---
date: 2027-06-20
topic: MVAP v1.2 Adoption Vote
session_type: deliberation
moderator: Arthur Vance
court_reporter: Eleanor Vance
rounds: 2
updates: mvap/MVAP-SPECIFICATION-v1.2-DRAFT.md
---

# MVAP v1.2 Adoption — 2027-06-20

**Arthur Vance:** Final vote on v1.2 controls following P7-05 tabletop and Q1 government risk review.

---

## Round 1 — Control Votes

| Control | Vote | Result |
|---------|------|--------|
| P7-09 Transitive SBOM | 17/27 | Conditional — tier-1 mandatory Q3 2027 |
| P7-10 KEV 4h/24h SLA | 19/27 | **ADOPTED** |
| P7-11 AI gateway hardening | 21/27 | **ADOPTED** |
| P6 tier-1 + tier-2 firmware | 18/27 | **ADOPTED** |
| P2-08 membership inference | 16/27 | Deferred v1.2.1 |
| SLSA L3 tier-1 | 16/27 | Deferred v1.3 |

**Kira:** P7-10 closes the LiteLLM exploitation window — 4 hours is aggressive but necessary given sub-36h weaponization.

**Oliver Hansen:** P7-09 conditional is correct; full tree SBOM on every npm transitive dep is noisy without tiering.

**Maya Patel:** P7-11b Starlette >=1.0.1 is non-negotiable after BadHost chain.

**NullByte:** SLSA L3 deferred again — dissent recorded for v1.3.

---

## Round 2 — Ratification

**Vote:** MVAP v1.2 adopted **20/27**.

**Eleanor Vance:** Specification status updated. Cross-reference `output/Cyber-Security-AI-Diligence-Research-Study.md` Chapter 3.4.

**Marcus Thorne:** Quarterly government re-attestation now includes P7-10 SLA evidence and P7-11 gateway audit logs.

---

**Formal ballot with dissent rationale:** See `sessions/VOTE-RECORD.md` — MVAP v1.2 Control Votes and ratification (20/27).