Open Points & Customer Clarifications

Prioritize customer clarifications, decision dependencies, and unresolved RFQ questions.

Last updated: 2026-06-25 12:57
RTRFQX Review TeamWorkspace

Open Points & Customer Clarifications

Prioritize customer clarifications, decision dependencies, and unresolved RFQ questions.

Open Points9total
High Priority6decide first
Medium Priority3next
Open9awaiting answer

Executive Takeaway

Open points are the customer-decision backlog for the ECA ECU proposal. They protect the baseline from silently accepting unclear diagnostics, update, PKI, secure communication, TARA, or CIA/RASIC responsibility assumptions.

  • High-priority items should be answered before agreement baseline.
  • Each open point states the customer decision needed, why it matters, the unresolved impact, and the recommended supplier position.

Customer Decision Status

9 open
Send to customer / capture decision

Open Point Decision Queue

OP-001: Confirm the exact ECU designation/variant and the agreed item definition and boundary used for the risk analysis (TARA).

Topic: ECU designation, variant and item definition for TARA | Owner: OEM / Customer | Status: Open | Related requirements: 9

Decision detail

Why it matters: The item definition fixes the scope of the whole cybersecurity case; without it, assets, goals and effort cannot be frozen.

Required decision: Confirm the exact ECU designation/variant and the agreed item definition and boundary used for the risk analysis (TARA).

Impact if unresolved: TARA scope and effort stay open; downstream assets, goals and design may rework.

High

OP-002: Confirm the diagnostic role model, the authorized services per role, and which party owns the diagnostic authorization policy.

Topic: Diagnostic security role model and service authorization | Owner: Shared (OEM policy / Supplier ECU) | Status: Open | Related requirements: 38

Decision detail

Why it matters: Diagnostic access is a primary attack surface; authorization scope drives security access design and verification effort.

Required decision: Confirm the diagnostic role model, the authorized services per role, and which party owns the diagnostic authorization policy.

Impact if unresolved: Security-access design and verification scope cannot be frozen; risk of an unprotected diagnostic service.

High

OP-003: Confirm ownership and provisioning flow for keys/certificates (generation, injection, storage, renewal, revocation) between OEM and supplier.

Topic: Key and certificate ownership, provisioning and lifecycle | Owner: OEM / Customer (PKI) + Supplier (ECU) | Status: Open | Related requirements: 19

Decision detail

Why it matters: Key lifecycle responsibility determines ECU storage requirements, provisioning interfaces and production-line dependencies.

Required decision: Confirm ownership and provisioning flow for keys/certificates (generation, injection, storage, renewal, revocation) between OEM and supplier.

Impact if unresolved: ECU secure-storage and provisioning design is blocked; production-line and PKI dependencies stay open.

High

OP-004: Confirm the update chain ownership (backend/campaign vs. ECU programming) and the authenticity/integrity scheme to be applied.

Topic: Secure software update / backend campaign responsibility | Owner: Shared (OEM backend / Supplier ECU) | Status: Open | Related requirements: 25

Decision detail

Why it matters: Update is a high-impact attack surface; the backend/ECU split decides which controls and evidence the supplier must deliver.

Required decision: Confirm the update chain ownership (backend/campaign vs. ECU programming) and the authenticity/integrity scheme to be applied.

Impact if unresolved: Update-control scope and evidence ownership stay open; risk of an unprotected update path.

High

OP-005: Confirm which signals/PDUs require SecOC/SDT, the freshness scheme, and the key distribution for protected communication.

Topic: Secure on-board communication (SecOC/SDT) signal allocation | Owner: OEM / Customer | Status: Open | Related requirements: 24

Decision detail

Why it matters: Communication protection allocation drives CAN matrix changes, key needs and runtime budget; it cannot be inferred safely.

Required decision: Confirm which signals/PDUs require SecOC/SDT, the freshness scheme, and the key distribution for protected communication.

Impact if unresolved: Protected-signal design, key needs and runtime budget stay open; risk of unprotected critical signals.

High

OP-009: Confirm the DIA / responsibility (RASIC/CIA) split for each cybersecurity work product before supplier scope is fixed.

