ijaers social
facebook
twitter
Blogger
google plus

International Journal of Advanced Engineering, Management and Science


C3P: A Continuous Compliance Control Protocol for Regulated Software Delivery

( Vol-12,Issue-3,May - June 2026 )

Author(s): Paul Gresham


Download Full Text PDF
Total View : 77
Downloads : 4
Page No: 245-253
ijaems crossref doiDOI: 10.22161/ijaems.123.22

Keywords:

audit governance, CI/CD, continuous compliance, design science research, regulated software engineering, traceability

Abstract:

This paper presents C3P (Continuous Compliance Control Protocol), a design-science research contribution that establishes end-to-end traceability, integrity, and provenance across the full software delivery lifecycle in highly regulated environments. The framework addresses a structural conflict inherent in modern software engineering: CI/CD pipelines optimize for speed and automation, while traditional compliance models — maker-checker controls, four-eyes approvals, point-in-time attestations — assume slow, sequential delivery. This conflict produces three endemic failure modes: traceability gaps, integrity gaps, and evidence gaps. C3P resolves this by embedding compliance directly into the delivery pipeline as a continuous, verifiable output, introducing the concept of CI/CD/CC (Continuous Integration / Continuous Delivery / Continuous Compliance). The paper describes the framework’s minimum artifact graph, control-plane separation model, evidence pack mechanism, and policy-as-code gate architecture. A working reference implementation built on widely available platform tooling demonstrates the framework’s feasibility. The framework is informed by the author’s decades of practitioner experience delivering software in globally regulated financial institutions, where precursor frameworks of this design were endorsed by independent internal audit functions and adopted at enterprise scale.

Article Info:

Received: 29 Apr 2026; Received in revised form: 26 May 2026; Accepted: 29 May 2026; Available online: 05 Jun 2026

Cite This Article:
Citations:
APA | ACM | Chicago | Harvard | IEEE | MLA | Vancouver | Bibtex
Share: