Skip to main content

Self-Certification Declaration: The Final Step

1. What we do in this chapter

Congratulations on making it this far. You have now completed all the key areas of an open source management system: organizational structure, policy creation, process design, SBOM generation and management, vulnerability analysis, and the training program.

Let's review the full list of deliverables created so far. If you have all of these in place, you are ready to declare your self-certification:

FolderDeliverables
output/organization/role-definition.md, raci-matrix.md, appointment-template.md
output/policy/oss-policy.md, license-allowlist.md
output/process/usage-approval.md, distribution-checklist.md, vulnerability-response.md, inquiry-response.md, process-diagram.md (+ contribution-process.md, project-publication-process.md conditional)
output/sbom/[project].cdx.json, sbom-commands.sh, license-report.md, copyleft-risk.md, sbom-management-plan.md, sbom-sharing-template.md
output/vulnerability/cve-report.md, remediation-plan.md
output/training/curriculum.md, completion-tracker.md, resources.md

In this chapter, we perform a gap analysis based on these deliverables, complete the self-certification declaration, and finish the official OpenChain registration.


2. Background knowledge: What is self-certification?

OpenChain Self-Certification is a way for an organization to declare that it meets the standard requirements without a third-party audit. Its key features are:

  • Self-declaration method: The organization checks and declares the checklist itself, without an external audit agency.
  • Official recognition: By registering on the OpenChain website, you receive official recognition from the OpenChain project.
  • Not legally binding: Although it is not a legal obligation, it serves as a trust signal to supply chain partners.
  • Validity period of 18 months: Per OpenChain guidance, rechecking every 18 months is recommended.

ISO/IEC 5230 (License Compliance) and ISO/IEC 18974 (Security Assurance) both provide a self-certification path, and simultaneous certification is also possible.


3. Final review before self-certification (self-study)

Self-study mode (about 2 hours)

The "about 2 hours" covers reading this document and running the agent to produce the gap analysis and declaration. If the gap analysis turns up unmet items, actually going back and fixing them in the relevant chapters takes extra time on top of that (anywhere from half a day to a few days, depending on how many items). The conformance-preparer agent automatically scans the entire output/ folder to identify unmet items.

Proceed in the following order:

  1. Read this document until the end.

  2. Run the conformance-preparer agent:

    Check before execution

    Terminate the current Claude session first (/exit or Ctrl+C), then run the command below in a new terminal.

    Bash
    cd agents/en/07-conformance-preparer && claude

    The agent automatically scans the entire output/ folder and generates a gap analysis report.

  3. Open the generated output/conformance/gap-analysis.md and check for unmet items.

  4. If any items are not met, return to the relevant chapter and supplement them.

  5. Review and edit the output/conformance/declaration-draft.md declaration.

  6. Register your self-certification on the OpenChain website, referring to output/conformance/submission-guide.md.


4. Understanding the gap analysis report

What is a gap analysis? It's the work of checking what you've built so far against what the standard requires, and finding the "gap" — what's still missing. The agent opens the entire output/ folder, compares it item by item against the standard's checklist, and writes the result to output/conformance/gap-analysis.md.

To check the certification question and verification material for each item yourself, keep the Requirements Detail Matrix open alongside it.

output/conformance/gap-analysis.md is created with the following structure:

SectionContent
List of satisfied itemsItems that fully meet requirements and their supporting deliverables
Partially satisfied itemsItems that are partially met but need supplementation, and how to supplement them
Unmet itemsItems not yet met and links to their chapters
Overall progressRatio of satisfied / partially satisfied / unmet items (%)

There is no need to panic if your gap analysis reveals unmet items. Each entry includes a link to the chapter you should return to. Partially satisfied items can often be converted to satisfied with only minor changes.

§4.1.4.3 — How to handle continuous improvement audit evidence (initial certification):

ISO/IEC 18974 §4.1.4.3 requires "audit evidence demonstrating continuous improvement." During initial certification, there is no history yet, so proceed as follows.

  • Initial certification: The gap-analysis.md generated by the conformance-preparer agent is itself the first audit record. If this is stated in gap-analysis.md, the item is treated as partially satisfied and does not block the certification declaration.
  • Renewal certification (18 months later): Once you have two or more gap analysis records, the item becomes fully satisfied (✅).

How to handle the two remaining time-based items (initial certification):

For the same reason, the two items below are normally only partially satisfied at first certification, and this does not block the certification declaration.

  • §4.1.2.5 Evidence of periodic review: Record the "next scheduled review date" in gap-analysis.md and the item is treated as partially satisfied. On renewal, one or more actual review records convert it to satisfied.
  • §4.1.2.6 Person responsible for verifying alignment with internal best practices: Assign the verification owner in role-definition.md and the item is treated as partially satisfied. On renewal, one or more recorded review results convert it to satisfied.

G4.5 — Confirming vulnerability remediation before distribution (18974 §4.3.2.2 · §4.4.1.1):

ISO/IEC 18974 does not require zero known vulnerabilities. It requires a record of the action taken for each identified vulnerability — including a decision that no action is needed (§4.3.2.2) — plus documented evidence that the program meets the requirements (§4.4.1.1). The conformance-preparer agent checks output/vulnerability/remediation-plan.md directly and decides whether to print the "completion" message based on the criteria below.

SituationHow to handle
The vulnerability is in the actual distributed software and already patchedDeclaration possible. Record the completed action in output/vulnerability/remediation-plan.md.
A Critical/High vulnerability is unresolved but still within its response deadline (1 week / 4 weeks)Does not block declaration. Note "unresolved until {date}" in remediation-plan.md.
A Critical/High vulnerability is unresolved past its response deadlineHold off declaring. Patch it or complete a mitigation first, then declare.
A vulnerability exists but mitigations have been completedDocument the mitigation measures and remaining risks in remediation-plan.md; a conditional declaration is possible.
The vulnerability is in a practice sampleSamples are not actual distributed software. Judge based on your actual distribution target product.
Declaration scope

Self-certification is a declaration about a specific software "scope." By clearly defining the scope (§3.1.4 / §4.1.4), you can make the declaration about actual products rather than practice samples.