Topic: Cybersecurity work products, DIA and responsibility split | Owner: OEM / Customer + Supplier (DIA) | Status: Open | Related requirements: 9

Decision detail

Why it matters: ISO 21434 work-product ownership must be agreed; otherwise the supplier may carry OEM-owned obligations or leave gaps.

Required decision: Confirm the DIA / responsibility (RASIC/CIA) split for each cybersecurity work product before supplier scope is fixed.

Impact if unresolved: Without an agreed DIA the supplier risks owning customer work products or leaving cybersecurity gaps in the case.

High

OP-006: Confirm the split of monitoring, triage, vulnerability handling and field response between OEM PSIRT and supplier.

Topic: Incident response and vulnerability management ownership | Owner: OEM / Customer (fleet) + Supplier (ECU) | Status: Open | Related requirements: 2

Decision detail

Why it matters: Post-SOP cybersecurity obligations (UNECE R155 / ISO 21434 clause 7) need a clear owner to bound lifecycle effort.

Required decision: Confirm the split of monitoring, triage, vulnerability handling and field response between OEM PSIRT and supplier.

Impact if unresolved: Lifecycle effort and field-response capability stay unbounded; risk of an R155 compliance gap.

Medium

OP-008: Confirm production/debug hardening expectations (debug lock, secure end-of-line, developer-access policy).

Topic: Production, development and debug-interface hardening | Owner: Shared (OEM process / Supplier ECU) | Status: Open | Related requirements: 5

Decision detail

Why it matters: Production and debug interfaces are a common attack surface; expectations drive hardware fusing and EOL process design.

Required decision: Confirm production/debug hardening expectations (debug lock, secure end-of-line, developer-access policy).

Impact if unresolved: Hardware fusing and EOL process design stay open; risk of an exposed debug/production interface.

Medium

OP-011: Confirm whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context for the ECA ECU baseline.

Topic: Document-specific scope and responsibility confirmation | Owner: OEM / Customer | Status: Open | Related requirements: 202

Decision detail

Why it matters: These requirements affect supplier proposal scope, traceability status, and effort assumptions but do not map cleanly to a predefined decision topic.

Required decision: Decide whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context.

Impact if unresolved: Supplier position, estimation, and affected design allocation remain conditional for the listed requirements.

