---
title: "Technical Quality Gate & Validation"
description: The four pillars of the STACKIT Quality Framework, recommended penetration testing aligned with EU regulation, and the binding technical self-attestation.
sidebar:
  label: "Quality Gate & Certification"
  order: 8
  attrs:
    data-icon: shield
source_url: "https://framework.stackit.cloud/isv/technical-quality-gate-and-certification/"
source_file: "docs/isv/technical-quality-gate-and-certification.mdx"
---

To guarantee enterprise-grade resilience, security, and digital sovereignty for our customers, every
application must pass the STACKIT Technical Quality Gate before being listed on the Marketplace.

At STACKIT, we strictly adhere to BSI C5 compliance, meaning we have **zero access to your project
environments or customer data**. Therefore, our Quality Gate operates on architectural compliance,
robust security validation, and binding self-attestation.

## The STACKIT Quality Framework (4 Pillars)

Your software is evaluated against the STACKIT Certified Sovereign ISV framework, which consists of
four core pillars.

**Pillar A — Sovereignty (ES³)**
Your application must pass the [ES³ assessment](/isv/es3-self-assessment/) (completed in Phase 7),
proving data residency and immunity against third-country access.

**Pillar B — Technical Resilience & Cloud-Native**
Your architecture must be designed for failure. This includes mandatory Multi-AZ deployments across
at least two STACKIT Availability Zones and a stateless architecture, preferably utilizing the
STACKIT Kubernetes Engine (SKE).

**Pillar C — Factory-Readiness (Standardization)**
You should leverage STACKIT's predefined Infrastructure-as-Code (IaC) templates. Implementations
should be based on the STACKIT Landing Zone repository and our Terraform Blueprints for services
like PostgreSQL and Object Storage.

**Pillar D — Enterprise Security & Compliance**
Enforced encryption (at rest and in transit), strict IAM policies without excessive administrative
privileges, and systematic vulnerability management.

## Security Validation & Recommended Penetration Testing (Pentest)

To protect both your customers and the reputation of the STACKIT platform, we strongly recommend
conducting a comprehensive Penetration Test (Pentest) prior to commissioning your application.

### Contractual Obligations (PBA Annex 2 TOMs)

While STACKIT cannot directly inspect your live infrastructure or enforce a specific third-party
audit, please note your contractual commitment:

<Aside type="danger" title="Mandatory compliance">
  By signing the [Partner Base Agreement (PBA)](/isv/signing-and-legal-alignment/), your
  organization has contractually committed to the Technical and Organizational Measures (TOMs)
  specified in Annex 2. All security and compliance controls outlined in Annex 2 must be
  technically validated and operational before going live.
</Aside>

### Regulatory Alignment in the EU

For ISVs targeting European enterprise and regulated markets, aligning your security testing with
European standards is critical. A penetration test in the EU context serves as an authorized
security audit aligned with strict regulatory frameworks:

- **TIBER-EU**: A framework for threat-led penetration testing under real-world conditions.
- **DORA (Digital Operational Resilience Act)**: Mandates rigorous and regular security testing for
  software vendors serving the financial sector in the EU.
- **NIS-2 & Cyber Resilience Act (CRA)**: Broaden obligations for digital service providers and
  software manufacturers to identify, manage, and report software vulnerabilities.

Executing a structured pentest ensures your application meets these evolving European compliance
requirements.

## Self-Attestation & Formal Confirmation

Until full integration into the STACKIT Partner Portal is available, the Technical Quality Gate
concludes with a formal email-based **Technical Self-Attestation**.

### Submission Process

The Technical Lead or CTO of your organization must send a formal confirmation email to the ISV
Factory team at `isv-sales@digits.schwarz`.

**Required Confirmation Content**: By submitting this email, your technical management explicitly
confirms that:

- The application architecture adheres to the 4 Pillars of the STACKIT Quality Framework.
- All Technical and Organizational Measures (TOMs) defined in PBA Annex 2 have been technically
  validated and fully implemented in your production deployment.
- Appropriate security validation (e.g., vulnerability scans or penetration testing) has been
  conducted to verify the software's resilience prior to launch.

<Aside type="note">
  STACKIT provides a standardized confirmation email template in the Resource Hub to simplify this
  step.
</Aside>

<Aside type="caution" title="Important Notice">
  Unresolved critical security vulnerabilities or severe post-launch deviations from PBA Annex 2
  TOMs may result in the immediate revocation of your Marketplace listing status.
</Aside>

## Phase Completion Criteria

- [ ] Architecture complies with the 4 Pillars of the STACKIT Quality Framework.
- [ ] Security controls and PBA Annex 2 TOMs technically validated.
- [ ] Pre-commissioning Penetration Test (Pentest) conducted (strongly recommended).
- [ ] Formal Technical Self-Attestation email sent to `isv-sales@digits.schwarz` by the
      ISV Technical Lead.
- [ ] **Milestone achieved**: Solution is granted the "STACKIT Sovereign Factory Approved" status
      and is ready for
      [Placement & Marketplace Enablement](/isv/placement-and-marketplace-enablement/).

## Support & Contact

If you encounter blockers or have questions regarding this phase, reach out to the ISV Factory team:

- **Contact Email**: `isv-sales@digits.schwarz`
- **Documentation & Knowledge Base**: <LinkChip href="https://docs.stackit.cloud">docs.stackit.cloud</LinkChip>
- **Platform Status**: <LinkChip href="https://status.stackit.cloud/">status.stackit.cloud</LinkChip>
