Skip to main content

Conformance Output Best Practice

These are completed examples of the three deliverables generated by the conformance-preparer agent. This agent asks no questions: it reads the existing deliverables in your output/ folder and generates the gap analysis and declaration automatically.

Reference shortcut: Self-Certification chapter guide


Gap Analysis Report

info

Generating agent: 07-conformance-preparer | Save path: output/conformance/gap-analysis.md


Report type: Gap Analysis (ISO/IEC 5230 + ISO/IEC 18974) Created: 2026-03-23 Target project: TechUnicorn open source program Tools used: trustedoss agents/07-conformance-preparer


1. Summary

  • Scope: ISO/IEC 5230:2020 (25 items) + ISO/IEC 18974:2023 (25 items) = 50 evidence items in total
  • ISO/IEC 5230: satisfied ✅ 22 / partially satisfied 3 / not satisfied ❌ 0
  • ISO/IEC 18974: satisfied ✅ 18 / partially satisfied 7 / not satisfied ❌ 0
  • No ❌ not-satisfied (certification-blocking) items → ready to declare Self-Certification
  • Immediate action recommended: enter real names of Program Managers (raci-matrix.md), start training completion (completion-tracker.md)
  • The 3 time-based partially satisfied items are normal at initial certification (satisfied at the 18-month renewal)

2. ISO/IEC 5230:2020 Status by Item

Item IDSummaryVerdictEvidence deliverables
3.1.1.1Documented open source policyOpen Source Policy
3.1.1.2Policy dissemination procedureOpen Source Policy §7, Open Source Training Curriculum
3.1.2.1List of roles and responsibilitiesOpen Source Roles and Responsibilities Definition §1
3.1.2.2Competency description per roleOpen Source Roles and Responsibilities Definition §2
3.1.2.3Competency assessment evidence🔶Training Completion Tracking Sheet (forms complete, actual completion not started)
3.1.3.1Participant awareness assessment evidence🔶Open Source Training Curriculum + Training Completion Tracking Sheet (training not started)
3.1.4.1Program scopeOpen Source Policy §1
3.1.5.1License obligations review procedureOpen source use approval process §4, Approved License List
3.2.1.1Public channel for external inquiriesOpen Source Roles and Responsibilities Definition §3 (opensource@techunicorn.example)
3.2.1.2Internal response procedure for external inquiriesOpen Source Roles and Responsibilities Definition §3, Open source use approval process
3.2.2.1Document naming role assignees🔶Open Source RACI Matrix (role structure complete, real names not entered)
3.2.2.2Role staffing and budget confirmationOpen Source RACI Matrix §Budget allocation status
3.2.2.3Method for accessing legal expertiseOpen Source Roles and Responsibilities Definition §4
3.2.2.4Internal responsibility assignment procedureOpen Source RACI Matrix §Internal responsibility assignment procedure
3.2.2.5Non-compliance case review and remediation procedureOpen Source RACI Matrix §Non-compliance case review procedure, Open Source Policy §8
3.3.1.1SBOM management procedureSBOM Management Plan, Open source use approval process §6
3.3.1.2Component records (SBOM file)output/sbom/java-vulnerable.cdx.json
3.3.2.1License use case handling procedureSBOM License Analysis Report, Copyleft Risk Report, Open source use approval process
3.4.1.1Compliance deliverable preparation and distributionPre-deployment license compliance checklist
3.4.1.2Compliance deliverable archiving procedurePre-deployment license compliance checklist §5
3.5.1.1Open source contribution policyOpen Source Policy §5
3.5.1.2Open source contribution management procedureOpen Source Policy §5
3.5.1.3Contribution policy awareness procedureOpen Source Policy §7
3.6.1.1Document confirming all requirements are metGap Analysis Report (this document)
3.6.2.1Document confirming requirements met within 18 monthsOpen Source Compliance Self-Certification Declaration

