Conformance Output Best Practice
These are completed examples of the three deliverables generated by the conformance-preparer agent.
This agent asks no questions: it reads the existing deliverables in your output/ folder and generates the gap analysis and declaration automatically.
Reference shortcut: Self-Certification chapter guide
Gap Analysis Report
Generating agent: 07-conformance-preparer | Save path: output/conformance/gap-analysis.md
Report type: Gap Analysis (ISO/IEC 5230 + ISO/IEC 18974) Created: 2026-03-23 Target project: TechUnicorn open source program Tools used: trustedoss agents/07-conformance-preparer
1. Summary
- Scope: ISO/IEC 5230:2020 (25 items) + ISO/IEC 18974:2023 (25 items) = 50 evidence items in total
- ISO/IEC 5230: satisfied ✅ 22 / partially satisfied 3 / not satisfied ❌ 0
- ISO/IEC 18974: satisfied ✅ 18 / partially satisfied 7 / not satisfied ❌ 0
- No ❌ not-satisfied (certification-blocking) items → ready to declare Self-Certification
- Immediate action recommended: enter real names of Program Managers (raci-matrix.md), start training completion (completion-tracker.md)
- The 3 time-based partially satisfied items are normal at initial certification (satisfied at the 18-month renewal)
2. ISO/IEC 5230:2020 Status by Item
| Item ID | Summary | Verdict | Evidence deliverables |
|---|---|---|---|
| 3.1.1.1 | Documented open source policy | ✅ | Open Source Policy |
| 3.1.1.2 | Policy dissemination procedure | ✅ | Open Source Policy §7, Open Source Training Curriculum |
| 3.1.2.1 | List of roles and responsibilities | ✅ | Open Source Roles and Responsibilities Definition §1 |
| 3.1.2.2 | Competency description per role | ✅ | Open Source Roles and Responsibilities Definition §2 |
| 3.1.2.3 | Competency assessment evidence | 🔶 | Training Completion Tracking Sheet (forms complete, actual completion not started) |
| 3.1.3.1 | Participant awareness assessment evidence | 🔶 | Open Source Training Curriculum + Training Completion Tracking Sheet (training not started) |
| 3.1.4.1 | Program scope | ✅ | Open Source Policy §1 |
| 3.1.5.1 | License obligations review procedure | ✅ | Open source use approval process §4, Approved License List |
| 3.2.1.1 | Public channel for external inquiries | ✅ | Open Source Roles and Responsibilities Definition §3 (opensource@techunicorn.example) |
| 3.2.1.2 | Internal response procedure for external inquiries | ✅ | Open Source Roles and Responsibilities Definition §3, Open source use approval process |
| 3.2.2.1 | Document naming role assignees | 🔶 | Open Source RACI Matrix (role structure complete, real names not entered) |
| 3.2.2.2 | Role staffing and budget confirmation | ✅ | Open Source RACI Matrix §Budget allocation status |
| 3.2.2.3 | Method for accessing legal expertise | ✅ | Open Source Roles and Responsibilities Definition §4 |
| 3.2.2.4 | Internal responsibility assignment procedure | ✅ | Open Source RACI Matrix §Internal responsibility assignment procedure |
| 3.2.2.5 | Non-compliance case review and remediation procedure | ✅ | Open Source RACI Matrix §Non-compliance case review procedure, Open Source Policy §8 |
| 3.3.1.1 | SBOM management procedure | ✅ | SBOM Management Plan, Open source use approval process §6 |
| 3.3.1.2 | Component records (SBOM file) | ✅ | output/sbom/java-vulnerable.cdx.json |
| 3.3.2.1 | License use case handling procedure | ✅ | SBOM License Analysis Report, Copyleft Risk Report, Open source use approval process |
| 3.4.1.1 | Compliance deliverable preparation and distribution | ✅ | Pre-deployment license compliance checklist |
| 3.4.1.2 | Compliance deliverable archiving procedure | ✅ | Pre-deployment license compliance checklist §5 |
| 3.5.1.1 | Open source contribution policy | ✅ | Open Source Policy §5 |
