# Evidentiary Sufficiency Gate

- **Artifact ID:** CHQ-D-2026-ESG
- **Version:** v1.0
- **Status:** ACTIVE
- **Public record:** https://record.cybersecurityhq.com/doctrine/chq-d-2026-esg
- **Machine-record SHA-256:** `06f357a68e38b6da38e48f537db3363905cbbeb74e1b9cb3ebf3cc358c058405`

## Complete structured record

```json
{
  "id": "CHQ-D-2026-ESG",
  "title": "Evidentiary Sufficiency Gate",
  "version": "v1.0",
  "issued": "2026-01-31",
  "status": "ACTIVE",
  "doctrine_class": "EVIDENCE_RULE",
  "doctrine_scope": "POSITIONS",
  "governed_artifacts": [
    "ACJ",
    "Positions",
    "Judgments"
  ],
  "related_doctrine": [
    "CHQ-D-2026-PIG",
    "CHQ-D-2026-PIG-APP"
  ],
  "purpose": "This document establishes the evidentiary standard that must be satisfied before CHQ issues authority-bearing artifacts. The Evidentiary Sufficiency Gate ensures that Judgments, Positions, and ACJs are grounded in observable structural conditions, not editorial conviction or pattern speculation.",
  "sections": [
    {
      "heading": "SCOPE",
      "content": [
        "This requirement applies to all CHQ artifacts that carry institutional authority:",
        "• Authoritative Canonical Judgments (ACJs)",
        "• Positions of Record",
        "• Judgments of Record",
        "",
        "It does not apply to Memos, Exhibits, Assumptions, Pressure Records, Signal Notes, or Weekly Briefs. These artifact classes operate under their own behavioral constraints and do not require ESG passage."
      ],
      "type": "paragraph"
    },
    {
      "heading": "DEFINITION OF EVIDENTIARY SUFFICIENCY",
      "content": [
        "An artifact satisfies the Evidentiary Sufficiency Gate when:",
        "• The structural condition it identifies is observable across at least two independent domains, sectors, or enforcement regimes.",
        "• The condition is not attributable to a single vendor failure, isolated incident, or transient operational event.",
        "• The evidentiary basis can be stated without causal claims, predictive assertions, or evaluative language about specific organizations.",
        "• The condition would be recognizable to an informed external reviewer without access to CHQ's internal analysis history.",
        "",
        "Evidentiary sufficiency does not require:",
        "• Consensus among industry participants.",
        "• Regulatory acknowledgment or enforcement action.",
        "• Quantitative thresholds or statistical measures.",
        "• Peer review or external validation."
      ],
      "type": "paragraph"
    },
    {
      "heading": "PASSAGE REQUIREMENTS",
      "content": [
        "Before an authority-bearing artifact may be issued, the following must be confirmed:",
        "",
        "1. Structural Observability. The condition is documented in at least two CHQ Pressure Records, Signal Notes, or Exhibits that independently surface the same structural pattern.",
        "",
        "2. Cross-Domain Recurrence. The condition has manifested across more than one technology domain, organizational type, or governance regime. A pattern observed only within a single vendor ecosystem, regulatory jurisdiction, or technology stack does not satisfy ESG.",
        "",
        "3. Temporal Persistence. The condition has persisted across at least two distinct observation windows. A pattern that appears and resolves within a single reporting cycle does not constitute a structural condition.",
        "",
        "4. Adversarial Coherence. The structural claim survives the adversarial paragraph test: a plausible alternative explanation using only operational language (vendor error, misconfiguration, delayed patching, resource constraints) must fail to fully account for the observed pattern. If the alternative explanation remains coherent, the artifact does not pass ESG."
      ],
      "type": "paragraph"
    },
    {
      "heading": "GRANDFATHERING",
      "content": [
        "Artifacts issued before the ESG ratification date (January 31, 2026) are classified as ESG: GRANDFATHERED. These artifacts are not retroactively subject to ESG requirements. They retain their classification and authority status as of their original issuance date.",
        "Grandfathered artifacts may not be amended or versioned under ESG. Any material update to a grandfathered artifact requires re-issuance as a new artifact subject to current ESG requirements."
      ],
      "type": "paragraph"
    },
    {
      "heading": "RELATIONSHIP TO OTHER DOCTRINE",
      "content": [
        "The Evidentiary Sufficiency Gate is the foundational issuance standard. Other doctrine documents layer additional requirements on top of ESG:",
        "• CHQ-D-2026-PIG (Position Issuance Gate) adds external authority tests specific to Position issuance.",
        "• CHQ-D-2026-PIG-APP (Adversarial Paragraph Protocol) operationalizes the adversarial coherence test required under ESG Passage Requirement 4.",
        "",
        "An artifact that passes PIG has necessarily passed ESG. An artifact that passes ESG has not necessarily passed PIG."
      ],
      "type": "paragraph"
    },
    {
      "heading": "ENFORCEMENT",
      "content": [
        "CHQ does not issue authority-bearing artifacts that have not passed ESG. If an artifact is later determined to have been issued without satisfying ESG requirements, it is subject to immediate review and potential reclassification as an Analytical Research Memo (ANRM) or retirement.",
        "The ESG determination is made at issuance and recorded as part of the artifact's internal governance metadata. ESG passage is not displayed on the public artifact but is available upon request for reliance registration purposes."
      ],
      "type": "paragraph"
    },
    {
      "heading": "GOVERNANCE",
      "content": [
        "This doctrine document is maintained by CHQ editorial governance.",
        "Amendments require version increment and explicit changelog.",
        "This document does not expire. It remains in force until superseded."
      ],
      "type": "paragraph"
    }
  ]
}
```