ISO/IEC 5230 subtotal: ✅ 22 / partially satisfied 3 / ❌ 0


3. ISO/IEC 18974:2023 Status by Item

Item IDSummaryVerdictEvidence deliverables
4.1.1.1Security assurance policyOpen Source Policy §4
4.1.1.2Policy dissemination procedureOpen Source Policy §7, Open Source Training Curriculum
4.1.2.1List of roles and responsibilitiesOpen Source Roles and Responsibilities Definition §1
4.1.2.2Competency description per roleOpen Source Roles and Responsibilities Definition §2
4.1.2.3Participant list and roles🔶Open Source RACI Matrix §Assignees by role (real names not entered)
4.1.2.4Competency assessment evidence🔶Training Completion Tracking Sheet (forms complete, actual completion not started)
4.1.2.5Evidence of periodic review and change🔶Open Source Policy §9 (review plan in place, no history accumulated yet) ※time-based
4.1.2.6Assignee verifying alignment with internal best practices🔶Open Source Roles and Responsibilities Definition §6 (assignee designated, review scheduled for 2026-12-31) ※time-based
4.1.3.1Participant awareness assessment evidence🔶Open Source Training Curriculum + Training Completion Tracking Sheet (training not started)
4.1.4.1Program scope documentOpen Source Policy §1
4.1.4.2Performance metricsOpen Source Policy §3 (5 KPI items)
4.1.4.3Evidence of continual improvement (audit history)🔶Gap Analysis Report (this document, first audit record) ※time-based
4.1.5.1Standard vulnerability response procedureVulnerability response procedures (all 8 methods included)
4.2.1.1Public channel for external vulnerability reportsOpen Source Roles and Responsibilities Definition §3 (security@techunicorn.example)
4.2.1.2Internal response procedure for external inquiriesVulnerability response procedures §7
4.2.2.1Document naming role assignees🔶Open Source RACI Matrix (role structure complete, real names not entered)
4.2.2.2Role staffing and budget confirmationOpen Source RACI Matrix §Budget allocation status
4.2.2.3Stated expertise in vulnerability resolutionOpen Source Roles and Responsibilities Definition §5 (security team, KrCERT)
4.2.2.4Internal responsibility assignment procedureOpen Source RACI Matrix §Internal responsibility assignment procedure
4.3.1.1Procedure for continuously recording the SBOM lifecycleSBOM Management Plan
4.3.1.2Component records (SBOM file)output/sbom/java-vulnerable.cdx.json
4.3.2.1Vulnerability detection and resolution procedureVulnerability response procedures + Vulnerability Remediation Plan
4.3.2.2Records of vulnerabilities and actionsVulnerability Analysis Report (5 CVEs recorded) + Vulnerability Remediation Plan
4.4.1.1Document confirming all requirements are metGap Analysis Report (this document)
4.4.2.1Document confirming requirements met within 18 monthsOpen Source Compliance Self-Certification Declaration

ISO/IEC 18974 subtotal: ✅ 18 / partially satisfied 7 / ❌ 0


4. Actions

  • Target: output/organization/raci-matrix.md §Assignees by role
  • Problem: The "(enter assignee name)" placeholders have not been replaced with real names
  • Affected items: 3.2.2.1, 4.1.2.3, 4.2.2.1
  • Action: Enter actual names in the assignees-by-role table in raci-matrix.md
  • Estimated time: 10 minutes

Medium — Start training completion (2026-Q2 execution plan already in place)

  • Target: output/training/completion-tracker.md
  • Problem: The training plan and forms are complete, but actual completion stands at 0 people (0%)
  • Affected items: 3.1.2.3, 3.1.3.1, 4.1.2.4, 4.1.3.1
  • Action: Run the training from 2026-Q2 according to curriculum.md §Training Schedule Plan
    • Operations, 100 people: online training starts during 2026-05
    • Managers, 10 people: offline group session in 2026-06
    • Developers, 1,000 people: staged online start across 2026-Q2~Q3
  • Estimated time: plan already established; now in the execution stage

