Use SpecMCP
Understand severity and verification types
Interpret requirement priority and certification evidence correctly.
SpecMCP normalizes gematik's RFC 2119 language into a fixed set of severities:
| Value | Meaning |
|---|---|
must | Mandatory; non-compliance is a certification failure. |
must_not | Explicitly prohibited. |
should / should_not | Strong recommendation; a deviation needs justification. |
may | Optional. |
not_defined | No severity was stated in the source. |
Certification scopes also state how compliance must be proven. Product scopes may require a product test, manufacturer declaration, security audit, or product audit. Provider scopes may require process or document review, an operations manual, or a provider declaration.
Severity tells you how strongly a requirement is expressed. Verification type tells you what evidence is expected to prove it. Keep both in your planning and traceability records.