Skip to main content

Integrated Requirements Checklist Mapping

Purpose of this document

This document brings the self-certification checklist items of ISO/IEC 5230 (license compliance) and ISO/IEC 18974 (security assurance) together into a single mapping table. It serves as a compass for the whole project.

Every agent's CLAUDE.md refers to this document to determine which module generates the deliverables that satisfy which standard requirements.

Source basis: for the original-text commentary and templates behind each item, see the OpenChain KWG (CC BY 4.0) Enterprise Open Source Guide and Policy and Process Templates. The chapter and deliverable structure of this mapping is reworked from those guides.

How to read this document

  1. Comparison of the two standards → first understand the purpose and scope of each standard
  2. Integrated mapping → for each G1-G4 group, check the evidence, deliverable files, and responsible agent in each item block
  3. Tags → quickly grasp the nature of each item from [Common] [5230] [18974] [Supply Chain] [Regulation]
  4. Summary statistics → see the overall status in numbers at the bottom of the document

Comparing the two standards

ItemISO/IEC 5230ISO/IEC 18974
Official nameOpenChain License ComplianceOpenChain Security Assurance
Latest version2.1 (2020)1.0 (2023)
PurposeEstablish an open source license compliance systemEstablish an open source security vulnerability assurance system
FocusFulfilling license obligations, BOM management, attribution notice creationIdentifying, tracking, and responding to known CVEs; SBOM-based security
Key requirementsPolicy, organization, process, BOM, compliance deliverables, contribution policy, declaration of compliancePolicy, organization, SBOM, CVE scan, vulnerability tracking/scoring/response, declaration of compliance
Certification methodSelf-declaration on the OpenChain websiteSelf-declaration on the OpenChain website
Validity period18 months18 months
Related regulations/standardsSPDX, REUSE, EU CRA (licensing aspect)EO 14028, NTIA SBOM, EU CRA, NVD/CVSS
ComplementarityShares the common foundation (policy, organization, SBOM); adds license-specific requirementsShares the common foundation; adds security-specific requirements
Key insight

The two standards share a common foundation in the areas of policy, organization, training, and SBOM. Building one automatically fulfills half of the other.


Tag notation rules

TagMeaning
[Common]Required by both standards
[5230]ISO/IEC 5230 only
[18974]ISO/IEC 18974 only (security-specific)
[Supply Chain]Related to software supply chain security
[Regulation]Items linked to international regulations (EO 14028, EU CRA, NTIA SBOM)

Integrated mapping

G1: Program foundation


G1.1 — Establishing and documenting an open source policy [Common]

ISO/IEC 5230 §3.1.1 · ISO/IEC 18974 §4.1.1

Without a policy you cannot establish systematic compliance; it is the basis for every activity.

Evidence IDContentDeliverable file
5230 §3.1.1.1 · 18974 §4.1.1.1Documented open source policyoutput/policy/oss-policy.md
5230 §3.1.1.2 · 18974 §4.1.1.2Policy dissemination procedureoutput/training/curriculum.md
  • Agent in charge: 03-policy-generator

G1.2 — Establishing a review process for the security assurance policy [18974]

ISO/IEC 18974 §4.1.1

18974 additionally requires a regular review process to keep the policy and its communication methods current.

Evidence IDContentDeliverable file
18974 §4.1.1.1Documented security assurance policy (including review process)output/policy/oss-policy.md
18974 §4.1.2.5Evidence of periodic review and changeoutput/conformance/gap-analysis.md
  • Agent in charge: 03-policy-generator

G1.3 — Designating the open source Program Manager and organization [Common]

ISO/IEC 5230 §3.1.2 · ISO/IEC 18974 §4.1.2

Without clear ownership, decision-making stalls.

Evidence IDContentDeliverable file
5230 §3.1.2.1 · 18974 §4.1.2.1List of roles and responsibilitiesoutput/organization/raci-matrix.md
5230 §3.1.2.2 · 18974 §4.1.2.2Document describing the competencies of each roleoutput/organization/role-definition.md
18974 §4.1.2.3Participant list and rolesoutput/organization/role-definition.md
5230 §3.1.2.3 · 18974 §4.1.2.4Evidence of competency assessmentoutput/training/completion-tracker.md
18974 §4.1.2.5Evidence of periodic review and process changes ⚠️output/conformance/gap-analysis.md
18974 §4.1.2.6Verification of alignment with internal best practices ⚠️output/conformance/gap-analysis.md
§4.1.2.5 · §4.1.2.6 at initial certification

At first certification there is no review history, so these are treated as partially satisfied. Record the review-cycle plan and owner assignment in gap-analysis.md, and satisfy them with actual history at the 18-month renewal.