Low — Confirm and complete budget information

  • Target: output/organization/raci-matrix.md §Budget allocation status
  • Problem: The open source tooling budget and external training budget entries still read "(fill in after confirmation)"
  • Affected item: 3.2.2.2 (currently judged ✅, but completing this entry is recommended)
  • Action: Enter the actual budget allocation figures
  • Estimated time: 30 minutes

5. Handling Time-Based Items (Normal at Initial Certification)

Evidence for the 3 items below cannot exist at the time of initial certification. They are treated as partially satisfied and convert to satisfied at the 18-month renewal.

Item IDCurrent actionCondition for conversion to satisfied
18974 §4.1.2.5 periodic review evidenceoss-policy.md §9 records "Next review date: 2027-03-23"At least 1 actual review record accumulated
18974 §4.1.2.6 best-practice alignment verificationrole-definition.md §6 records the assignee and the first review date (2026-12-31)At least 1 recorded review result
18974 §4.1.4.3 continual improvement evidenceThis gap analysis (2026-03-23) is recorded as the first audit recordAt least 2 audit records

6. Renewal Schedule

DateTask
2026-06-30Update completion-tracker.md after manager training is complete
2026-09-30First developer group (250 people) completes offline training
2026-12-31Perform the 18974 §4.1.2.6 best-practice alignment review → update gap-analysis.md
2027-03-23Annual policy review (oss-policy.md §9) → update gap-analysis.md
2027-09-23Self-Certification validity expires (declaration date + 18 months) → re-declare

Open Source Compliance Self-Certification Declaration

info

Generating agent: 07-conformance-preparer | Save path: output/conformance/declaration-draft.md


Declaration Information

ItemContent
Declaring companyTechUnicorn
Declaring Program ManagerDevOps team open source Program Manager
Contact emailopensource@techunicorn.example
Declaration date2026-03-23
Validity period2026-03-23 ~ 2027-09-23 (18 months)
Re-declaration due date2027-09-23

Applicable Standards

  • ISO/IEC 5230:2020 — OpenChain License Compliance Specification
  • ISO/IEC 18974:2023 — OpenChain Security Assurance Specification

Scope

All software developed, distributed, and operated by TechUnicorn:

  • Distribution methods: SaaS, app stores (iOS/Android), embedded (on-device), internal systems
  • Applies to: everyone involved in open source use, including developers, managers, and operations teams
  • Program name: TechUnicorn Open Source Compliance Program v1.0

ISO/IEC 5230:2020 Checklist

We confirm and declare the status of the 25 evidence items below. Partially satisfied items have completed plans in place and convert to satisfied once training completion and time-based evidence are secured.

Item IDContentStatusDeliverables
3.1.1.1Documented open source policyOpen Source Policy
3.1.1.2Policy dissemination procedureOpen Source Policy §7, Open Source Training Curriculum
3.1.2.1List of roles and responsibilitiesOpen Source Roles and Responsibilities Definition
3.1.2.2Competency description per roleOpen Source Roles and Responsibilities Definition §2
3.1.2.3Competency assessment evidence🔶Training Completion Tracking Sheet (completion about to begin)
3.1.3.1Participant awareness assessment evidence🔶Open Source Training Curriculum + Training Completion Tracking Sheet
3.1.4.1Program scope documentOpen Source Policy §1
3.1.5.1License obligations review procedureOpen source use approval process §4, Approved License List
3.2.1.1Public channel for external inquiriesOpen Source Roles and Responsibilities Definition §3
3.2.1.2Internal response procedure for external inquiriesOpen Source Roles and Responsibilities Definition §3
3.2.2.1Document naming role assignees🔶Open Source RACI Matrix (real-name entry in progress)
3.2.2.2Role staffing and budget confirmationOpen Source RACI Matrix §Budget allocation status
3.2.2.3Method for accessing legal expertiseOpen Source Roles and Responsibilities Definition §4
3.2.2.4Internal responsibility assignment procedureOpen Source RACI Matrix §Internal responsibility assignment procedure
3.2.2.5Non-compliance case review and remediation procedureOpen Source RACI Matrix §Non-compliance case review procedure
3.3.1.1SBOM management procedureSBOM Management Plan
3.3.1.2Component records (SBOM file)output/sbom/java-vulnerable.cdx.json
3.3.2.1License use case handling procedureSBOM License Analysis Report, Open source use approval process
3.4.1.1Compliance deliverable preparation and distributionPre-deployment license compliance checklist
3.4.1.2Compliance deliverable archiving procedurePre-deployment license compliance checklist §5
3.5.1.1Open source contribution policyOpen Source Policy §5
3.5.1.2Open source contribution management procedureOpen Source Policy §5
3.5.1.3Contribution policy awareness procedureOpen Source Policy §7
3.6.1.1Document confirming all requirements are metGap Analysis Report
3.6.2.1Confirmation of requirements met within 18 monthsOpen Source Compliance Self-Certification Declaration (this document)

