Skip to main content

Requirements Detail Matrix

This page is the canonical, item-by-item expansion of the 31 requirements in ISO/IEC 5230 and ISO/IEC 18974. Each item carries the original OpenChain self-certification question, the verification material named by the standard, the deliverable file that satisfies it, and the agent that produces that file.

You do not need this page when you first start reading. To understand what the two standards require, read the Standard requirements at a glance summary first. Use this matrix at the self-certification stage, when you check gap analysis results item by item.

Item ID scheme

G1 program foundation, G2 scoped tasks and support, G3-L license compliance, G3-S security assurance, G3-B SBOM and supply chain, G4 conformance declaration and maintenance. The per-group explanation is in Standard requirements at a glance.

Remark tags

TagMeaning
[Common]Required by both standards
[5230]ISO/IEC 5230 only
[18974]ISO/IEC 18974 only (security specific)
[Supply chain]Related to software supply chain security
[Regulation]Linked to regulations (EO 14028, EU CRA, CISA SBOM minimum elements)

Source basis: For the original standard commentary and templates behind each item, see the OpenChain KWG (CC BY 4.0) Enterprise Open Source Guide and policy and process templates.

Item-by-item mapping

G1: Program foundation


G1.1 — Establishing and documenting an open source policy [Common]

ISO/IEC 5230 §3.1.1 · ISO/IEC 18974 §4.1.1

Without a policy you cannot establish systematic compliance; it is the basis for every activity.

Evidence IDContentDeliverable file
5230 §3.1.1.1 · 18974 §4.1.1.1Documented open source policyoutput/policy/oss-policy.md
5230 §3.1.1.2 · 18974 §4.1.1.2Policy dissemination procedureoutput/training/curriculum.md
  • Certification question
    • 5230 §3.1.1: "Do you have a documented open source policy?"
    • 18974 §4.1.1: "Do you have a documented open source security assurance policy?"
  • Agent in charge: 03-policy-generator

G1.2 — Establishing a review process for the security assurance policy [18974]

ISO/IEC 18974 §4.1.1

18974 additionally requires a regular review process to keep the policy and its communication methods current.

Evidence IDContentDeliverable file
18974 §4.1.1.1Documented security assurance policy (including review process)output/policy/oss-policy.md
18974 §4.1.2.5Evidence of periodic review and changeoutput/conformance/gap-analysis.md
  • Certification question
    • 18974 §4.1.1: "Do you have a documented open source security assurance policy?"
  • Agent in charge: 03-policy-generator

G1.3 — Designating the open source Program Manager and organization [Common]

ISO/IEC 5230 §3.1.2 · ISO/IEC 18974 §4.1.2

Without clear ownership, decision-making stalls.

Evidence IDContentDeliverable file
5230 §3.1.2.1 · 18974 §4.1.2.1List of roles and responsibilitiesoutput/organization/raci-matrix.md
5230 §3.1.2.2 · 18974 §4.1.2.2Document describing the competencies of each roleoutput/organization/role-definition.md
18974 §4.1.2.3Participant list and rolesoutput/organization/role-definition.md
5230 §3.1.2.3 · 18974 §4.1.2.4Evidence of competency assessmentoutput/training/completion-tracker.md
18974 §4.1.2.5Evidence of periodic review and process changes ⚠️output/conformance/gap-analysis.md
18974 §4.1.2.6Verification of alignment with internal best practices ⚠️output/conformance/gap-analysis.md
§4.1.2.5 · §4.1.2.6 at initial certification

At first certification there is no review history, so these are treated as partially satisfied. Record the review-cycle plan and owner assignment in gap-analysis.md, and satisfy them with actual history at the 18-month renewal.

  • Certification question
    • 5230 §3.1.2: "Do you have documented roles and responsibilities for your open source program?"
    • 18974 §4.1.2: "Do you have documented roles and responsibilities for your open source security assurance program?"
  • Agent in charge: 02-organization-designer

G1.4 — Establishing a training program [Common]

ISO/IEC 5230 §3.1.2 · ISO/IEC 18974 §4.1.2 (education and training aspects)

Build and continuously maintain staff competency; both standards require evidence of training completion.

