Lifecycle Phases: Enterprise Governance & Engineering SDLC

Last Audited: 2026-08-14
Tier-2 Authoritative
In Plain Language

Software lifecycles in regulated industries operate on two complementary levels: an overarching 7-phase enterprise view for business and governance milestones, and a practical 6-phase engineering view for sprint-to-sprint software development. Neither view replaces the other. The 7-phase view guarantees business and regulatory alignment from initial strategy through post-market operations, while the 6-phase view gives software developers a clear sequence from requirements to deployment.

Understanding the Two Lifecycle Perspectives

When teams build software in regulated environments, misunderstandings often arise because executives and software engineers use the word "phase" to mean different things. In NUP, this is resolved by explicitly maintaining two aligned lifecycle models:

  • The 7-Phase Enterprise Lifecycle: Focuses on governance, business feasibility, risk baselining, and post-market clinical/operational surveillance (Strategy, Envision, Inception, Elaboration, Construction, Transition, Production).
  • The 6-Phase Engineering SDLC: Focuses on developer workflows, system design, automated test execution, continuous integration, and deployments (Discovery, Design, Development, Verification, Deployment, Maintenance).

Lifecycle Alignment Architecture

The diagram below demonstrates how the 6 engineering SDLC phases map cleanly into the 7 enterprise governance phases:

Dual Lifecycle Alignment: 7 Enterprise Phases vs. 6 Engineering SDLC PhasesVisual bridge showing how the 6 engineering development phases map within the 7 extended enterprise governance phases of the Deterministic NUP framework.Dual Lifecycle Alignment FrameworkBridging Extended Enterprise Governance (7-Phase) with Engineering Execution (6-Phase)7 ENTERPRISE PHASES (Governance View)1. StrategyBusiness/ROI2. EnvisionBusiness/ROI3. InceptionScope/Arch4. ElaborationScope/Arch5. ConstructionBuild/Sprint6. TransitionDeploy/Ops7. ProductionDeploy/Ops▼ Core Engineering Execution Alignment ▼6 SDLC PHASES (Engineering View)1. DiscoveryUser Needs2. DesignSpec & ADR3. DevelopmentCode & UT4. VerificationTest & V&V5. DeploymentCI/CD Gate6. MaintenanceMonitoring
Figure 2: Dual Lifecycle Alignment — Enterprise 7-Phase Strategic Governance mapped to Engineering 6-Phase Execution.

Comprehensive Phase-to-Phase Mapping Matrix

Enterprise PhaseEngineering SDLC MappingPrimary Focus & PurposeKey Deliverables
1. StrategyPre-SDLC (Portfolio Planning)Define enterprise business objectives, market fit, and organizational readiness for regulatory compliance.Market Analysis, Regulatory Feasibility Assessment, ROI Model
2. EnvisionDiscovery PhaseEstablish product vision, primary user personas, core system boundaries, and initial risk thresholds.Product Vision Document, User Journey Maps, High-Level Regulatory Classification
3. InceptionDiscovery & Design PhasesAlign stakeholders on scope, initial requirements, technical architecture feasibility, and resource commitments.Initial Software Requirements Specification (SRS), Architecture Spike, Initial Risk Plan
4. ElaborationDesign & Verification PlanningEliminate major architectural risks, establish baseline system architecture, and formalize detailed verification criteria.Executable Architecture Baseline, Formal ADRs, Master Verification & Validation (V&V) Plan
5. ConstructionDevelopment & Automated Verification PhasesIteratively develop, unit test, and integrate software components with continuous compliance evidence generation.Tested Production Code, Automated Test Suites, Code Review Records, Continuous SBOM
6. TransitionDeployment PhasePerform formal design validation, user acceptance testing, regulatory submission assembly, and production deployment.Design History File (DHF), Validation Summary Report, Release Package, Deployment Verification Sign-off
7. ProductionMaintenance PhaseMaintain operational reliability, monitor real-world security telemetry, manage post-market surveillance, and handle incidents.Audit Logs, Incident Post-Mortems, Post-Market Clinical Follow-up (PMCF) Records, Periodic Safety Reports
Analyze Phase Milestones with AI

Use this prompt to audit your current project phase deliverables against ISO 13485 design control gates.

Act as a senior medical device software compliance auditor. Review the following project phase deliverables: - Current Phase: [e.g., Elaboration / Design] - Completed Artifacts: [e.g., Architecture Decision Records, Threat Model, Verification Plan] Evaluate whether these deliverables satisfy ISO 13485:2016 Clause 7.3.2 (Planning) and IEC 62304:2015 Clause 5.1 requirements. Identify any missing audit evidence before phase gate sign-off.

Community Discussion & Feedback

Attributed peer feedback and official Netspective architecture notes.

Was this documentation helpful?(100% found this helpful • 0 ratings)

Leave Feedback or Question

○ Loading user info...
0/2000 chars

Discussion (0)

Loading discussion thread...