ISO/IEC 18974:2023 Checklist

We confirm and declare the status of the 25 evidence items below. Partially satisfied items have completed plans in place and convert to satisfied once training completion and time-based evidence are secured.

Item IDContentStatusDeliverables
4.1.1.1Documented security assurance policyOpen Source Policy §4
4.1.1.2Policy dissemination procedureOpen Source Policy §7, Open Source Training Curriculum
4.1.2.1List of roles and responsibilitiesOpen Source Roles and Responsibilities Definition §1
4.1.2.2Competency description per roleOpen Source Roles and Responsibilities Definition §2
4.1.2.3Participant list and roles🔶Open Source RACI Matrix (real-name entry in progress)
4.1.2.4Competency assessment evidence🔶Training Completion Tracking Sheet (completion about to begin)
4.1.2.5Evidence of periodic review and change🔶Open Source Policy §9 (review plan in place, history to be accumulated)
4.1.2.6Assignee verifying alignment with internal best practices🔶Open Source Roles and Responsibilities Definition §6 (assignee designated, review scheduled for 2026-12-31)
4.1.3.1Participant awareness assessment evidence🔶Open Source Training Curriculum + Training Completion Tracking Sheet
4.1.4.1Program scope documentOpen Source Policy §1
4.1.4.2Performance metricsOpen Source Policy §3 (5 KPI items)
4.1.4.3Evidence of continual improvement (audit history)🔶Gap Analysis Report (first audit record)
4.1.5.1Standard vulnerability response procedureVulnerability response procedures
4.2.1.1Public channel for external vulnerability reportsOpen Source Roles and Responsibilities Definition §3 (security@techunicorn.example)
4.2.1.2Internal response procedure for external inquiriesVulnerability response procedures §7
4.2.2.1Document naming role assignees🔶Open Source RACI Matrix (real-name entry in progress)
4.2.2.2Role staffing and budget confirmationOpen Source RACI Matrix §Budget allocation status
4.2.2.3Stated expertise in vulnerability resolutionOpen Source Roles and Responsibilities Definition §5
4.2.2.4Internal responsibility assignment procedureOpen Source RACI Matrix §Internal responsibility assignment procedure
4.3.1.1Procedure for continuously recording the SBOM lifecycleSBOM Management Plan
4.3.1.2Component records (SBOM file)output/sbom/java-vulnerable.cdx.json
4.3.2.1Vulnerability detection and resolution procedureVulnerability response procedures + Vulnerability Remediation Plan
4.3.2.2Records of vulnerabilities and actionsVulnerability Analysis Report (5 CVEs recorded) + Vulnerability Remediation Plan
4.4.1.1Document confirming all requirements are metGap Analysis Report
4.4.2.1Confirmation of requirements met within 18 monthsOpen Source Compliance Self-Certification Declaration (this document)

Signature

This declaration self-certifies that TechUnicorn operates an open source compliance and security assurance program that satisfies all requirements of ISO/IEC 5230:2020 and ISO/IEC 18974:2023.