Evidence IDContentDeliverable file
5230 §3.1.2.1 · 18974 §4.1.2.1List of roles and responsibilitiesoutput/organization/raci-matrix.md
5230 §3.1.2.3 · 18974 §4.1.2.4Evidence of competency assessmentoutput/training/completion-tracker.md
  • Certification question
    • 5230 §3.1.2: "Do you have documented evidence that each program participant has completed the necessary training?"
    • 18974 §4.1.2: "Do you have documented evidence that each program participant has the necessary competence for security assurance?"
  • Agent in charge: 06-training-manager

G1.5 — Defining the program scope [Common]

ISO/IEC 5230 §3.1.4 · ISO/IEC 18974 §4.1.4

Clarifying the target software and products enables efficient resource allocation.

Evidence IDContentDeliverable file
5230 §3.1.4.1 · 18974 §4.1.4.1Program scope and limitations documentoutput/policy/oss-policy.md
18974 §4.1.4.2Performance metricsoutput/policy/oss-policy.md
18974 §4.1.4.3Evidence of continuous improvement ⚠️output/conformance/gap-analysis.md
§4.1.4.3 at initial certification

There is no improvement history at first certification. Record the initial gap analysis run itself in gap-analysis.md as one audit record; at the 18-month renewal, two or more records will satisfy this item.

  • Certification question
    • 5230 §3.1.4: "Is the scope of your open source program documented?"
    • 18974 §4.1.4: "Is the scope of your open source security assurance program documented?"
  • Agent in charge: 03-policy-generator

G1.6 — Establishing procedures to review license obligations [5230]

ISO/IEC 5230 §3.1.5

Prevent license violations before distribution; covers obligations such as copyleft source-code disclosure.

Evidence IDContentDeliverable file
5230 §3.1.5.1Procedures for reviewing and recording the obligations, restrictions, and rights of each identified licenseoutput/process/usage-approval.md
  • Certification question
    • 5230 §3.1.5: "Do you have a documented procedure to review and record the obligations, restrictions, and rights granted by each identified license?"
  • Agent in charge: 04-process-designer

G1.7 — Program participant awareness records [Common]

ISO/IEC 5230 §3.1.3 · ISO/IEC 18974 §4.1.3

Document, per person and role, that each participant understands the policy, the goals, and how to contribute; this is key evidence during an audit.

Evidence IDContentDeliverable file
5230 §3.1.3.1 · 18974 §4.1.3.1Evidence assessing participant awareness of the program goals, ways to contribute, and impact of non-complianceoutput/training/completion-tracker.md
  • Certification question
    • 5230 §3.1.3: "Do you have documented evidence that your program participants are aware of your open source policy?"
    • 18974 §4.1.3: "Do you have documented evidence that your program participants are aware of your open source security assurance policy?"
  • Agent in charge: 06-training-manager


G2.1 — Establishing roles and responsibilities (RACI) [Common]

ISO/IEC 5230 §3.2.2 · ISO/IEC 18974 §4.2.2

Clarify who performs, approves, and reviews open source activities; prevent gaps in ownership.

Evidence IDContentDeliverable file
5230 §3.2.2.1 · 18974 §4.2.2.1Document naming the owner/group/job title for each roleoutput/organization/raci-matrix.md
5230 §3.2.2.2 · 18974 §4.2.2.2Confirmation of adequate role staffing and budgetoutput/organization/raci-matrix.md
5230 §3.2.2.3Method for accessing legal counsel on license complianceoutput/organization/role-definition.md
5230 §3.2.2.4 · 18974 §4.2.2.4Internal responsibility assignment procedureoutput/organization/raci-matrix.md
5230 §3.2.2.5Procedure for reviewing and correcting license non-compliance casesoutput/process/usage-approval.md, output/process/distribution-checklist.md
18974 §4.2.2.3Identification of the expertise available to resolve vulnerabilitiesoutput/organization/role-definition.md
  • Certification question
    • 5230 §3.2.2: "Do you have a documented list of roles and responsibilities with personnel assigned to each role?"
    • 18974 §4.2.2: "Do you have a process for assigning responsibilities for handling open source security vulnerabilities?"
  • Agent in charge: 02-organization-designer

G2.2 — Operating channels for receiving external inquiries [Common]

ISO/IEC 5230 §3.2.1 · ISO/IEC 18974 §4.2.1

An official channel is required so third parties can request fulfillment of license obligations and report security vulnerabilities.