Medium

Document Traceability

Open per-PDF document intelligence

Full Open Points Register

Open full register table
Open Point IDTopicQuestionRequired Customer DecisionImpactRecommended Supplier PositionOwnerStatusRelated Requirements
OP-001ECU designation, variant and item definition for TARAConfirm the exact ECU designation/variant and the agreed item definition and boundary used for the risk analysis (TARA).Confirm the exact ECU designation/variant and the agreed item definition and boundary used for the risk analysis (TARA).TARA scope and effort stay open; downstream assets, goals and design may rework.Proceed on the working ECA-ECU interpretation; flag every TARA-scope statement as assumption until confirmed.OEM / CustomerOpen9
OP-002Diagnostic security role model and service authorizationConfirm the diagnostic role model, the authorized services per role, and which party owns the diagnostic authorization policy.Confirm the diagnostic role model, the authorized services per role, and which party owns the diagnostic authorization policy.Security-access design and verification scope cannot be frozen; risk of an unprotected diagnostic service.Implement configurable session/security-access on the ECU and request the customer-confirmed service-to-role table.Shared (OEM policy / Supplier ECU)Open38
OP-003Key and certificate ownership, provisioning and lifecycleConfirm ownership and provisioning flow for keys/certificates (generation, injection, storage, renewal, revocation) between OEM and supplier.Confirm ownership and provisioning flow for keys/certificates (generation, injection, storage, renewal, revocation) between OEM and supplier.ECU secure-storage and provisioning design is blocked; production-line and PKI dependencies stay open.Provide ECU-side secure storage and provisioning hooks; require OEM confirmation of PKI ownership and the provisioning interface.OEM / Customer (PKI) + Supplier (ECU)Open19
OP-004Secure software update / backend campaign responsibilityConfirm the update chain ownership (backend/campaign vs. ECU programming) and the authenticity/integrity scheme to be applied.Confirm the update chain ownership (backend/campaign vs. ECU programming) and the authenticity/integrity scheme to be applied.Update-control scope and evidence ownership stay open; risk of an unprotected update path.Implement authenticated, integrity-protected ECU programming with controlled boot/app state; require OEM update-chain definition.Shared (OEM backend / Supplier ECU)Open25
OP-005Secure on-board communication (SecOC/SDT) signal allocationConfirm which signals/PDUs require SecOC/SDT, the freshness scheme, and the key distribution for protected communication.Confirm which signals/PDUs require SecOC/SDT, the freshness scheme, and the key distribution for protected communication.Protected-signal design, key needs and runtime budget stay open; risk of unprotected critical signals.Support SecOC/SDT in the platform and request the customer-confirmed protected-signal list and freshness policy.OEM / CustomerOpen24
OP-009Cybersecurity work products, DIA and responsibility splitConfirm the DIA / responsibility (RASIC/CIA) split for each cybersecurity work product before supplier scope is fixed.Confirm the DIA / responsibility (RASIC/CIA) split for each cybersecurity work product before supplier scope is fixed.Without an agreed DIA the supplier risks owning customer work products or leaving cybersecurity gaps in the case.Deliver supplier-owned work products per concept; require a signed DIA/RASIC before treating shared items as supplier scope.OEM / Customer + Supplier (DIA)Open9
OP-006Incident response and vulnerability management ownershipConfirm the split of monitoring, triage, vulnerability handling and field response between OEM PSIRT and supplier.Confirm the split of monitoring, triage, vulnerability handling and field response between OEM PSIRT and supplier.Lifecycle effort and field-response capability stay unbounded; risk of an R155 compliance gap.Define supplier vulnerability handling and field-fix capability; require OEM confirmation of monitoring/communication ownership.OEM / Customer (fleet) + Supplier (ECU)Open2
OP-008Production, development and debug-interface hardeningConfirm production/debug hardening expectations (debug lock, secure end-of-line, developer-access policy).Confirm production/debug hardening expectations (debug lock, secure end-of-line, developer-access policy).Hardware fusing and EOL process design stay open; risk of an exposed debug/production interface.Apply debug lock and secured production access; request the customer-confirmed production-security and EOL requirements.Shared (OEM process / Supplier ECU)Open5
OP-011Document-specific scope and responsibility confirmationConfirm whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context for the ECA ECU baseline.Decide whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context.Supplier position, estimation, and affected design allocation remain conditional for the listed requirements.Carry the items as customer-confirmation dependencies and review them in the next clarification workshop.OEM / CustomerOpen202

Open Point Detail

Open full decision detail
OP-001 - ECU designation, variant and item definition for TARA (High)

Question: Confirm the exact ECU designation/variant and the agreed item definition and boundary used for the risk analysis (TARA).

Why it matters: The item definition fixes the scope of the whole cybersecurity case; without it, assets, goals and effort cannot be frozen.

Required customer decision: Confirm the exact ECU designation/variant and the agreed item definition and boundary used for the risk analysis (TARA).

Impact if unresolved: TARA scope and effort stay open; downstream assets, goals and design may rework.

Recommended supplier position: Proceed on the working ECA-ECU interpretation; flag every TARA-scope statement as assumption until confirmed.

Closure reason: -

Closure source / evidence: - / -

Owner: OEM / Customer | Status: Open | Target: TBD

Related requirements: RFQX-1001379436-P10-000-01-0003;RFQX-3299216-1-0008;RFQX-3299216-1-0009;RFQX-3299216-1-0015;RFQX-CVS123-2-0019;RFQX-CVS123-2-0274;RFQX-CVS124-0246;RFQX-CVS124-0382;RFQX-CVS154-0026

OP-002 - Diagnostic security role model and service authorization (High)

Question: Confirm the diagnostic role model, the authorized services per role, and which party owns the diagnostic authorization policy.

Why it matters: Diagnostic access is a primary attack surface; authorization scope drives security access design and verification effort.

Required customer decision: Confirm the diagnostic role model, the authorized services per role, and which party owns the diagnostic authorization policy.

Impact if unresolved: Security-access design and verification scope cannot be frozen; risk of an unprotected diagnostic service.

Recommended supplier position: Implement configurable session/security-access on the ECU and request the customer-confirmed service-to-role table.

