From zero to self-certification, step by step
Just follow the order. An agent at each step generates company-specific artifacts for you.
These agents live in the Trusted OSS Agent repository- 00
Get started
Grasp the big picture of supply chain security and the two standards.
- 01
Set up
Prepare the foundation for self-study and artifact generation.
- 02
Organization
Define governance owners with a responsibility (RACI) model.
- 03
OSS policy
Establish license approval tiers and policy documents.
- 04
Process
Design operating procedures: review, approval, disclosure.
- 05
SBOM & vulnerabilities
Generate and analyze SBOMs and manage vulnerabilities with tools.
- 06
Training
Build the capability to keep the system running over time.
- 07
Self-certification
Check conformance and complete a self-certification declaration.
Three tracks for your role
A standards-based management system, a security pipeline, and AI coding compliance. Start with the track you need.
Build Your System
Build an enterprise open source management system from scratch to completion, based on ISO/IEC 5230 & 18974.
Learn more →DevSecOps
Integrate security into your development pipeline. Covers SAST, SCA, container security, and CI/CD automation.
Learn more →AI Coding
Manage AI coding tools like Claude Code, Cursor, and Copilot alongside open source compliance.
Learn more →Reference
Look up the requirements matrix and the deliverable samples. See what to produce for each standard item.
Learn more →Real artifacts the agents produce
Preview the artifacts auto-generated for your company through these best-practice samples.
# Open Source Policy
## 3.1 License approval tiers
- Allowed: MIT · Apache-2.0
- Review: LGPL · MPL-2.0
- Forbidden: AGPL · commercial EULA{
"bomFormat": "CycloneDX",
"components": [
{ "name": "log4j-core",
"version": "2.14.1",
"vuln": "CVE-2021-44228" }
]
}ISO/IEC 5230 conformance declaration
Organization: ____________________
[v] 3.1 Program foundation
[v] 3.2 Assigned support and responsibility
[v] 3.3 Content review and approvalWhy Trusted OSS, together with KWG
Trusted OSS grew out of the KWG community. KWG points the way with standards and blank templates; Trusted OSS turns that into executable artifacts with AI and automation.
OpenChain KWG
Tells you what the standard requires and why. Provides the international standards, an enterprise OSS management guide, and blank templates.
- ISO/IEC 5230 and 18974 standard guides
- Blank policy and process templates
- Tool guides and links
Trusted OSS
Helps you actually achieve the standard with AI and automation, on a single path from zero to self-certification.
- AI agents auto-generate company-tailored artifacts
- Copy-paste CI workflows and Rules, no-API-key demos
- Extends to DevSecOps and AI coding governance
Trusted OSS is an open source initiative that grew out of the KWG community. It synchronizes KWG content and attributes it under CC BY 4.0. View the OpenChain KWG guide
Start with step one, today
A free OpenChain KWG guide, all the way to self-certification. No install, no cost, no vendor lock-in.
Want to keep monitoring vulnerabilities, licenses, and SBOMs after certification? Check out TRUSCA.