Evidence IDContentDeliverable file
5230 §3.2.1.1 · 18974 §4.2.1.1Public channel through which third parties can inquireoutput/organization/role-definition.md
5230 §3.2.1.2 · 18974 §4.2.1.2Internal response procedure for third-party inquiriesoutput/process/inquiry-response.md, output/process/vulnerability-response.md
  • Certification question
    • 5230 §3.2.1: "Do you have a publicly visible contact method for open source compliance inquiries?"
    • 18974 §4.2.1: "Do you have a publicly visible contact method for open source vulnerability reporting?"
  • Agent in charge: 02-organization-designer, 04-process-designer

G2.3 — Operating an awareness program [Common]

ISO/IEC 5230 §3.1.3 · ISO/IEC 18974 §4.1.3

Compliance is only effective when every member knows and follows the policy.

Evidence IDContentDeliverable file
5230 §3.1.3.1 · 18974 §4.1.3.1Evidence of participant awareness assessment (including goals, contribution, and impact of non-compliance)output/training/resources.md, output/training/completion-tracker.md
  • Certification question
    • 5230 §3.1.3: "Do you have documented evidence that your program participants are aware of your open source policy?"
    • 18974 §4.1.3: "Do you have documented evidence that your program participants are aware of your open source security assurance policy?"
  • Agent in charge: 06-training-manager

G3-L: License compliance (ISO/IEC 5230 focus)


G3L.1 — License identification and classification [5230]

ISO/IEC 5230 §3.3.1 · §3.3.2

Identify the license status of each component from the SBOM; flag copyleft risk.

Evidence IDContentDeliverable file
5230 §3.3.1.1Procedure for identifying, tracking, reviewing, approving, and archiving the SBOMoutput/process/usage-approval.md
5230 §3.3.1.2Component records (evidence of procedural compliance)output/sbom/[project].cdx.json
5230 §3.3.2.1Procedure for handling license use casesoutput/sbom/license-report.md, output/sbom/copyleft-risk.md
  • Certification question
    • 5230 §3.3.1: "Do you have a process for creating and managing a bill of materials for each supply software release?"
    • 5230 §3.3.2: "Do you have a documented procedure for handling the common open source license use cases for the components in your supply software?"
  • Agent in charge: 05-sbom-analyst

G3L.2 — Fulfilling license obligations [5230]

ISO/IEC 5230 §3.3.2

Fulfill copyleft license obligations such as GPL, LGPL, and AGPL; maintain an Approved License List.

Evidence IDContentDeliverable file
5230 §3.3.2.1Procedure for handling the license use cases of each open source componentoutput/process/distribution-checklist.md, output/policy/license-allowlist.md
  • Certification question
    • 5230 §3.3.2: "Do you have a documented procedure for handling the common open source license use cases for the components in your supply software?"
  • Agent in charge: 04-process-designer

G3L.3 — Generating compliance artifacts [5230]

ISO/IEC 5230 §3.4.1

Obligation to provide, at distribution time, the files that demonstrate fulfillment of legal obligations, such as attribution notices and source code.

Evidence IDContentDeliverable file
5230 §3.4.1.1Procedure for preparing and distributing compliance artifactsoutput/sbom/license-report.md
5230 §3.4.1.2Procedure for archiving compliance artifacts and records of fulfillmentoutput/sbom/license-report.md
  • Certification question
    • 5230 §3.4.1: "Do you have a process for creating the necessary compliance artifacts?"
  • Agent in charge: 05-sbom-analyst

G3L.4 — Establishing an open source contribution policy [5230]

ISO/IEC 5230 §3.5.1

Prevents IP leakage and license-contamination risk when contributing upstream.

Evidence IDContentDeliverable file
5230 §3.5.1.1Open source contribution policyoutput/policy/oss-policy.md
5230 §3.5.1.3Contribution policy awareness procedureoutput/training/curriculum.md
  • Certification question
    • 5230 §3.5.1: "Do you have a policy for open source community participation?"
  • Agent in charge: 03-policy-generator

G3L.5 — Process for verifying that license obligations are met [5230]

ISO/IEC 5230 §3.4.1

Verify before distribution that all license obligations (source-code disclosure, inclusion of attribution notices, and so on) have actually been met; acts as a release approval gate.