Closure reason: -

Closure source / evidence: - / -

Owner: Shared (OEM policy / Supplier ECU) | Status: Open | Target: TBD

Related requirements: RFQX-CVS123-2-0023;RFQX-CVS123-2-0034;RFQX-CVS123-2-0047;RFQX-CVS123-2-0078;RFQX-CVS123-2-0079;RFQX-CVS123-2-0166;RFQX-CVS123-2-0187;RFQX-CVS123-2-0242;RFQX-CVS123-2-0244;RFQX-CVS123-2-0286;RFQX-CVS123-2-0303;RFQX-CVS124-0014;RFQX-CVS124-0171;RFQX-CVS124-0306;RFQX-CVS124-0431;RFQX-CVS151-0004;RFQX-CVS151-0037;RFQX-CVS151-0041;RFQX-CVS151-0045;RFQX-CVS151-0049;RFQX-CVS151-0054;RFQX-CVS151-0058;RFQX-CVS151-0065;RFQX-CVS151-0066;RFQX-CVS151-0083;RFQX-CVS151-0085;RFQX-CVS151-0086;RFQX-CVS151-0088;RFQX-CVS31-0006;RFQX-CVS31-0014;RFQX-CVS31-0015;RFQX-CVS31-0017;RFQX-CVS31-0042;RFQX-CVS31-0111;RFQX-CVS31-0119;RFQX-CVS31-0143;RFQX-CVS32-0014;RFQX-CVS32-0016

OP-003 - Key and certificate ownership, provisioning and lifecycle (High)

Question: Confirm ownership and provisioning flow for keys/certificates (generation, injection, storage, renewal, revocation) between OEM and supplier.

Why it matters: Key lifecycle responsibility determines ECU storage requirements, provisioning interfaces and production-line dependencies.

Required customer decision: Confirm ownership and provisioning flow for keys/certificates (generation, injection, storage, renewal, revocation) between OEM and supplier.

Impact if unresolved: ECU secure-storage and provisioning design is blocked; production-line and PKI dependencies stay open.

Recommended supplier position: Provide ECU-side secure storage and provisioning hooks; require OEM confirmation of PKI ownership and the provisioning interface.

Closure reason: -

Closure source / evidence: - / -

Owner: OEM / Customer (PKI) + Supplier (ECU) | Status: Open | Target: TBD

Related requirements: RFQX-1001379436-P10-000-01-0041;RFQX-CVS151-0060;RFQX-CVS151-0091;RFQX-CVS31-0019;RFQX-CVS31-0021;RFQX-CVS31-0027;RFQX-CVS31-0028;RFQX-CVS31-0036;RFQX-CVS31-0037;RFQX-CVS31-0038;RFQX-CVS31-0075;RFQX-CVS31-0078;RFQX-CVS31-0080;RFQX-CVS31-0081;RFQX-CVS31-0083;RFQX-CVS31-0096;RFQX-CVS31-0099;RFQX-CVS31-0106;RFQX-CVS31-0156

OP-004 - Secure software update / backend campaign responsibility (High)

Question: Confirm the update chain ownership (backend/campaign vs. ECU programming) and the authenticity/integrity scheme to be applied.

Why it matters: Update is a high-impact attack surface; the backend/ECU split decides which controls and evidence the supplier must deliver.

Required customer decision: Confirm the update chain ownership (backend/campaign vs. ECU programming) and the authenticity/integrity scheme to be applied.

Impact if unresolved: Update-control scope and evidence ownership stay open; risk of an unprotected update path.

Recommended supplier position: Implement authenticated, integrity-protected ECU programming with controlled boot/app state; require OEM update-chain definition.

Closure reason: -

Closure source / evidence: - / -

Owner: Shared (OEM backend / Supplier ECU) | Status: Open | Target: TBD

Related requirements: RFQX-3299216-1-0041;RFQX-3299216-1-0176;RFQX-CVS123-2-0030;RFQX-CVS123-2-0042;RFQX-CVS123-2-0050;RFQX-CVS123-2-0055;RFQX-CVS123-2-0070;RFQX-CVS123-2-0071;RFQX-CVS123-2-0188;RFQX-CVS123-2-0197;RFQX-CVS123-2-0199;RFQX-CVS123-2-0206;RFQX-CVS123-2-0349;RFQX-CVS124-0141;RFQX-CVS124-0142;RFQX-CVS124-0185;RFQX-CVS124-0248;RFQX-CVS124-0340;RFQX-CVS124-0389;RFQX-CVS124-0397;RFQX-CVS31-0060;RFQX-CVS31-0062;RFQX-CVS31-0063;RFQX-CVS31-0070;RFQX-CVS32-0007

OP-005 - Secure on-board communication (SecOC/SDT) signal allocation (High)

Question: Confirm which signals/PDUs require SecOC/SDT, the freshness scheme, and the key distribution for protected communication.