| 3.5.1.2 | Open source contribution management procedure | ✅ | Open Source Policy §5 |
| 3.5.1.3 | Contribution policy awareness procedure | ✅ | Open Source Policy §7 |
| 3.6.1.1 | Document confirming all requirements are met | ✅ | Gap Analysis Report (this document) |
| 3.6.2.1 | Document confirming requirements met within 18 months | ✅ | Open Source Compliance Self-Certification Declaration |
ISO/IEC 5230 subtotal: ✅ 22 / partially satisfied 3 / ❌ 0
3. ISO/IEC 18974:2023 Status by Item
| Item ID | Summary | Verdict | Evidence deliverables |
|---|---|---|---|
| 4.1.1.1 | Security assurance policy | ✅ | Open Source Policy §4 |
| 4.1.1.2 | Policy dissemination procedure | ✅ | Open Source Policy §7, Open Source Training Curriculum |
| 4.1.2.1 | List of roles and responsibilities | ✅ | Open Source Roles and Responsibilities Definition §1 |
| 4.1.2.2 | Competency description per role | ✅ | Open Source Roles and Responsibilities Definition §2 |
| 4.1.2.3 | Participant list and roles | 🔶 | Open Source RACI Matrix §Assignees by role (real names not entered) |
| 4.1.2.4 | Competency assessment evidence | 🔶 | Training Completion Tracking Sheet (forms complete, actual completion not started) |
| 4.1.2.5 | Evidence of periodic review and change | 🔶 | Open Source Policy §9 (review plan in place, no history accumulated yet) ※time-based |
| 4.1.2.6 | Assignee verifying alignment with internal best practices | 🔶 | Open Source Roles and Responsibilities Definition §6 (assignee designated, review scheduled for 2026-12-31) ※time-based |
| 4.1.3.1 | Participant awareness assessment evidence | 🔶 | Open Source Training Curriculum + Training Completion Tracking Sheet (training not started) |
| 4.1.4.1 | Program scope document | ✅ | Open Source Policy §1 |
| 4.1.4.2 | Performance metrics | ✅ | Open Source Policy §3 (5 KPI items) |
| 4.1.4.3 | Evidence of continual improvement (audit history) | 🔶 | Gap Analysis Report (this document, first audit record) ※time-based |
| 4.1.5.1 | Standard vulnerability response procedure | ✅ | Vulnerability response procedures (all 8 methods included) |
| 4.2.1.1 | Public channel for external vulnerability reports | ✅ | Open Source Roles and Responsibilities Definition §3 (security@techunicorn.example) |
| 4.2.1.2 | Internal response procedure for external inquiries | ✅ | Vulnerability response procedures §7 |
| 4.2.2.1 | Document naming role assignees | 🔶 | Open Source RACI Matrix (role structure complete, real names not entered) |
| 4.2.2.2 | Role staffing and budget confirmation | ✅ | Open Source RACI Matrix §Budget allocation status |
| 4.2.2.3 | Stated expertise in vulnerability resolution | ✅ | Open Source Roles and Responsibilities Definition §5 (security team, KrCERT) |
| 4.2.2.4 | Internal responsibility assignment procedure | ✅ | Open Source RACI Matrix §Internal responsibility assignment procedure |
| 4.3.1.1 | Procedure for continuously recording the SBOM lifecycle | ✅ | SBOM Management Plan |
| 4.3.1.2 | Component records (SBOM file) | ✅ | output/sbom/java-vulnerable.cdx.json |
| 4.3.2.1 | Vulnerability detection and resolution procedure | ✅ | Vulnerability response procedures + Vulnerability Remediation Plan |
| 4.3.2.2 | Records of vulnerabilities and actions | ✅ | Vulnerability Analysis Report (5 CVEs recorded) + Vulnerability Remediation Plan |
| 4.4.1.1 | Document confirming all requirements are met | ✅ | Gap Analysis Report (this document) |
| 4.4.2.1 | Document confirming requirements met within 18 months | ✅ | Open Source Compliance Self-Certification Declaration |
ISO/IEC 18974 subtotal: ✅ 18 / partially satisfied 7 / ❌ 0
4. Actions
Medium — Enter real names of Program Managers (recommended within 1 month)
- Target:
output/organization/raci-matrix.md§Assignees by role - Problem: The "(enter assignee name)" placeholders have not been replaced with real names
- Affected items: 3.2.2.1, 4.1.2.3, 4.2.2.1
- Action: Enter actual names in the assignees-by-role table in raci-matrix.md
- Estimated time: 10 minutes
Medium — Start training completion (2026-Q2 execution plan already in place)
- Target:
output/training/completion-tracker.md - Problem: The training plan and forms are complete, but actual completion stands at 0 people (0%)
- Affected items: 3.1.2.3, 3.1.3.1, 4.1.2.4, 4.1.3.1
- Action: Run the training from 2026-Q2 according to curriculum.md §Training Schedule Plan
- Operations, 100 people: online training starts during 2026-05
- Managers, 10 people: offline group session in 2026-06
- Developers, 1,000 people: staged online start across 2026-Q2~Q3
- Estimated time: plan already established; now in the execution stage
Low — Confirm and complete budget information
- Target:
output/organization/raci-matrix.md§Budget allocation status - Problem: The open source tooling budget and external training budget entries still read "(fill in after confirmation)"
- Affected item: 3.2.2.2 (currently judged ✅, but completing this entry is recommended)
- Action: Enter the actual budget allocation figures
- Estimated time: 30 minutes
5. Handling Time-Based Items (Normal at Initial Certification)
Evidence for the 3 items below cannot exist at the time of initial certification. They are treated as partially satisfied and convert to satisfied at the 18-month renewal.
| Item ID | Current action | Condition for conversion to satisfied |
|---|---|---|
| 18974 §4.1.2.5 periodic review evidence | oss-policy.md §9 records "Next review date: 2027-03-23" | At least 1 actual review record accumulated |
| 18974 §4.1.2.6 best-practice alignment verification | role-definition.md §6 records the assignee and the first review date (2026-12-31) | At least 1 recorded review result |
| 18974 §4.1.4.3 continual improvement evidence | This gap analysis (2026-03-23) is recorded as the first audit record | At least 2 audit records |
6. Renewal Schedule
| Date | Task |
|---|---|
| 2026-06-30 | Update completion-tracker.md after manager training is complete |
| 2026-09-30 | First developer group (250 people) completes offline training |
| 2026-12-31 | Perform the 18974 §4.1.2.6 best-practice alignment review → update gap-analysis.md |
| 2027-03-23 | Annual policy review (oss-policy.md §9) → update gap-analysis.md |
| 2027-09-23 | Self-Certification validity expires (declaration date + 18 months) → re-declare |
Open Source Compliance Self-Certification Declaration
Generating agent: 07-conformance-preparer | Save path: output/conformance/declaration-draft.md
Declaration Information
| Item | Content |
|---|---|
| Declaring company | TechUnicorn |
| Declaring Program Manager | DevOps team open source Program Manager |
| Contact email | opensource@techunicorn.example |
| Declaration date | 2026-03-23 |
| Validity period | 2026-03-23 ~ 2027-09-23 (18 months) |
| Re-declaration due date | 2027-09-23 |
Applicable Standards
- ISO/IEC 5230:2020 — OpenChain License Compliance Specification
- ISO/IEC 18974:2023 — OpenChain Security Assurance Specification
Scope
All software developed, distributed, and operated by TechUnicorn:
- Distribution methods: SaaS, app stores (iOS/Android), embedded (on-device), internal systems
- Applies to: everyone involved in open source use, including developers, managers, and operations teams
- Program name: TechUnicorn Open Source Compliance Program v1.0
ISO/IEC 5230:2020 Checklist
We confirm and declare the status of the 25 evidence items below. Partially satisfied items have completed plans in place and convert to satisfied once training completion and time-based evidence are secured.