Evidence IDContentDeliverable file
5230 §3.4.1.1Procedure for preparing and distributing compliance artifactsoutput/process/distribution-checklist.md
5230 §3.4.1.2Procedure for archiving compliance artifacts and records of fulfillmentoutput/process/distribution-checklist.md
  • Certification question
    • 5230 §3.4.1: "Do you have a process to ensure compliance artifacts accompany each distribution?"
  • Agent in charge: 04-process-designer

G3L.6 — Operating an open source contribution process [5230]

ISO/IEC 5230 §3.5.1

Concrete procedures for implementing the policy (G3L.4): the contribution review, approval, and submission workflow. Policy alone cannot govern actual contributions.

Evidence IDContentDeliverable file
5230 §3.5.1.2Open source contribution management procedureoutput/policy/oss-policy.md, output/process/contribution-process.md (conditional)
  • Certification question
    • 5230 §3.5.1: "Do you have a process for contributing to open source projects?"
  • Agent in charge: 03-policy-generator, 04-process-designer (conditional)

G3-S: Security assurance (ISO/IEC 18974 focus)


G3S.1 — Identifying known vulnerabilities (CVE scan) [18974]

ISO/IEC 18974 §4.3.2 · §4.1.5

Failing to identify CVEs invites security incidents and legal liability; this is an EO 14028 requirement.

Evidence IDContentDeliverable file
18974 §4.1.5.1Standard vulnerability response procedure, including vulnerability detection methodsoutput/process/vulnerability-response.md
18974 §4.3.2.1Vulnerability detection and resolution procedureoutput/vulnerability/cve-report.md
18974 §4.3.2.2Record of vulnerabilities and actions takenoutput/vulnerability/cve-report.md
  • Certification question
    • 18974 §4.3.2: "Do you have a process for identifying, tracking, and remediating known vulnerabilities in supply software?"
  • Agent in charge: 05-vulnerability-analyst

G3S.2 — Vulnerability tracking and status management [18974]

ISO/IEC 18974 §4.3.2 · §4.1.5

Continuously track identified vulnerabilities until remediation is complete; prevent items from being missed or left unattended.

Evidence IDContentDeliverable file
18974 §4.1.5.1Standard response procedure, including how to follow up on vulnerabilitiesoutput/process/vulnerability-response.md
18974 §4.3.2.1Vulnerability detection and resolution procedureoutput/vulnerability/cve-report.md
18974 §4.3.2.2Record of vulnerabilities and actions takenoutput/vulnerability/cve-report.md
  • Certification question
    • 18974 §4.3.2: "Do you have a process for identifying, tracking, and remediating known vulnerabilities in supply software?"
  • Agent in charge: 05-vulnerability-analyst

G3S.3 — CVE risk scoring (CVSS) [18974]

ISO/IEC 18974 §4.3.2

Prioritize by CVSS score; allocate resources efficiently.

Evidence IDContentDeliverable file
18974 §4.3.2.1Vulnerability handling procedure, including risk/impact score assignmentoutput/vulnerability/cve-report.md
18974 §4.3.2.2Record of identified vulnerabilities and risk scoresoutput/vulnerability/cve-report.md
  • Certification question
    • 18974 §4.3.2: "Do you have a process for identifying, tracking, and remediating known vulnerabilities in supply software?"
  • Agent in charge: 05-vulnerability-analyst

G3S.4 — Vulnerability response and patching procedures [18974]

ISO/IEC 18974 §4.3.2 · §4.1.5

A system for rapidly patching, upgrading, or mitigating discovered vulnerabilities.