  • Agent in charge: 02-organization-designer

G1.4 — Establishing a training program [Common]

ISO/IEC 5230 §3.1.2 · ISO/IEC 18974 §4.1.2 (education and training aspects)

Build and continuously maintain staff competency; both standards require evidence of training completion.

Evidence IDContentDeliverable file
5230 §3.1.2.1 · 18974 §4.1.2.1List of roles and responsibilitiesoutput/organization/raci-matrix.md
5230 §3.1.2.3 · 18974 §4.1.2.4Evidence of competency assessmentoutput/training/completion-tracker.md
  • Agent in charge: 06-training-manager

G1.5 — Defining the program scope [Common]

ISO/IEC 5230 §3.1.4 · ISO/IEC 18974 §4.1.4

Clarifying the target software and products enables efficient resource allocation.

Evidence IDContentDeliverable file
5230 §3.1.4.1 · 18974 §4.1.4.1Program scope and limitations documentoutput/policy/oss-policy.md
18974 §4.1.4.2Performance metricsoutput/policy/oss-policy.md
18974 §4.1.4.3Evidence of continuous improvement ⚠️output/conformance/gap-analysis.md
§4.1.4.3 at initial certification

There is no improvement history at first certification. Record the initial gap analysis run itself in gap-analysis.md as one audit record; at the 18-month renewal, two or more records will satisfy this item.

  • Agent in charge: 03-policy-generator

G1.6 — Establishing procedures to review license obligations [5230]

ISO/IEC 5230 §3.1.5

Prevent license violations before distribution; covers obligations such as copyleft source-code disclosure.

Evidence IDContentDeliverable file
5230 §3.1.5.1Procedures for reviewing and recording the obligations, restrictions, and rights of each identified licenseoutput/process/usage-approval.md
  • Agent in charge: 04-process-designer

G1.7 — Program participant awareness records [Common]

ISO/IEC 5230 §3.1.3 · ISO/IEC 18974 §4.1.3

Document, per person and role, that each participant understands the policy, the goals, and how to contribute; this is key evidence during an audit.

Evidence IDContentDeliverable file
5230 §3.1.3.1 · 18974 §4.1.3.1Evidence assessing participant awareness of the program goals, ways to contribute, and impact of non-complianceoutput/training/completion-tracker.md
  • Agent in charge: 06-training-manager


G2.1 — Establishing roles and responsibilities (RACI) [Common]

ISO/IEC 5230 §3.2.2 · ISO/IEC 18974 §4.2.2

Clarify who performs, approves, and reviews open source activities; prevent gaps in ownership.

Evidence IDContentDeliverable file
5230 §3.2.2.1 · 18974 §4.2.2.1Document naming the owner/group/job title for each roleoutput/organization/raci-matrix.md
5230 §3.2.2.2 · 18974 §4.2.2.2Confirmation of adequate role staffing and budgetoutput/organization/raci-matrix.md
5230 §3.2.2.3Method for accessing legal counsel on license complianceoutput/organization/role-definition.md
5230 §3.2.2.4 · 18974 §4.2.2.4Internal responsibility assignment procedureoutput/organization/raci-matrix.md
5230 §3.2.2.5Procedure for reviewing and correcting license non-compliance casesoutput/process/usage-approval.md, output/process/distribution-checklist.md
18974 §4.2.2.3Identification of the expertise available to resolve vulnerabilitiesoutput/organization/role-definition.md
  • Agent in charge: 02-organization-designer

G2.2 — Operating channels for receiving external inquiries [Common]

ISO/IEC 5230 §3.2.1 · ISO/IEC 18974 §4.2.1

An official channel is required so third parties can request fulfillment of license obligations and report security vulnerabilities.

Evidence IDContentDeliverable file
5230 §3.2.1.1 · 18974 §4.2.1.1Public channel through which third parties can inquireoutput/organization/role-definition.md
5230 §3.2.1.2 · 18974 §4.2.1.2Internal response procedure for third-party inquiriesoutput/process/inquiry-response.md, output/process/vulnerability-response.md
  • Agent in charge: 02-organization-designer, 04-process-designer

G2.3 — Operating an awareness program [Common]

ISO/IEC 5230 §3.1.3 · ISO/IEC 18974 §4.1.3

Compliance is only effective when every member knows and follows the policy.

