Phase 6: Security & Compliance Gates
Goal: Production accepts traffic only when agreed controls are proven—not because of deadline pressure alone.
- User Acceptance Testing (UAT) — business scenarios, execution evidence, product owner sign-off
- Security review — Snyk/Wiz/Infrastructure as Code (IaC) scan findings closed or documented accepted risk
- Compliance pack — diagrams, log retention, Disaster Recovery (DR) drill if in scope
- Go/no-go — sponsor + risk + platform
Next: Phase 7: Handover