Level 1: assertion
A proposal statement, questionnaire answer, marketing page, roadmap statement, or verbal response tells you what the supplier believes or is willing to claim. It is useful for discovery, but it is weak evidence for a consequential acceptance decision.
Use assertions to identify what needs to be demonstrated, documented, contractually committed, or tested next.
Level 2: documented design
Policies, architecture diagrams, procedures, control descriptions, accessibility conformance reports, data-flow diagrams, and implementation plans provide inspectable context. They can reveal scope and design intent, but may not prove the control or workflow behaves as described.
Check the date, scope, product or environment covered, exclusions, and whether the document describes current operation or a future state.
Level 3: operating evidence
Representative demonstrations, configuration exports, logs, test results, restore evidence, migration samples, audit events, vulnerability-remediation records, accessibility workflow tests, and incident artifacts show behavior. For high-impact requirements, this is often where confidence becomes defensible.
A test is strongest when the scenario resembles the environment, roles, data, integrations, and failure conditions the buyer will actually operate.
Level 4: accountable commitment
Contract language, service levels, acceptance criteria, named remediation obligations, exit assistance, portability commitments, and approved risk exceptions establish who owns the consequence when reality differs from the claim. They do not replace technical evidence, but they make responsibility explicit.
For a material dependency, pair operating evidence with a durable commitment whenever the buyer would otherwise carry unacceptable ambiguity after award.
Use a decision record instead of scattered notes.
For each material requirement, preserve the pass condition, criticality, evidence requested, evidence actually reviewed, disposition, unresolved condition, accountable owner, approval authority, review trigger, and implementation acceptance criterion. This creates continuity between requirements, evaluation, implementation, production readiness, and later audit or renewal review.