Evidence IDContentDeliverable file
5230 §3.1.3.1 · 18974 §4.1.3.1Evidence of participant awareness assessment (including goals, contribution, and impact of non-compliance)output/training/resources.md, output/training/completion-tracker.md
  • Agent in charge: 06-training-manager

G3-L: License compliance (ISO/IEC 5230 focus)


G3L.1 — License identification and classification [5230]

ISO/IEC 5230 §3.3.1 · §3.3.2

Identify the license status of each component from the SBOM; flag copyleft risk.

Evidence IDContentDeliverable file
5230 §3.3.1.1Procedure for identifying, tracking, reviewing, approving, and archiving the SBOMoutput/process/usage-approval.md
5230 §3.3.1.2Component records (evidence of procedural compliance)output/sbom/[project].cdx.json
5230 §3.3.2.1Procedure for handling license use casesoutput/sbom/license-report.md, output/sbom/copyleft-risk.md
  • Agent in charge: 05-sbom-analyst

G3L.2 — Fulfilling license obligations [5230]

ISO/IEC 5230 §3.3.2

Fulfill copyleft license obligations such as GPL, LGPL, and AGPL; maintain an Approved License List.

Evidence IDContentDeliverable file
5230 §3.3.2.1Procedure for handling the license use cases of each open source componentoutput/process/distribution-checklist.md, output/policy/license-allowlist.md
  • Agent in charge: 04-process-designer

G3L.3 — Generating compliance artifacts [5230]

ISO/IEC 5230 §3.4.1

Obligation to provide, at distribution time, the files that demonstrate fulfillment of legal obligations, such as attribution notices and source code.

Evidence IDContentDeliverable file
5230 §3.4.1.1Procedure for preparing and distributing compliance artifactsoutput/sbom/license-report.md
5230 §3.4.1.2Procedure for archiving compliance artifacts and records of fulfillmentoutput/sbom/license-report.md
  • Agent in charge: 05-sbom-analyst

G3L.4 — Establishing an open source contribution policy [5230]

ISO/IEC 5230 §3.5.1

Prevents IP leakage and license-contamination risk when contributing upstream.

Evidence IDContentDeliverable file
5230 §3.5.1.1Open source contribution policyoutput/policy/oss-policy.md
5230 §3.5.1.3Contribution policy awareness procedureoutput/training/curriculum.md
  • Agent in charge: 03-policy-generator

G3L.5 — Process for verifying that license obligations are met [5230]

ISO/IEC 5230 §3.4.1

Verify before distribution that all license obligations (source-code disclosure, inclusion of attribution notices, and so on) have actually been met; acts as a release approval gate.

Evidence IDContentDeliverable file
5230 §3.4.1.1Procedure for preparing and distributing compliance artifactsoutput/process/distribution-checklist.md
5230 §3.4.1.2Procedure for archiving compliance artifacts and records of fulfillmentoutput/process/distribution-checklist.md
  • Agent in charge: 04-process-designer

G3L.6 — Operating an open source contribution process [5230]

ISO/IEC 5230 §3.5.1

Concrete procedures for implementing the policy (G3L.4): the contribution review, approval, and submission workflow. Policy alone cannot govern actual contributions.

Evidence IDContentDeliverable file
5230 §3.5.1.2Open source contribution management procedureoutput/policy/oss-policy.md, output/process/contribution-process.md (conditional)
  • Agent in charge: 03-policy-generator, 04-process-designer (conditional)

G3-S: Security assurance (ISO/IEC 18974 focus)


G3S.1 — Identifying known vulnerabilities (CVE scan) [18974]

ISO/IEC 18974 §4.3.2 · §4.1.5

Failing to identify CVEs invites security incidents and legal liability; this is an EO 14028 requirement.

Evidence IDContentDeliverable file
18974 §4.1.5.1Standard vulnerability response procedure, including vulnerability detection methodsoutput/process/vulnerability-response.md
18974 §4.3.2.1Vulnerability detection and resolution procedureoutput/vulnerability/cve-report.md
18974 §4.3.2.2Record of vulnerabilities and actions takenoutput/vulnerability/cve-report.md
  • Agent in charge: 05-vulnerability-analyst

G3S.2 — Vulnerability tracking and status management [18974]

ISO/IEC 18974 §4.3.2 · §4.1.5

Continuously track identified vulnerabilities until remediation is complete; prevent items from being missed or left unattended.