Evidence IDContentDeliverable file
18974 §4.1.5.1Standard response procedure, including appropriate action methods for each risk leveloutput/vulnerability/remediation-plan.md
18974 §4.3.2.1Vulnerability resolution procedureoutput/vulnerability/remediation-plan.md
18974 §4.3.2.2Record of actions takenoutput/vulnerability/remediation-plan.md
  • Certification question
    • 18974 §4.1.5: "Do you have a documented procedure for handling known vulnerabilities in open source components?"
  • Agent in charge: 05-vulnerability-analyst

G3S.5 — Security artifact delivery process [18974, Supply Chain]

ISO/IEC 18974 §4.3.1

Formal procedures for delivering security deliverables such as the SBOM and CVE reports to supply chain partners and customers; addresses the EO 14028 and EU CRA disclosure obligations.

Evidence IDContentDeliverable file
18974 §4.3.1.1Procedure for continuously recording the SBOM throughout the supplied software life cycleoutput/sbom/sbom-sharing-template.md
18974 §4.3.1.2Component records (evidence of procedural compliance)output/sbom/[project].cdx.json
  • Certification question
    • 18974 §4.3.1: "Do you have a documented process for creating and maintaining a SBOM for supply software throughout its lifecycle?"
  • Agent in charge: 05-sbom-management

G3S.6 — Process for verifying that security obligations are met [18974]

ISO/IEC 18974 §4.3.2

Procedure to verify that the response, patch, and mitigation actions for identified and tracked vulnerabilities were actually completed; confirms real implementation rather than a mere declaration.

Evidence IDContentDeliverable file
18974 §4.3.2.1Procedure including verification that vulnerability resolution is completeoutput/vulnerability/remediation-plan.md
18974 §4.3.2.2Record of completed actionsoutput/vulnerability/remediation-plan.md
  • Certification question
    • 18974 §4.3.2: "Do you have a process for identifying, tracking, and remediating known vulnerabilities in supply software?"
  • Agent in charge: 05-vulnerability-analyst

G3-B: SBOM and supply chain (common)


G3B.1 — Creating an SBOM (CycloneDX/SPDX) [Common, Supply Chain]

ISO/IEC 5230 §3.3.1 · ISO/IEC 18974 §4.3.1

The starting point for component transparency; the input for both license and security analysis.

Evidence IDContentDeliverable file
5230 §3.3.1.1 · 18974 §4.3.1.1Procedure for identifying, tracking, reviewing, approving, and archiving the SBOMoutput/sbom/sbom-commands.sh
5230 §3.3.1.2 · 18974 §4.3.1.2Component records (evidence of procedural compliance)output/sbom/[project].cdx.json
  • Certification question
    • 5230 §3.3.1: "Do you have a process for creating and managing a bill of materials for each supply software release?"
    • 18974 §4.3.1: "Do you have a documented process for creating and maintaining a SBOM for supply software throughout its lifecycle?"
  • Agent in charge: 05-sbom-guide

G3B.2 — SBOM management and maintenance [Common, Supply Chain]

ISO/IEC 5230 §3.3.1 · ISO/IEC 18974 §4.3.1

Keep the SBOM current on every release and update; integrate it with configuration management.

Evidence IDContentDeliverable file
5230 §3.3.1.1 · 18974 §4.3.1.1SBOM life cycle management procedureoutput/sbom/sbom-management-plan.md
5230 §3.3.1.2 · 18974 §4.3.1.2Up-to-date component recordsoutput/sbom/[project].cdx.json
  • Certification question
    • 5230 §3.3.1: "Do you have a process for creating and managing a bill of materials for each supply software release?"
    • 18974 §4.3.1: "Do you have a documented process for creating and maintaining a SBOM for supply software throughout its lifecycle?"
  • Agent in charge: 05-sbom-management

G3B.3 — Sharing the SBOM (with supply chain partners) [Supply Chain, Regulation]

ISO/IEC 18974 §4.3.1

Pass transparency down the supply chain; addresses the CISA SBOM minimum elements and EU CRA supply chain disclosure obligations.

Evidence IDContentDeliverable file
18974 §4.3.1.1Life cycle recording procedure, including sharing the SBOM with supply chain partnersoutput/sbom/sbom-sharing-template.md
18974 §4.3.1.2Component recordsoutput/sbom/[project].cdx.json
  • Certification question
    • 18974 §4.3.1: "Do you have a documented process for creating and maintaining a SBOM for supply software throughout its lifecycle?"
  • Agent in charge: 05-sbom-management

G3B.4 — Continuous monitoring of supply chain vulnerabilities [Supply Chain]

ISO/IEC 18974 §4.3.2

When a new CVE is disclosed, immediately identify which supply chain components are affected.