Why it matters: Communication protection allocation drives CAN matrix changes, key needs and runtime budget; it cannot be inferred safely.

Required customer decision: Confirm which signals/PDUs require SecOC/SDT, the freshness scheme, and the key distribution for protected communication.

Impact if unresolved: Protected-signal design, key needs and runtime budget stay open; risk of unprotected critical signals.

Recommended supplier position: Support SecOC/SDT in the platform and request the customer-confirmed protected-signal list and freshness policy.

Closure reason: -

Closure source / evidence: - / -

Owner: OEM / Customer | Status: Open | Target: TBD

Related requirements: RFQX-CVS32-0019;RFQX-CVS32-0027;RFQX-CVS32-0028;RFQX-CVS32-0031;RFQX-CVS32-0048;RFQX-CVS32-0051;RFQX-CVS32-0054;RFQX-CVS32-0080;RFQX-CVS32-0082;RFQX-CVS32-0106;RFQX-CVS32-0108;RFQX-CVS32-0120;RFQX-CVS32-0121;RFQX-CVS32-0122;RFQX-CVS32-0123;RFQX-CVS32-0124;RFQX-CVS32-0125;RFQX-CVS32-0126;RFQX-CVS32-0128;RFQX-CVS32-0130;RFQX-CVS32-0131;RFQX-CVS32-0133;RFQX-CVS32-0147;RFQX-CVS32-0151

OP-009 - Cybersecurity work products, DIA and responsibility split (High)

Question: Confirm the DIA / responsibility (RASIC/CIA) split for each cybersecurity work product before supplier scope is fixed.

Why it matters: ISO 21434 work-product ownership must be agreed; otherwise the supplier may carry OEM-owned obligations or leave gaps.

Required customer decision: Confirm the DIA / responsibility (RASIC/CIA) split for each cybersecurity work product before supplier scope is fixed.

Impact if unresolved: Without an agreed DIA the supplier risks owning customer work products or leaving cybersecurity gaps in the case.

Recommended supplier position: Deliver supplier-owned work products per concept; require a signed DIA/RASIC before treating shared items as supplier scope.

Closure reason: -

Closure source / evidence: - / -

Owner: OEM / Customer + Supplier (DIA) | Status: Open | Target: TBD

Related requirements: RFQX-3299216-1-0306;RFQX-CVS123-2-0002;RFQX-CVS124-0003;RFQX-CVS124-0088;RFQX-CVS124-0328;RFQX-CVS151-0002;RFQX-CVS154-0002;RFQX-CVS31-0003;RFQX-CVS32-0003

OP-006 - Incident response and vulnerability management ownership (Medium)

Question: Confirm the split of monitoring, triage, vulnerability handling and field response between OEM PSIRT and supplier.

Why it matters: Post-SOP cybersecurity obligations (UNECE R155 / ISO 21434 clause 7) need a clear owner to bound lifecycle effort.

Required customer decision: Confirm the split of monitoring, triage, vulnerability handling and field response between OEM PSIRT and supplier.

Impact if unresolved: Lifecycle effort and field-response capability stay unbounded; risk of an R155 compliance gap.

Recommended supplier position: Define supplier vulnerability handling and field-fix capability; require OEM confirmation of monitoring/communication ownership.

Closure reason: -

Closure source / evidence: - / -

Owner: OEM / Customer (fleet) + Supplier (ECU) | Status: Open | Target: TBD

Related requirements: RFQX-1001379436-P10-000-01-0054;RFQX-1001379436-P10-000-01-0056

OP-008 - Production, development and debug-interface hardening (Medium)

Question: Confirm production/debug hardening expectations (debug lock, secure end-of-line, developer-access policy).

Why it matters: Production and debug interfaces are a common attack surface; expectations drive hardware fusing and EOL process design.

