Lifecycle Phases: Enterprise Governance & Engineering SDLC
Software lifecycles in regulated industries operate on two complementary levels: an overarching 7-phase enterprise view for business and governance milestones, and a practical 6-phase engineering view for sprint-to-sprint software development. Neither view replaces the other. The 7-phase view guarantees business and regulatory alignment from initial strategy through post-market operations, while the 6-phase view gives software developers a clear sequence from requirements to deployment.
Understanding the Two Lifecycle Perspectives
When teams build software in regulated environments, misunderstandings often arise because executives and software engineers use the word "phase" to mean different things. In NUP, this is resolved by explicitly maintaining two aligned lifecycle models:
- The 7-Phase Enterprise Lifecycle: Focuses on governance, business feasibility, risk baselining, and post-market clinical/operational surveillance (Strategy, Envision, Inception, Elaboration, Construction, Transition, Production).
- The 6-Phase Engineering SDLC: Focuses on developer workflows, system design, automated test execution, continuous integration, and deployments (Discovery, Design, Development, Verification, Deployment, Maintenance).
Lifecycle Alignment Architecture
The diagram below demonstrates how the 6 engineering SDLC phases map cleanly into the 7 enterprise governance phases:
Comprehensive Phase-to-Phase Mapping Matrix
| Enterprise Phase | Engineering SDLC Mapping | Primary Focus & Purpose | Key Deliverables |
|---|---|---|---|
| 1. Strategy | Pre-SDLC (Portfolio Planning) | Define enterprise business objectives, market fit, and organizational readiness for regulatory compliance. | Market Analysis, Regulatory Feasibility Assessment, ROI Model |
| 2. Envision | Discovery Phase | Establish product vision, primary user personas, core system boundaries, and initial risk thresholds. | Product Vision Document, User Journey Maps, High-Level Regulatory Classification |
| 3. Inception | Discovery & Design Phases | Align stakeholders on scope, initial requirements, technical architecture feasibility, and resource commitments. | Initial Software Requirements Specification (SRS), Architecture Spike, Initial Risk Plan |
| 4. Elaboration | Design & Verification Planning | Eliminate major architectural risks, establish baseline system architecture, and formalize detailed verification criteria. | Executable Architecture Baseline, Formal ADRs, Master Verification & Validation (V&V) Plan |
| 5. Construction | Development & Automated Verification Phases | Iteratively develop, unit test, and integrate software components with continuous compliance evidence generation. | Tested Production Code, Automated Test Suites, Code Review Records, Continuous SBOM |
| 6. Transition | Deployment Phase | Perform formal design validation, user acceptance testing, regulatory submission assembly, and production deployment. | Design History File (DHF), Validation Summary Report, Release Package, Deployment Verification Sign-off |
| 7. Production | Maintenance Phase | Maintain operational reliability, monitor real-world security telemetry, manage post-market surveillance, and handle incidents. | Audit Logs, Incident Post-Mortems, Post-Market Clinical Follow-up (PMCF) Records, Periodic Safety Reports |
Use this prompt to audit your current project phase deliverables against ISO 13485 design control gates.
Community Discussion & Feedback
Attributed peer feedback and official Netspective architecture notes.