Evidence IDContentDeliverable file
18974 §4.3.2.1Response procedure, including methods for analyzing new vulnerabilities after releaseoutput/sbom/sbom-management-plan.md
18974 §4.3.2.2Record of vulnerabilities and actions takenoutput/sbom/sbom-management-plan.md
  • Certification question
    • 18974 §4.3.2: "Do you have a process for continuously monitoring supply software components for new vulnerabilities?"
  • Agent in charge: 05-sbom-management

G4: Declaring and maintaining compliance


G4.1 — ISO/IEC 5230 self-certification declaration [5230]

ISO/IEC 5230 §3.6.1

Official declaration of license compliance capability; earns the trust of supply chain partners.

Evidence IDContentDeliverable file
5230 §3.6.1.1Document confirming that the program in §3.1.4 meets all requirements of this specificationoutput/conformance/declaration-draft.md
  • Certification question
    • 5230 §3.6.1: "Do you confirm that your program meets all the requirements of this specification?"
  • Agent in charge: 07-conformance-preparer

G4.2 — ISO/IEC 18974 self-certification declaration [18974]

ISO/IEC 18974 §4.4.1

Official declaration of security assurance capability; evidence for EO 14028 and EU CRA compliance.

Evidence IDContentDeliverable file
18974 §4.4.1.1Document confirming that the program in §4.1.4 meets all requirements of this specificationoutput/conformance/declaration-draft.md
  • Certification question
    • 18974 §4.4.1: "Do you confirm that your security assurance program meets all the requirements of this specification?"
  • Agent in charge: 07-conformance-preparer

G4.3 — Managing the certification validity period (18 months) [Common]

ISO/IEC 5230 §3.6.2 · ISO/IEC 18974 §4.4.2

Both standards require re-declaration every 18 months; this avoids automatic expiration.

Evidence IDContentDeliverable file
5230 §3.6.2.1 · 18974 §4.4.2.1Document confirming that all requirements have been met within 18 months of obtaining conformanceoutput/conformance/submission-guide.md
  • Certification question
    • 5230 §3.6.2: "Do you have a process to confirm the program meets the requirements at least once every 18 months?"
    • 18974 §4.4.2: "Do you have a process to confirm the security assurance program meets the requirements at least once every 18 months?"
  • Agent in charge: 07-conformance-preparer

G4.4 — Regular gap analysis and policy updates [Common]

ISO/IEC 5230 §3.6.2 · ISO/IEC 18974 §4.4.2

Evolve the system as the technical and regulatory environment changes; required before a renewal declaration.

Evidence IDContentDeliverable file
5230 §3.6.2.1 · 18974 §4.4.2.1Document confirming re-satisfaction of requirements after renewaloutput/conformance/gap-analysis.md
  • Certification question
    • 5230 §3.6.2: "Do you have a process to confirm the program meets the requirements at least once every 18 months?"
    • 18974 §4.4.2: "Do you have a process to confirm the security assurance program meets the requirements at least once every 18 months?"
  • Agent in charge: 07-conformance-preparer

G4.5 — Confirming vulnerability remediation before distribution [18974]

ISO/IEC 18974 §4.4.1 · §4.3.2

Confirm before distribution that each identified vulnerability has been remediated or recorded as needing no action. ISO/IEC 18974 does not require zero known vulnerabilities; it requires that the detect/assess/remediate/record process runs and that its results are documented. Residual CVEs are acceptable as long as the decision and the record exist.

Evidence IDContentDeliverable file
18974 §4.4.1.1Document confirming that distributed software fully meets the requirementsoutput/conformance/declaration-draft.md
18974 §4.3.2.2Record of completed vulnerability actionsoutput/vulnerability/cve-report.md
  • Certification question
    • 18974 §4.4.1: "Do you confirm that your security assurance program meets all the requirements of this specification?"
    • 18974 §4.3.2: "Do you have a process for identifying, tracking, and remediating known vulnerabilities in supply software?"
  • Agent in charge: 07-conformance-preparer