| Item ID | Content | Status | Deliverables |
|---|---|---|---|
| 3.1.1.1 | Documented open source policy | ✅ | Open Source Policy |
| 3.1.1.2 | Policy dissemination procedure | ✅ | Open Source Policy §7, Open Source Training Curriculum |
| 3.1.2.1 | List of roles and responsibilities | ✅ | Open Source Roles and Responsibilities Definition |
| 3.1.2.2 | Competency description per role | ✅ | Open Source Roles and Responsibilities Definition §2 |
| 3.1.2.3 | Competency assessment evidence | 🔶 | Training Completion Tracking Sheet (completion about to begin) |
| 3.1.3.1 | Participant awareness assessment evidence | 🔶 | Open Source Training Curriculum + Training Completion Tracking Sheet |
| 3.1.4.1 | Program scope document | ✅ | Open Source Policy §1 |
| 3.1.5.1 | License obligations review procedure | ✅ | Open source use approval process §4, Approved License List |
| 3.2.1.1 | Public channel for external inquiries | ✅ | Open Source Roles and Responsibilities Definition §3 |
| 3.2.1.2 | Internal response procedure for external inquiries | ✅ | Open Source Roles and Responsibilities Definition §3 |
| 3.2.2.1 | Document naming role assignees | 🔶 | Open Source RACI Matrix (real-name entry in progress) |
| 3.2.2.2 | Role staffing and budget confirmation | ✅ | Open Source RACI Matrix §Budget allocation status |
| 3.2.2.3 | Method for accessing legal expertise | ✅ | Open Source Roles and Responsibilities Definition §4 |
| 3.2.2.4 | Internal responsibility assignment procedure | ✅ | Open Source RACI Matrix §Internal responsibility assignment procedure |
| 3.2.2.5 | Non-compliance case review and remediation procedure | ✅ | Open Source RACI Matrix §Non-compliance case review procedure |
| 3.3.1.1 | SBOM management procedure | ✅ | SBOM Management Plan |
| 3.3.1.2 | Component records (SBOM file) | ✅ | output/sbom/java-vulnerable.cdx.json |
| 3.3.2.1 | License use case handling procedure | ✅ | SBOM License Analysis Report, Open source use approval process |
| 3.4.1.1 | Compliance deliverable preparation and distribution | ✅ | Pre-deployment license compliance checklist |
| 3.4.1.2 | Compliance deliverable archiving procedure | ✅ | Pre-deployment license compliance checklist §5 |
| 3.5.1.1 | Open source contribution policy | ✅ | Open Source Policy §5 |
| 3.5.1.2 | Open source contribution management procedure | ✅ | Open Source Policy §5 |
| 3.5.1.3 | Contribution policy awareness procedure | ✅ | Open Source Policy §7 |
| 3.6.1.1 | Document confirming all requirements are met | ✅ | Gap Analysis Report |
| 3.6.2.1 | Confirmation of requirements met within 18 months | ✅ | Open Source Compliance Self-Certification Declaration (this document) |
ISO/IEC 18974:2023 Checklist
We confirm and declare the status of the 25 evidence items below. Partially satisfied items have completed plans in place and convert to satisfied once training completion and time-based evidence are secured.
