SPDF Control Mapping for FDA Premarket Cybersecurity Submissions — answering "who verifies the verifier" after Anthropic's Agentic Misalignment (Summer 2026) findings, grounded in algorithmic-auditing literature on auditor independence (FAccT '22; Kim et al. 2026).
Amp is used as an evidence-generation and orchestration layer for FDA SBOM/VEX and process-specific submissions — Static Code Analysis, Unit Testing, Code Coverage, and Penetration Testing — such that no single AI verdict is load-bearing and every compliance claim has deterministic, cross-vendor, and human sign-off.
The single-picture summary: work flows through five layers; verdict authority increases upward.
Open →Five Anthropic-derived threats plus process-specific cover-up vectors, framed against FDA/NIST expectations.
Open →L0–L4: deterministic checks, cross-vendor oracle, named human judge, immutable evidence.
Open →Thirteen audit-ready controls, each with what it controls, implementation, evidence artifact, and auditor re-check.
Open →Centered on Parasoft C/C++test. Turns the suppression surface itself into evidence — rule-pack hash, scope, baseline delta, suppression diff, signed register.
Open →13 controls × 9 threats. Every threat has ≥2 controls; no threat relies on a single control.
Open →How the 5 layers redistribute per process — including the Static-Analysis Evidence Shape (§9.4).
Open →Honest caveats and the full reference list — FDA, IEC, NIST, Anthropic, FAccT '22, Kim et al. 2026, Parasoft.
Open →