CM-14 - Signed Components

Prevent the installation of [Assignment: organization-defined software and firmware components] without verification that the component has been digitally signed using a certificate that is recognized and approved by the organization.


ID: CM-14
Enhancements: 

Space Segment Guidance

Signed components establish trust in flight software, bootloaders, and configuration packages under on-board constraints. Consider how signatures are created, protected, and verified; how key rotation is performed on-orbit; and how activation behaves when verification fails during short contacts. Staging new keys in advance, using dual-bank or controlled fallback images, and reporting verification outcomes in telemetry help maintain recoverability without ambiguity.