offers an accessible and proportionate entry point for SMEs with limited resources.

## Basic visibility

- [ ] Is the project actively maintained?
- [ ] Is version history transparent?
- [ ] Is a security contact publicly available?

## Vulnerability awareness

- [ ] Are vulnerabilities documented?
- [ ] Are fixes released in a structured manner?
- [ ] Is there evidence of responsiveness?

## Supply chain transparency

- [ ] Is the component included in the SBOM?
- [ ] Are dependencies visible?
- [ ] Is versioning consistent?

## Lifecycle considerations

- [ ] Is there evidence of ongoing maintenance?
- [ ] Are updates communicated clearly?
- [ ] Is end-of-life status defined?

---

_Based on OCCTET deliverable D2.3 – CRA Adoption Best Practice Document (v1.0, March 2026), licensed under CC BY 4.0._

<https://occtet.eu/best-practices/checklists-and-templates/>