| Item ID | Content | Status | Deliverables |
|---|---|---|---|
| 4.1.1.1 | Documented security assurance policy | ✅ | Open Source Policy §4 |
| 4.1.1.2 | Policy dissemination procedure | ✅ | Open Source Policy §7, Open Source Training Curriculum |
| 4.1.2.1 | List of roles and responsibilities | ✅ | Open Source Roles and Responsibilities Definition §1 |
| 4.1.2.2 | Competency description per role | ✅ | Open Source Roles and Responsibilities Definition §2 |
| 4.1.2.3 | Participant list and roles | 🔶 | Open Source RACI Matrix (real-name entry in progress) |
| 4.1.2.4 | Competency assessment evidence | 🔶 | Training Completion Tracking Sheet (completion about to begin) |
| 4.1.2.5 | Evidence of periodic review and change | 🔶 | Open Source Policy §9 (review plan in place, history to be accumulated) |
| 4.1.2.6 | Assignee verifying alignment with internal best practices | 🔶 | Open Source Roles and Responsibilities Definition §6 (assignee designated, review scheduled for 2026-12-31) |
| 4.1.3.1 | Participant awareness assessment evidence | 🔶 | Open Source Training Curriculum + Training Completion Tracking Sheet |
| 4.1.4.1 | Program scope document | ✅ | Open Source Policy §1 |
| 4.1.4.2 | Performance metrics | ✅ | Open Source Policy §3 (5 KPI items) |
| 4.1.4.3 | Evidence of continual improvement (audit history) | 🔶 | Gap Analysis Report (first audit record) |
| 4.1.5.1 | Standard vulnerability response procedure | ✅ | Vulnerability response procedures |
| 4.2.1.1 | Public channel for external vulnerability reports | ✅ | Open Source Roles and Responsibilities Definition §3 (security@techunicorn.example) |
| 4.2.1.2 | Internal response procedure for external inquiries | ✅ | Vulnerability response procedures §7 |
| 4.2.2.1 | Document naming role assignees | 🔶 | Open Source RACI Matrix (real-name entry in progress) |
| 4.2.2.2 | Role staffing and budget confirmation | ✅ | Open Source RACI Matrix §Budget allocation status |
| 4.2.2.3 | Stated expertise in vulnerability resolution | ✅ | Open Source Roles and Responsibilities Definition §5 |
| 4.2.2.4 | Internal responsibility assignment procedure | ✅ | Open Source RACI Matrix §Internal responsibility assignment procedure |
| 4.3.1.1 | Procedure for continuously recording the SBOM lifecycle | ✅ | SBOM Management Plan |
| 4.3.1.2 | Component records (SBOM file) | ✅ | output/sbom/java-vulnerable.cdx.json |
| 4.3.2.1 | Vulnerability detection and resolution procedure | ✅ | Vulnerability response procedures + Vulnerability Remediation Plan |
| 4.3.2.2 | Records of vulnerabilities and actions | ✅ | Vulnerability Analysis Report (5 CVEs recorded) + Vulnerability Remediation Plan |
| 4.4.1.1 | Document confirming all requirements are met | ✅ | Gap Analysis Report |
| 4.4.2.1 | Confirmation of requirements met within 18 months | ✅ | Open Source Compliance Self-Certification Declaration (this document) |
Signature
This declaration self-certifies that TechUnicorn operates an open source compliance and security assurance program that satisfies all requirements of ISO/IEC 5230:2020 and ISO/IEC 18974:2023.
| Field | Content |
|---|---|
| Declared by | DevOps team open source Program Manager |
| Approved by | DevOps team leader |
| Declaration date | 2026-03-23 |
| Next re-declaration date | 2027-09-23 |
Note on partially satisfied items: Real-name entry for Program Managers (3.2.2.1, 4.1.2.3, 4.2.2.1) and training completion (3.1.2.3, 4.1.2.4) are in progress and will be completed after the declaration. The time-based items (4.1.2.5, 4.1.2.6, 4.1.4.3) become satisfied at the 18-month renewal.
OpenChain Self-Certification Registration Guide
Generating agent: 07-conformance-preparer | Save path: output/conformance/submission-guide.md
Overview
TechUnicorn registers its ISO/IEC 5230:2020 (license compliance) and ISO/IEC 18974:2023 (security assurance) Self-Certification on the official OpenChain project site and declares it publicly.
| Item | Content |
|---|---|
| Registration site | https://www.openchainproject.org/conformance |
| Declaration type | Self-Certification |
| Applicable standards | ISO/IEC 5230:2020 + ISO/IEC 18974:2023 |
| Validity period | 18 months (2026-03-23 ~ 2027-09-23) |
Preparation Before Registration
Complete the items below before proceeding with registration.
