SKIP TO CONTENT
TOOL 04 / RULE 702

Daubert Exposure Check

Twelve questions about a digital forensic methodology, each mapped to one of the six failure modes that account for most exclusions in this field. Answer them against the report in front of you and the check returns the gaps, the remediation for each, and nothing that pretends to be a prediction.

QUESTIONS
12, in a fixed order
FAILURE MODES
6 tested
OUTPUT
Gaps and remediation · no score
RULE
FRE 702, amended 1 Dec 2023
DATA
Nothing stored, nothing sent
COST
Free · no sign-up
IN SHORT

Digital forensic opinions are rarely excluded because hashing does not work. They are excluded because the methodology was never written down, the tool was never validated for the function relied on, the hashes were never verified, custody has a hole in it, the opinion outran the artifact, or the witness answered a question outside their field. These twelve questions test for those six things.

0 OF 12 ANSWERED
  1. MODE 1UNDOCUMENTED METHODOLOGYDoes the report name the acquisition tool and its version number?

    WHERE TO LOOK — The methodology section, and any appendix of examination notes. A product name without a version is not an answer — tools change behaviour between releases, and the version is what makes the step reproducible.

  2. MODE 1UNDOCUMENTED METHODOLOGYCould a competent examiner, handed the same source material, re-run the work from the report alone?

    WHERE TO LOOK — Read the report as if you had the image and no access to its author. Every step, in order, with its settings — or a gap where one should be.

  3. MODE 2TOOL VALIDATIONIs there a stated basis for believing each tool is reliable for the specific function the opinion depends on?

    WHERE TO LOOK — A NIST CFTT reference where one covers the function, a vendor validation record, an internal validation against known data, or a second tool agreeing.

  4. MODE 2TOOL VALIDATIONIs every load-bearing artifact corroborated by a second tool or by manual parsing?

    WHERE TO LOOK — The one or two artifacts the conclusion actually rests on. Everything else can rest on a single tool; these cannot.

  5. MODE 2TOOL VALIDATIONDoes the report state the known limitations of the tools used, before the other side does?

    WHERE TO LOOK — A limitations section that names what the tooling does not do well, rather than one that only disclaims liability.

  6. MODE 3UNVERIFIED HASHESAre acquisition and verification hash values recorded for every item of evidence?

    WHERE TO LOOK — Both values, per item, per algorithm. One hash is an assertion; two matching hashes are a verification.

  7. MODE 3UNVERIFIED HASHESWhere a hash did not match, is the mismatch documented together with its cause, at the time it occurred?

    WHERE TO LOOK — A live acquisition from a running system frequently cannot verify against an unchanged source, and that is a legitimate and explicable result. Answer YES if there was no mismatch to record.

  8. MODE 4GAPS IN THE CHAIN OF CUSTODYIs there one custody record per item, opened at collection, showing every custodian, transfer, storage location and access?

    WHERE TO LOOK — The custody documentation as an exhibit, not a sentence in the narrative asserting that custody was maintained.

  9. MODE 5OVERSTATED CERTAINTYDoes the report keep the account, the device and the person distinct throughout?

    WHERE TO LOOK — Every sentence that names a party. A log records an account; attributing that session to a human being requires something outside the machine, and the report should say which.

  10. MODE 5OVERSTATED CERTAINTYAre alternative explanations identified, with what in the evidence does or does not rule each one out?

    WHERE TO LOOK — A section that considers the competing account on the record. Its absence is conspicuous; its presence is difficult to attack.

  11. MODE 6SCOPE CREEP BEYOND THE EXPERT'S EXPERTISEDoes the report define the boundaries of the assignment, and stay inside them?

    WHERE TO LOOK — A scope statement at the front, then every opinion in the report tested against it — particularly opinions about intent, damages, or the ultimate legal question.

  12. MODE 6SCOPE CREEP BEYOND THE EXPERT'S EXPERTISEWhere the question crossed into another specialty, was a second expert retained rather than the first stretched?

    WHERE TO LOOK — Mobile handsets, source code, media authenticity and enterprise log analysis are different specialties with different validation records. Answer YES if the question never crossed a boundary.

