SpecMCP
Use SpecMCP

Understand severity and verification types

Interpret requirement priority and certification evidence correctly.

SpecMCP normalizes gematik's RFC 2119 language into a fixed set of severities:

ValueMeaning
mustMandatory; non-compliance is a certification failure.
must_notExplicitly prohibited.
should / should_notStrong recommendation; a deviation needs justification.
mayOptional.
not_definedNo severity was stated in the source.

Certification scopes also state how compliance must be proven. Product scopes may require a product test, manufacturer declaration, security audit, or product audit. Provider scopes may require process or document review, an operations manual, or a provider declaration.

Severity tells you how strongly a requirement is expressed. Verification type tells you what evidence is expected to prove it. Keep both in your planning and traceability records.