Required customer decision: Confirm production/debug hardening expectations (debug lock, secure end-of-line, developer-access policy).

Impact if unresolved: Hardware fusing and EOL process design stay open; risk of an exposed debug/production interface.

Recommended supplier position: Apply debug lock and secured production access; request the customer-confirmed production-security and EOL requirements.

Closure reason: -

Closure source / evidence: - / -

Owner: Shared (OEM process / Supplier ECU) | Status: Open | Target: TBD

Related requirements: RFQX-1001379436-P10-000-01-0036;RFQX-3299216-1-0011;RFQX-3299216-1-0090;RFQX-3299216-1-0091;RFQX-CVS123-2-0061

OP-011 - Document-specific scope and responsibility confirmation (Medium)

Question: Confirm whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context for the ECA ECU baseline.

Why it matters: These requirements affect supplier proposal scope, traceability status, and effort assumptions but do not map cleanly to a predefined decision topic.

Required customer decision: Decide whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context.

Impact if unresolved: Supplier position, estimation, and affected design allocation remain conditional for the listed requirements.

Recommended supplier position: Carry the items as customer-confirmation dependencies and review them in the next clarification workshop.

Closure reason: -

Closure source / evidence: - / -

Owner: OEM / Customer | Status: Open | Target: TBD

Related requirements: RFQX-1001379436-P10-000-01-0009;RFQX-1001379436-P10-000-01-0010;RFQX-1001379436-P10-000-01-0011;RFQX-1001379436-P10-000-01-0014;RFQX-1001379436-P10-000-01-0016;RFQX-1001379436-P10-000-01-0026;RFQX-1001379436-P10-000-01-0033;RFQX-1001379436-P10-000-01-0035;RFQX-1001379436-P10-000-01-0052;RFQX-1001379436-P10-000-01-0053;RFQX-1001379436-P10-000-01-0057;RFQX-1001379436-P10-000-01-0064;RFQX-1001379436-P10-000-01-0065;RFQX-1001379436-P10-000-01-0066;RFQX-3299216-1-0001;RFQX-3299216-1-0010;RFQX-3299216-1-0016;RFQX-3299216-1-0017;RFQX-3299216-1-0018;RFQX-3299216-1-0028;RFQX-3299216-1-0037;RFQX-3299216-1-0038;RFQX-3299216-1-0044;RFQX-3299216-1-0045;RFQX-3299216-1-0050;RFQX-3299216-1-0051;RFQX-3299216-1-0054;RFQX-3299216-1-0056;RFQX-3299216-1-0063;RFQX-3299216-1-0064;RFQX-3299216-1-0065;RFQX-3299216-1-0066;RFQX-3299216-1-0067;RFQX-3299216-1-0068;RFQX-3299216-1-0072;RFQX-3299216-1-0073;RFQX-3299216-1-0076;RFQX-3299216-1-0077;RFQX-3299216-1-0078;RFQX-3299216-1-0081;RFQX-3299216-1-0082;RFQX-3299216-1-0085;RFQX-3299216-1-0086;RFQX-3299216-1-0087;RFQX-3299216-1-0092;RFQX-3299216-1-0093;RFQX-3299216-1-0094;RFQX-3299216-1-0096;RFQX-3299216-1-0097;RFQX-3299216-1-0106;RFQX-3299216-1-0109;RFQX-3299216-1-0117;RFQX-3299216-1-0118;RFQX-3299216-1-0131