THE READOUT

0 of 12 answered

Findings appear against each question as you answer it, and are collected below. The banded readout needs all twelve — a form with nothing on it is not a report with nothing wrong with it, and this tool will not print the first as though it were the second.

Nothing flagged so far

Answer NO or CAN'T TELL to any question and the mode it belongs to appears here, with the remediation for it.

What the amended rule actually asks

The proponent must show, more likely than not, that each requirement of Rule 702 is met — and that the opinion reflects a reliable application of the method to these facts.

A witness who is qualified as an expert by knowledge, skill, experience, training, or education may testify in the form of an opinion or otherwise if the proponent demonstrates to the court that it is more likely than not that: (a) the expert’s scientific, technical, or other specialized knowledge will help the trier of fact to understand the evidence or to determine a fact in issue; (b) the testimony is based on sufficient facts or data; (c) the testimony is the product of reliable principles and methods; and (d) the expert’s opinion reflects a reliable application of the principles and methods to the facts of the case.
Fed. R. Evid. 702, as amended effective 1 December 2023

The 2023 amendment did not create a new standard. It corrected two readings courts had been giving the old text: that the reliability requirements were questions of weight for the jury rather than admissibility questions for the judge, and that subsection (d) asked only whether a reliable method existed rather than whether this opinion reflected a reliable application of it. The advisory committee note is explicit that an expert may not overstate a conclusion beyond what the basis and methodology support — which, in this discipline, is the difference between what an artifact records and what an opinion says it shows. The full treatment is in the guide to Daubert challenges to digital evidence; which standard governs in your forum is a separate question, and the jurisdiction lookup covers it.

The six failure modes

These are the six the questions above test for, with the challenge as it is actually made and the answer that meets it. The check maps every gap it finds back onto one of them, because the remediation for a gap is a property of the mode rather than of the question that surfaced it.

FAILURE MODEHOW THE CHALLENGE IS MADEWHAT ANSWERS IT
1. Undocumented methodologyThe report says the examiner “imaged the device and analyzed it,” with no acquisition tool, no version, no hash, no settings and no sequence of steps. Opposing counsel cannot reproduce anything, and neither can the court. Under Rule 702(c) and (d) there is simply nothing to evaluate, and the burden is on the proponent.Contemporaneous examination notes, with the tool and version recorded at each step, and a report written so that a competent examiner handed the same source material can re-run the work and reach the same result.
2. Tool validationThe examiner cannot say whether the tool was ever tested for the specific function the opinion depends on, or relied on a one-off script written for this matter and never run against known data. Factor three has nothing to attach to.Cite the tool's testing record, including NIST CFTT reports where they cover the function; state the tool's known limitations before the other side does; and corroborate any load-bearing artifact with a second tool or by parsing the underlying structure by hand.
3. Unverified hashesNo acquisition hash, no verification hash, or a mismatch nobody addressed. This is an authentication problem as much as a reliability one: FRE 901(b)(9) asks for evidence describing a process or system and showing that it produces an accurate result, and FRE 902(14) — the self-authentication route for data copied from a device — is built entirely on authentication “by a process of digital identification.”Record acquisition and verification values for every item, and document any mismatch together with its cause at the time it occurs rather than leaving it for a deposition to discover. Where the evidence came from a provider rather than a device there is no source to hash against, and the equivalent discipline is a contemporaneous collection record.
4. Gaps in the chain of custodyUnexplained transfers, no record of seal or storage, or a device unaccounted for between collection and examination. Custody gaps usually go to weight — but a gap wide enough, paired with any other defect on this list, becomes an admissibility argument, and it reliably costs the expert credibility with the bench.One custody record per item, opened at collection, showing every custodian, date, transfer, storage location and access.
5. Overstated certainty“Conclusively,” “one hundred percent certain,” or — the common one in this field — attributing an act to a person when the artifact establishes only an account or a device. This is the exact failure the 2023 advisory committee note names, and it is now a Rule 702(d) argument rather than a cross-examination point.State each conclusion at the level the artifact actually supports, keep the device and the user distinct, and identify the alternative explanations along with what in the evidence does or does not rule them out.
6. Scope creep beyond the expert's expertiseA computer examiner opining on mobile chip-off recovery, on damages, on what a party intended, or on the ultimate legal question. Rule 702 qualifies a witness in a field; it does not qualify them for the whole case.Define the boundaries of the assignment in the report, decline questions outside them on the record, and retain a second expert rather than stretching one past their qualifications.
Reproduced from the firm's guide to Daubert challenges to digital evidence. The list is not exhaustive — it is the six that account for most of the exclusions in this field, not all of the ways an opinion can fail.