Required actions (recommended before registration)
-
output/organization/raci-matrix.md§Assignees by role — real names entered -
output/organization/appointment-template.md— appointment letter signed - Training completion started — at minimum, the manager course launched (2026-06)
Final deliverable check
- Confirm
output/conformance/gap-analysis.mdexists - Confirm
output/conformance/declaration-draft.mdexists - Confirm all deliverables are up to date
Registration Procedure (Step by Step)
Step 1 — Visit the OpenChain site
- Go to https://www.openchainproject.org/conformance
- Click "Submit Conformance" in the menu at the top or bottom of the page
Step 2 — Select the standards
- Select ISO/IEC 5230 (license compliance)
- Select ISO/IEC 18974 (security assurance)
- Both standards can be submitted at the same time
Step 3 — Enter company information
| Field | Value |
|---|---|
| Company name | TechUnicorn |
| Contact name | Real name of the DevOps team open source Program Manager |
| opensource@techunicorn.example | |
| Country | Korea (South) |
| Website | https://www.techunicorn.example |
Step 4 — Check off the checklist items
Refer to output/conformance/declaration-draft.md and check each item.
ISO/IEC 5230 checklist (25 items):
- Check every item from 3.1.1.1 through 3.6.2.1
- For the partially satisfied items (3.1.2.3, 3.1.3.1, 3.2.2.1), convert them to satisfied where possible (start training completion, enter real names) before submitting; if submitting before conversion, check them with the understanding that their plans are complete
ISO/IEC 18974 checklist (25 items):
- Check every item from 4.1.1.1 through 4.4.2.1
- Among the partially satisfied items, the 3 time-based ones (4.1.2.5, 4.1.2.6, 4.1.4.3) are acceptable at initial certification; convert the rest to satisfied where possible before submitting
Step 5 — Submit and confirm
- After checking all items, click "Submit"
- Confirm receipt of the confirmation email at the address you entered
- TechUnicorn is listed on the official OpenChain registration list
After Registration
Public announcement
After registration, announcing through the channels below is recommended:
- Post the certification status on the company wiki/intranet
- Add an OpenChain certification banner to the company security/compliance page
- Notify major customers/recipients of the certification (builds trust)
Deliverable retention
After OpenChain registration, retain the following evidence:
- A copy of the registration confirmation email
- A screenshot taken at registration time (kept in the
output/conformance/folder) - The signed
declaration-draft.md(signed by the Program Manager and the team leader)
Maintenance Schedule
18-month re-declaration cycle
| When | Task |
|---|---|
| 2026-09-23 (6 months after declaration) | Interim check — verify progress on partially satisfied items |
| 2027-03-23 (12 months after declaration) | Re-run the annual gap analysis, update gap-analysis.md |
| 2027-09-23 (18 months after declaration) | Re-declare — re-register on the OpenChain site |
Ad-hoc update triggers
When any of the following occurs, update the deliverables immediately and re-run the gap analysis:
| Trigger | Deliverables to update |
|---|---|
| Open source policy change | oss-policy.md, gap-analysis.md |
| Program Manager change | role-definition.md, raci-matrix.md |
| New Critical CVE | cve-report.md, remediation-plan.md |
| New product/service launch | sbom/*, distribution-checklist.md |
| New distribution channel | license-allowlist.md, oss-policy.md |
Contacts
| Type | Contact |
|---|---|
| License compliance inquiries | opensource@techunicorn.example |
| Security vulnerability reports | security@techunicorn.example |
| OpenChain project (official) | https://www.openchainproject.org |
This document was prepared to fulfill the ISO/IEC 5230 §3.6.1 and ISO/IEC 18974 §4.4.1 requirements.