Skip to main content

Integrated Requirements Checklist Mapping

This document summarizes what ISO/IEC 5230 (license compliance) and ISO/IEC 18974 (security assurance) require, on a single screen. The self-certification question, verification material, and deliverable file for each individual item live in the Requirements Detail Matrix. You use that matrix at the self-certification stage to check gap analysis results; for now the three sections below are all you need.

Comparing the two standards

ItemISO/IEC 5230ISO/IEC 18974
Official nameOpenChain License ComplianceOpenChain Security Assurance
Current editionISO/IEC 5230:2020 (OpenChain spec 2.1)ISO/IEC 18974:2023
PurposeEstablish an open source license compliance programEstablish an open source security vulnerability assurance program
FocusMeeting license obligations, BOM management, notice generationIdentifying, tracking, and responding to known CVEs; SBOM-based security
Main requirementsPolicy, organization, process, BOM, compliance artifacts, contribution policy, declarationPolicy, organization, SBOM, CVE scanning, vulnerability tracking and scoring, declaration
Certification methodSelf-declaration on the OpenChain websiteSelf-declaration on the OpenChain website
Validity period18 months18 months
Related regulationsSPDX, REUSE, EU CRA (license side)EO 14028, CISA SBOM minimum elements, EU CRA, NVD/CVSS
ComplementarityShares the common base (policy, organization, SBOM) and adds license-specific itemsShares the common base and adds security-specific items
Key insight

The two standards share a common base across policy, organization, training, and SBOM. Building one automatically satisfies about half of the other.

The four groups of requirements

All 31 requirements fall into the groups below. Each group has a chapter that fills it, so working through the chapters in order fills the requirements along the way.

GroupWhat it coversChapters that fill it
G1Program foundation (policy, org, training)02 Organization, 03 Policy, 06 Training
G2Scoped tasks (roles, channels, awareness)02 Organization, 04 Process
G3-LLicense compliance (5230 focused)03 Policy, 04 Process, 05 SBOM generation
G3-SSecurity assurance (18974 focused)04 Process, 05 Vulnerability
G3-BSBOM and supply chain (common)05 SBOM generation, 05 SBOM management
G4Conformance declaration and maintenance07 Conformance

Why do both standards together

CategoryNumber of items
ISO/IEC 5230 mapped items20
ISO/IEC 18974 mapped items23
Items common to both12
Total number of items31

The 12 common items are counted in both the 5230 total (20) and the 18974 total (23). Preparing both standards at once means doing those 12 only once, saving roughly 39% (12/31). That is why this kit's chapter order handles the common items first.

Source basis: For the original standard commentary and templates behind each item, see the OpenChain KWG (CC BY 4.0) Enterprise Open Source Guide and policy and process templates. This mapping's chapter and deliverable structure is reworked from that guide.

Next steps

Once you have this much, move on to Environment setup to install the tools, then start producing deliverables from Organization structure.

The point where you need the per-item certification questions and verification material is the self-certification chapter. At that point, open the Requirements Detail Matrix and check it against your gap analysis results.