Why gaps in two modes are worse than two gaps

Findings in this field compound rather than add. A chain-of-custody gap standing alone is ordinarily argued as weight, and a court will frequently say so. The same gap sitting beside unverified hashes is a different argument: the proponent now has neither a record of where the item was nor a means of showing that what was examined is what was collected, and the burden the amended rule restates has nothing to rest on.

That is why the readout groups findings by mode instead of listing twelve questions in a row. Three gaps in documentation is one problem, fixable by attaching notes that already exist. One gap in documentation, one in custody and one in certainty is three problems, and it is the pattern that turns a deposition line into a motion. How those arguments have actually run is what the Daubert docket tracks.

Two ways to use it

  • On your own expert, before service. Every finding is cheaper now than later. A gap you disclose and close is worth considerably less to the other side than the same gap they find, and several of the twelve are satisfied by material that already exists and simply was not attached.
  • On an opposing report, before the deposition. The findings identify where a line of questions has something to attach to. A NO answer is a question to ask on the record; a CAN’T TELL is usually a document request rather than a motion, because the notes may exist and the report simply did not incorporate them.
  • Before retention, alongside the vetting checklist. The vetting checklist asks a candidate for a redacted sample report. Running these twelve questions against that sample tells you how the candidate works when nothing is at stake, which is the best available predictor of how they will work when something is.

What this tool does not tell you

  • It does not predict how a court will rule. Nothing could. Admissibility turns on the forum, the judge, the posture, what the opinion is actually offered to prove, and how well it is defended at the hearing. The bands describe your answers and say so in their own text.
  • It tests methodology, not qualifications, relevance or the data. Rule 702 has four subsections and these questions bear mainly on two of them. An expert with a flawless method can still be unqualified for the question asked, or working from facts and data that are insufficient, and neither shows up here.
  • It reflects the Federal Rules, and your forum may not. A substantial minority of states apply a general-acceptance test or a state-specific variant in which several of these questions carry different weight. Check which standard governs before you brief any of this.
  • A clean result is not a defensible report. Twelve questions cannot test whether the examiner looked in the right places, interpreted the artifacts correctly, or considered the source material that was never collected. The most serious defect a forensic report can have — an opinion built on evidence nobody thought to preserve — is invisible to every question here.
  • Answers depend on who is reading the report. A reader who knows what a validation record looks like will answer question three differently from one who does not, and the tool cannot tell which reader it has. It structures the reading; it does not perform it.
  • It is not legal advice and not an opinion on your matter. Whether to move, when to move, and what to say are decisions for counsel. This is a reading aid.

Questions counsel ask

What changed when Rule 702 was amended on 1 December 2023?

Two things, both clarifications the drafters said were needed because courts had been getting them wrong. First, the rule now states expressly that the proponent must demonstrate to the court that it is more likely than not that each requirement of the rule is met — restating the preponderance burden that many courts had been treating as a question of weight for the jury. Second, subsection (d) was reworded so that the expert's opinion must reflect a reliable application of the principles and methods to the facts of the case. The advisory committee note singles out overstatement: an expert may not state a conclusion with more confidence than the underlying basis and methodology support. In digital forensics that is the difference between what an artifact records and what an opinion says it shows.

Why does this tool not produce a score or a percentage?

Because a percentage implies a measurement, and there is nothing here to measure. No defensible weighting of these six failure modes against one another exists — a single unexplained hash mismatch may matter more than four documentation gaps, or considerably less, depending on what the opinion rests on — and a court's decision is not a function of a questionnaire. The output is therefore a count of gaps and the list of what they are, which is the only claim this instrument can actually support. A tool that printed a confident number here would be committing failure mode 5 in the course of warning about it.