;RFQX-3299216-1-0132;RFQX-3299216-1-0140;RFQX-3299216-1-0142;RFQX-3299216-1-0148;RFQX-3299216-1-0149;RFQX-3299216-1-0150;RFQX-3299216-1-0160;RFQX-3299216-1-0161;RFQX-3299216-1-0162;RFQX-3299216-1-0163;RFQX-3299216-1-0164;RFQX-3299216-1-0165;RFQX-3299216-1-0166;RFQX-3299216-1-0167;RFQX-3299216-1-0168;RFQX-3299216-1-0169;RFQX-3299216-1-0170;RFQX-3299216-1-0174;RFQX-3299216-1-0175;RFQX-3299216-1-0179;RFQX-3299216-1-0180;RFQX-3299216-1-0182;RFQX-3299216-1-0183;RFQX-3299216-1-0184;RFQX-3299216-1-0185;RFQX-3299216-1-0186;RFQX-3299216-1-0187;RFQX-3299216-1-0188;RFQX-3299216-1-0189;RFQX-3299216-1-0190;RFQX-3299216-1-0191;RFQX-3299216-1-0192;RFQX-3299216-1-0193;RFQX-3299216-1-0194;RFQX-3299216-1-0195;RFQX-3299216-1-0196;RFQX-3299216-1-0202;RFQX-3299216-1-0203;RFQX-3299216-1-0204;RFQX-3299216-1-0205;RFQX-3299216-1-0206;RFQX-3299216-1-0209;RFQX-3299216-1-0210;RFQX-3299216-1-0211;RFQX-3299216-1-0212;RFQX-3299216-1-0215;RFQX-3299216-1-0216;RFQX-3299216-1-0217;RFQX-3299216-1-0219;RFQX-3299216-1-0220;RFQX-3299216-1-0221;RFQX-3299216-1-0256;RFQX-3299216-1-0279;RFQX-3299216-1-0280;RFQX-3299216-1-0281;RFQX-3299216-1-0282;RFQX-3299216-1-0283;RFQX-3299216-1-0286;RFQX-3299216-1-0287;RFQX-3299216-1-0288;RFQX-3299216-1-0289;RFQX-3299216-1-0290;RFQX-3299216-1-0291;RFQX-3299216-1-0292;RFQX-3299216-1-0293;RFQX-3299216-1-0294;RFQX-3299216-1-0295;RFQX-3299216-1-0296;RFQX-3299216-1-0297;RFQX-3299216-1-0298;RFQX-3299216-1-0299;RFQX-3299216-1-0300;RFQX-3299216-1-0302;RFQX-CVS123-2-0003;RFQX-CVS123-2-0014;RFQX-CVS123-2-0020;RFQX-CVS123-2-0021;RFQX-CVS123-2-0022;RFQX-CVS123-2-0024;RFQX-CVS123-2-0029;RFQX-CVS123-2-0035;RFQX-CVS123-2-0040;RFQX-CVS123-2-0041;RFQX-CVS123-2-0053;RFQX-CVS123-2-0069;RFQX-CVS123-2-0075;RFQX-CVS123-2-0153;RFQX-CVS123-2-0182;RFQX-CVS123-2-0183;RFQX-CVS123-2-0189;RFQX-CVS123-2-0322;RFQX-CVS123-2-0343;RFQX-CVS123-2-0351;RFQX-CVS124-0001;RFQX-CVS124-0004;RFQX-CVS124-0005;RFQX-CVS124-0007;RFQX-CVS124-0008;RFQX-CVS124-0011;RFQX-CVS124-0012;RFQX-CVS124-0013;RFQX-CVS124-0016;RFQX-CVS124-0017;RFQX-CVS124-0039;RFQX-CVS124-0138;RFQX-CVS124-0158;RFQX-CVS124-0159;RFQX-CVS124-0169;RFQX-CVS124-0212;RFQX-CVS124-0237;RFQX-CVS124-0239;RFQX-CVS124-0241;RFQX-CVS124-0245;RFQX-CVS124-0247;RFQX-CVS124-0249;RFQX-CVS124-0265;RFQX-CVS124-0316;RFQX-CVS124-0317;RFQX-CVS124-0318;RFQX-CVS124-0319;RFQX-CVS124-0320;RFQX-CVS124-0331;RFQX-CVS124-0347;RFQX-CVS124-0375;RFQX-CVS124-0377;RFQX-CVS151-0003;RFQX-CVS151-0036;RFQX-CVS151-0092;RFQX-CVS151-0093;RFQX-CVS151-0094;RFQX-CVS154-0003;RFQX-CVS154-0004;RFQX-CVS154-0025;RFQX-CVS154-0032;RFQX-CVS154-0035;RFQX-CVS154-0047;RFQX-CVS31-0001;RFQX-CVS31-0004;RFQX-CVS31-0005;RFQX-CVS31-0007;RFQX-CVS31-0008;RFQX-CVS31-0009;RFQX-CVS31-0010;RFQX-CVS31-0049;RFQX-CVS32-0001;RFQX-CVS32-0004;RFQX-CVS32-0008;RFQX-CVS32-0020