01Provider and owner
Which mission systems could provide data, and which named organizations and individuals control access, release, quality, and operational use?
02Meaning and lineage
Are semantics, provenance, transformations, freshness, quality, limitations, and counter-evidence documented well enough for later SME validation?
03Boundary and handling
Where may data be stored, moved, processed, combined, retrieved, or used for evaluation? Which impact, privacy, classification, export, or licensing constraints apply?
04Interface and operations
Do interfaces, identity, service levels, observability, continuity, change ownership, and incident paths support repeatable access rather than a one-time extract?
05Strategic data intent
Is a data mesh, fabric, catalog, exchange, product, or domain-ownership strategy merely proposed, actively piloted, or demonstrably operational?
06AI-specific unknowns
What evaluation sets, retrieval constraints, contamination risks, feedback paths, named-person review points, and post-deployment monitoring questions remain unresolved?
cMAP may identify candidate data providers and due-diligence questions. It does not designate an authoritative source, approve a data mesh, or replace data owners and data SMEs.