Is 'I can't tell from the report' a bad answer?

It is the most informative answer on the form. Every one of these twelve questions is answerable from the four corners of a competent report. If the person holding the report cannot answer one, that is itself a finding, and it is a finding in the first failure mode: methodology that is not documented cannot be evaluated, which is what Rule 702(c) and (d) ask the court to do. The correct next step is usually a targeted request for the examination notes rather than a motion.

Do custody gaps make forensic evidence inadmissible?

Usually not on their own. Chain-of-custody problems are ordinarily treated as going to the weight the fact-finder gives the evidence rather than to its admissibility, and a court will often say so in as many words. The compounding is what matters: a custody gap alongside unverified hashes, or alongside a methodology nobody wrote down, stops being a cross-examination point and becomes an argument that the proponent has not carried the burden the amended rule restates. Gaps in more than one failure mode do not add, they multiply.

Does a gap identified here mean the expert will be excluded?

No, and nothing on this page should be read that way. Exclusion is rarer than the volume of motions suggests; partial limitation of an opinion is far more common than striking a witness, and many gaps are cured by a supplement, by producing contemporaneous notes that existed all along but were not attached, or by a corrected report where the schedule still permits one. What the check identifies is exposure — the places where the report will have to be defended — not an outcome.

Can I run this against my own expert before serving the report?

That is the use it is built for. Every finding is cheaper to fix before service than to explain after it, because a gap you disclose is worth considerably less to the other side than the same gap they find. Running it on an opposing report tells you where a motion or a deposition line has something to attach to; running it on your own tells you what to fix while fixing it is still an option.
A SECOND READ ON A REPORT

Where a report has to be defended or attacked on these grounds, the work is a written analysis of the methodology and its limits — the same six modes, applied to the actual record rather than to twelve general questions.

Bring the output above and it becomes the agenda for the call.

A conflicts check and scoping call follow, normally within one business day. Please do not send privileged or case-sensitive material until conflicts have cleared.

WEEKLY BRIEFING

Digital evidence, explained for litigators.

One email a week on forensic method, digital evidence, and expert testimony — written for counsel, not for technicians. No pitches.

DOUBLE OPT-IN · UNSUBSCRIBE ANY TIME · PRIVACY POLICY

Other tools

  • TOOL 01 / RETENTION
    Preservation Deadline Calculator

    Enter an incident date, pick the systems in play, and see when each source's default retention window closes — with the licence tier every figure depends on stated beside it.

  • TOOL 02 / ARTIFACTS
    Can This Artifact Prove That?

    Pick the claim you need to support. See which artifacts bear on it, what each one actually records, and — the half that matters on cross — what none of them establishes.

  • TOOL 03 / RETENTION DILIGENCE
    Expert Vetting Checklist

    The nine-step vetting procedure and the eight documents to request, as a checklist you can work through, save in your browser, and print for the file.

  • TOOL 05 / DISCLOSURE
    Rule 26 Report Check

    The six things Fed. R. Civ. P. 26(a)(2)(B) requires a retained expert's report to contain, quoted in full, as a checklist against the report on your desk.

  • TOOL 06 / JURISDICTION
    Daubert or Frye Lookup

    Which admissibility standard each state applies to expert evidence, including the states whose posture is mixed, state-specific, or has recently changed — and the amended federal Rule 702.

  • TOOL 07 / SCOPE
    Engagement Scope Estimator

    Build a scope schedule from device count, device type, question complexity, deadline and deliverable — the drivers that move a forensic estimate, itemised.

Attorney advertising / expert services. This tool describes forensic practice and the procedural rules that govern expert evidence in general terms. It is not legal advice, it does not create an attorney–client or expert-engagement relationship, and it is not a substitute for checking the rules, standing orders, and case law of your own forum. Rule text is quoted from the Federal Rules of Evidence as amended effective 1 December 2023; state rules differ and several states apply a different admissibility standard entirely. Prior results do not guarantee a similar outcome.