Bound the decision
Start with a source and destination scope or named record group. State what evidence was actually reviewed: an authorized reconciliation report, a sampled record list, a signed-off exception list, or another agreed artifact. Do not convert an uninspected vendor assertion into an accepted fact.
CISA's Secure by Demand Guide encourages structured buyer questions for software suppliers. It does not set a private contract's migration criteria, payment terms, remedies, or acceptance decision. Use the guide only for the narrow principle that material questions should be inspectable.
Keep exceptions attached to the decision
For every rejected or unresolved group, record the item identity or scope, the
exception owner, and the correction or re-run path. Add the agreement or
acceptance-criterion reference, authorized decision-maker, and decision date so
an operational data check is not mistaken for commercial acceptance. Unknown
or hold is a valid state. It is more useful than marking a migration accepted
while leaving a buyer to discover later whether an exception was intentionally
excluded.
The register below is a commercial discussion aid, not legal advice. A commercial buyer and operational data owner should apply it to an authorized agreement and evidence before it affects payment or acceptance.
| Scope or record group | Agreement or acceptance criterion | Evidence reviewed | Accepted items | Rejected or unresolved items | Exception owner | Correction or re-run path | Authorized decision-maker and date | Acceptance decision |
|---|---|---|---|---|---|---|---|---|
__________ |
__________ |
__________ |
__________ |
__________ |
__________ |
__________ |
__________ |
Accept / hold / reject |
__________ |
__________ |
__________ |
__________ |
__________ |
__________ |
__________ |
__________ |
Accept / hold / reject |
Illustrative only: a fictional fixture with one unresolved row should remain
hold until the named authority makes a dated decision. This is not evidence
about a vendor, agreement, or real migration.
| Scope or record group | Agreement or acceptance criterion | Evidence reviewed | Accepted items | Rejected or unresolved items | Exception owner | Correction or re-run path | Authorized decision-maker and date | Acceptance decision |
|---|---|---|---|---|---|---|---|---|
| Synthetic appointment fixture | Fictional fixture criterion | Row-ID reconciliation report | r-1, r-2 |
r-3 missing required owner |
Buyer data owner | Correct fixture, rerun, compare same row IDs | Buyer lead, date pending | Hold |
Do not collapse distinct gates
Migration acceptance is not the same as proposal assumptions or implementation prerequisites. Use Record Assumptions in a Software Proposal before award, and Record Software Implementation Prerequisites Before Start before work begins. For the broader final-payment packet, see What a Custom-Software Acceptance Packet Should Prove.
Must every unresolved item force rejection?
Not necessarily. The buyer must make the unresolved item, owner, correction path, and decision explicit under the applicable agreement. This worksheet does not say what any agreement requires or make a commercial decision for the buyer.