Evidence IDContentDeliverable file
18974 §4.1.5.1Standard response procedure, including how to follow up on vulnerabilitiesoutput/process/vulnerability-response.md
18974 §4.3.2.1Vulnerability detection and resolution procedureoutput/vulnerability/cve-report.md
18974 §4.3.2.2Record of vulnerabilities and actions takenoutput/vulnerability/cve-report.md
  • Agent in charge: 05-vulnerability-analyst

G3S.3 — CVE risk scoring (CVSS) [18974]

ISO/IEC 18974 §4.3.2

Prioritize by CVSS score; allocate resources efficiently.

Evidence IDContentDeliverable file
18974 §4.3.2.1Vulnerability handling procedure, including risk/impact score assignmentoutput/vulnerability/cve-report.md
18974 §4.3.2.2Record of identified vulnerabilities and risk scoresoutput/vulnerability/cve-report.md
  • Agent in charge: 05-vulnerability-analyst

G3S.4 — Vulnerability response and patching procedures [18974]

ISO/IEC 18974 §4.3.2 · §4.1.5

A system for rapidly patching, upgrading, or mitigating discovered vulnerabilities.

Evidence IDContentDeliverable file
18974 §4.1.5.1Standard response procedure, including appropriate action methods for each risk leveloutput/vulnerability/remediation-plan.md
18974 §4.3.2.1Vulnerability resolution procedureoutput/vulnerability/remediation-plan.md
18974 §4.3.2.2Record of actions takenoutput/vulnerability/remediation-plan.md
  • Agent in charge: 05-vulnerability-analyst

G3S.5 — Security artifact delivery process [18974, Supply Chain]

ISO/IEC 18974 §4.3.1

Formal procedures for delivering security deliverables such as the SBOM and CVE reports to supply chain partners and customers; addresses the EO 14028 and EU CRA disclosure obligations.

Evidence IDContentDeliverable file
18974 §4.3.1.1Procedure for continuously recording the SBOM throughout the supplied software life cycleoutput/sbom/sbom-sharing-template.md
18974 §4.3.1.2Component records (evidence of procedural compliance)output/sbom/[project].cdx.json
  • Agent in charge: 05-sbom-management

G3S.6 — Process for verifying that security obligations are met [18974]

ISO/IEC 18974 §4.3.2

Procedure to verify that the response, patch, and mitigation actions for identified and tracked vulnerabilities were actually completed; confirms real implementation rather than a mere declaration.

Evidence IDContentDeliverable file
18974 §4.3.2.1Procedure including verification that vulnerability resolution is completeoutput/vulnerability/remediation-plan.md
18974 §4.3.2.2Record of completed actionsoutput/vulnerability/remediation-plan.md
  • Agent in charge: 05-vulnerability-analyst

G3-B: SBOM and supply chain (common)


G3B.1 — Creating an SBOM (CycloneDX/SPDX) [Common, Supply Chain]

ISO/IEC 5230 §3.3.1 · ISO/IEC 18974 §4.3.1

The starting point for component transparency; the input for both license and security analysis.

Evidence IDContentDeliverable file
5230 §3.3.1.1 · 18974 §4.3.1.1Procedure for identifying, tracking, reviewing, approving, and archiving the SBOMoutput/sbom/sbom-commands.sh
5230 §3.3.1.2 · 18974 §4.3.1.2Component records (evidence of procedural compliance)output/sbom/[project].cdx.json
  • Agent in charge: 05-sbom-guide

G3B.2 — SBOM management and maintenance [Common, Supply Chain]

ISO/IEC 5230 §3.3.1 · ISO/IEC 18974 §4.3.1

Keep the SBOM current on every release and update; integrate it with configuration management.

Evidence IDContentDeliverable file
5230 §3.3.1.1 · 18974 §4.3.1.1SBOM life cycle management procedureoutput/sbom/sbom-management-plan.md
5230 §3.3.1.2 · 18974 §4.3.1.2Up-to-date component recordsoutput/sbom/[project].cdx.json
  • Agent in charge: 05-sbom-management

G3B.3 — Sharing the SBOM (with supply chain partners) [Supply Chain, Regulation]

ISO/IEC 18974 §4.3.1

Pass transparency down the supply chain; addresses the NTIA and EU CRA supply chain disclosure obligations.