5. OpenChain self-certification declaration procedure

Once the gap analysis is complete and there are no unmet items (or a resolution plan is in place), proceed with official registration using the following steps:

Cost

OpenChain self-certification registration is free. There is no review fee or registration charge — you self-check and then submit your company's information through the online form.

Step 1: Do a final review of the contents of output/conformance/declaration-draft.md and confirm them.

Step 2: Download the self-certification checklist. The OpenChain Reference-Material repository hosts language-specific files under Checklist/ISO-IEC-5230 and Checklist/ISO-IEC-18974. Download each one you intend to declare against.

Step 3: Answer each checklist item Yes/No as a self-assessment. The per-item verdicts in declaration-draft.md map directly onto it.

Step 4: Complete the online application form on the OpenChain get-started page to request listing. You do not upload the checklist itself; you submit company details on the premise that the self-assessment is done.

Step 5: Once listed, you appear among officially recognized companies and can use the OpenChain logo.

This step meets the requirements of ISO/IEC 5230 G4.1 (3.6.1) and ISO/IEC 18974 G4.2 (4.4.1).

Standard requirements met

Completing this exercise satisfies the requirements below.

5230 §3.6.1, §3.6.2 · 18974 §4.4.1, §4.4.2

The original self-certification question and the verification material for each item are in the Requirements Detail Matrix.


6. Strategy for certifying both standards at once

Finish the common items first, then the ISO/IEC 5230-only items, then the ISO/IEC 18974-only items. That order saves roughly 39% of the work, and this kit's chapter order follows it.

The item counts and the basis for that saving are in Standard requirements at a glance; the per-item mapping is in the Requirements Detail Matrix.


7. Post-certification maintenance

Self-certification is not a one-time event. It requires ongoing maintenance:

  • Annual policy review: Review output/policy/oss-policy.md and output/policy/license-allowlist.md once a year and keep them up to date.
  • Handover when the program manager changes: Follow a systematic handover process using the RACI matrix and the appointment letter template.
  • Response when a new version of a standard is released: Re-run the gap analysis when revisions of ISO/IEC 5230 and ISO/IEC 18974 are released.
  • Recheck every 18 months: As OpenChain recommends, reconfirm your self-certification every 18 months and declare a renewal when necessary.

This step meets the requirements of ISO/IEC 5230 G4.3 (3.6.2) and ISO/IEC 18974 G4.3 (4.4.2).

Setting the next goal: the OpenChain Capability Model

Self-certification produces only two values: met and not met. Once you are met, the standard does not tell you what to improve next. OpenChain published its Capability Model to fill that space; it reached general release on 2025-01-31 and is distributed as CC0 (effectively public domain), so you can copy it straight into your internal documents.

A version mapped to ISO/IEC 5230 (OpenChain 2.1) is provided as a spreadsheet. Recording a current level and a target level for each item gives you the improvement plan for the next 18 months up to renewal. It is available from OpenChain-Maturity-Models.

Other OpenChain material worth reading

ISO/IEC 5230:2020 and ISO/IEC 18974:2023 remain valid without revision. What does get updated is the supporting material below, so it is worth reviewing at each recheck cycle.

MaterialDateWhat it is for
Artificial Intelligence System Bill of Materials Compliance Management Guide v1.02025-10Sets out the policy, competence, AI content review and approval, and governance requirements for exchanging AI SBOMs across a supply chain, in the same shape as 5230. It also references ISO/IEC 42001:2023. CC BY 4.0
Telco SBOM Guide v1.12025-05Builds on SPDX and the NTIA minimum elements to define how SBOMs are created, delivered, and consumed in the telecom industry. Validators are distributed alongside it

Both live in the OpenChain Reference-Material repository, under the AI-SBOM-Compliance and SBOM-Quality-Management folders.


8. Completion checklist

Check all items below before finishing this chapter:

  • output/conformance/gap-analysis.md created
  • output/conformance/declaration-draft.md created
  • output/conformance/submission-guide.md created
  • There are no unmet items in the gap analysis, or there are plans to resolve them
  • Self-certification declaration completed
Example deliverables

You can see the actual format of the generated files in Self-Certification Deliverables Best Practice.


9. Celebrate completion and next steps

Your organization's open source management system is now complete.

From organizational structure to policy, process, SBOM, vulnerability management, training, and the self-certification declaration — every element required by ISO/IEC 5230 and ISO/IEC 18974 has been systematically put in place. This achievement is a strong trust signal to your supply chain partners and customers, demonstrating the maturity of your open source management.

Ways to keep growing with the open source ecosystem after certification:

  • Participate in the OpenChain KWG community: Share your experience with other companies in the Korean OpenChain community. https://openchain-project.github.io/OpenChain-KWG
  • Establish an in-house open source contribution policy: Move from consumption to contribution — set up a policy for contributing to open source communities.
  • Consider establishing an OSPO (Open Source Program Office): Strengthen long-term capability by formalizing a team dedicated to open source management.

Next: Scale with automation

Now that certification has defined what to do, the next step is enforcing it automatically in daily development.

  • AI Coding Tools and Open Source Compliance: Use Rules to keep AI coding tools such as Cursor, Copilot, and Claude Code within your policy.
  • DevSecOps: Turn SBOM generation and vulnerability scanning into CI pipeline gates that automatically block policy violations.