Evidence IDContentDeliverable file
18974 §4.3.1.1Life cycle recording procedure, including sharing the SBOM with supply chain partnersoutput/sbom/sbom-sharing-template.md
18974 §4.3.1.2Component recordsoutput/sbom/[project].cdx.json
  • Agent in charge: 05-sbom-management

G3B.4 — Continuous monitoring of supply chain vulnerabilities [Supply Chain]

ISO/IEC 18974 §4.3.2

When a new CVE is disclosed, immediately identify which supply chain components are affected.

Evidence IDContentDeliverable file
18974 §4.3.2.1Response procedure, including methods for analyzing new vulnerabilities after releaseoutput/sbom/sbom-management-plan.md
18974 §4.3.2.2Record of vulnerabilities and actions takenoutput/sbom/sbom-management-plan.md
  • Agent in charge: 05-sbom-management

G4: Declaring and maintaining compliance


G4.1 — ISO/IEC 5230 self-certification declaration [5230]

ISO/IEC 5230 §3.6.1

Official declaration of license compliance capability; earns the trust of supply chain partners.

Evidence IDContentDeliverable file
5230 §3.6.1.1Document confirming that the program in §3.1.4 meets all requirements of this specificationoutput/conformance/declaration-draft.md
  • Agent in charge: 07-conformance-preparer

G4.2 — ISO/IEC 18974 self-certification declaration [18974]

ISO/IEC 18974 §4.4.1

Official declaration of security assurance capability; evidence for EO 14028 and EU CRA compliance.

Evidence IDContentDeliverable file
18974 §4.4.1.1Document confirming that the program in §4.1.4 meets all requirements of this specificationoutput/conformance/declaration-draft.md
  • Agent in charge: 07-conformance-preparer

G4.3 — Managing the certification validity period (18 months) [Common]

ISO/IEC 5230 §3.6.2 · ISO/IEC 18974 §4.4.2

Both standards require re-declaration every 18 months; this avoids automatic expiration.

Evidence IDContentDeliverable file
5230 §3.6.2.1 · 18974 §4.4.2.1Document confirming that all requirements have been met within 18 months of obtaining conformanceoutput/conformance/submission-guide.md
  • Agent in charge: 07-conformance-preparer

G4.4 — Regular gap analysis and policy updates [Common]

ISO/IEC 5230 §3.6.2 · ISO/IEC 18974 §4.4.2

Evolve the system as the technical and regulatory environment changes; required before a renewal declaration.

Evidence IDContentDeliverable file
5230 §3.6.2.1 · 18974 §4.4.2.1Document confirming re-satisfaction of requirements after renewaloutput/conformance/gap-analysis.md
  • Agent in charge: 07-conformance-preparer

G4.5 — Confirming distributed software has no known vulnerabilities [18974]

ISO/IEC 18974 §4.4.1 · §4.3.2

Before distribution, verify and declare that externally distributed software has no known vulnerabilities; a practical prerequisite for the certification declaration.

Evidence IDContentDeliverable file
18974 §4.4.1.1Document confirming that distributed software fully meets the requirementsoutput/conformance/declaration-draft.md
18974 §4.3.2.2Record of completed vulnerability actionsoutput/vulnerability/cve-report.md
  • Agent in charge: 07-conformance-preparer

Summary statistics

CategoryNumber of items
ISO/IEC 5230 mapped items20
ISO/IEC 18974 mapped items23
Items common to both standards12
Supply chain related items ([Supply Chain] tag)5
Regulation-linked items ([Regulation] tag)1
Total number of items31
Note

The common items (12) are counted in both the 5230 total (20) and the 18974 total (23). Preparing both standards at once lets you handle the common items only once, saving roughly 39% (12/31).


Next steps

Self-study mode (about 1 hour)

Once you understand this mapping document, start producing the actual deliverables. If the output/ folder is empty, begin with the steps below.

  1. Organization designcd agents/02-organization-designer && claude
  2. Create policycd agents/03-policy-generator && claude
  3. Process designcd agents/04-process-designer && claude
  4. Create SBOMcd agents/05-sbom-guide && claude
  5. License analysiscd agents/05-sbom-analyst && claude
  6. SBOM management plancd agents/05-sbom-management && claude
  7. Vulnerability analysiscd agents/05-vulnerability-analyst && claude
  8. Training programcd agents/06-training-manager && claude
  9. Certification declarationcd agents/07-conformance-preparer && claude
Status of this document

This document is the project's canonical mapping reference for the full ISO/IEC 5230 and the full ISO/IEC 18974 requirements. Each agent's CLAUDE.md refers to this file.