FieldContent
Declared byDevOps team open source Program Manager
Approved byDevOps team leader
Declaration date2026-03-23
Next re-declaration date2027-09-23

Note on partially satisfied items: Real-name entry for Program Managers (3.2.2.1, 4.1.2.3, 4.2.2.1) and training completion (3.1.2.3, 4.1.2.4) are in progress and will be completed after the declaration. The time-based items (4.1.2.5, 4.1.2.6, 4.1.4.3) become satisfied at the 18-month renewal.


OpenChain Self-Certification Registration Guide

info

Generating agent: 07-conformance-preparer | Save path: output/conformance/submission-guide.md


Overview

TechUnicorn registers its ISO/IEC 5230:2020 (license compliance) and ISO/IEC 18974:2023 (security assurance) Self-Certification on the official OpenChain project site and declares it publicly.

ItemContent
Registration sitehttps://www.openchainproject.org/conformance
Declaration typeSelf-Certification
Applicable standardsISO/IEC 5230:2020 + ISO/IEC 18974:2023
Validity period18 months (2026-03-23 ~ 2027-09-23)

Preparation Before Registration

Complete the items below before proceeding with registration.

  • output/organization/raci-matrix.md §Assignees by role — real names entered
  • output/organization/appointment-template.md — appointment letter signed
  • Training completion started — at minimum, the manager course launched (2026-06)

Final deliverable check

  • Confirm output/conformance/gap-analysis.md exists
  • Confirm output/conformance/declaration-draft.md exists
  • Confirm all deliverables are up to date

Registration Procedure (Step by Step)

Step 1 — Visit the OpenChain site

  1. Go to https://www.openchainproject.org/conformance
  2. Click "Submit Conformance" in the menu at the top or bottom of the page

Step 2 — Select the standards

  • Select ISO/IEC 5230 (license compliance)
  • Select ISO/IEC 18974 (security assurance)
  • Both standards can be submitted at the same time

Step 3 — Enter company information

FieldValue
Company nameTechUnicorn
Contact nameReal name of the DevOps team open source Program Manager
Emailopensource@techunicorn.example
CountryKorea (South)
Websitehttps://www.techunicorn.example

Step 4 — Check off the checklist items

Refer to output/conformance/declaration-draft.md and check each item.

ISO/IEC 5230 checklist (25 items):

  • Check every item from 3.1.1.1 through 3.6.2.1
  • For the partially satisfied items (3.1.2.3, 3.1.3.1, 3.2.2.1), convert them to satisfied where possible (start training completion, enter real names) before submitting; if submitting before conversion, check them with the understanding that their plans are complete

ISO/IEC 18974 checklist (25 items):

  • Check every item from 4.1.1.1 through 4.4.2.1
  • Among the partially satisfied items, the 3 time-based ones (4.1.2.5, 4.1.2.6, 4.1.4.3) are acceptable at initial certification; convert the rest to satisfied where possible before submitting

Step 5 — Submit and confirm

  1. After checking all items, click "Submit"
  2. Confirm receipt of the confirmation email at the address you entered
  3. TechUnicorn is listed on the official OpenChain registration list

After Registration

Public announcement

After registration, announcing through the channels below is recommended:

  • Post the certification status on the company wiki/intranet
  • Add an OpenChain certification banner to the company security/compliance page
  • Notify major customers/recipients of the certification (builds trust)

Deliverable retention

After OpenChain registration, retain the following evidence:

  • A copy of the registration confirmation email
  • A screenshot taken at registration time (kept in the output/conformance/ folder)
  • The signed declaration-draft.md (signed by the Program Manager and the team leader)

Maintenance Schedule

18-month re-declaration cycle

WhenTask
2026-09-23 (6 months after declaration)Interim check — verify progress on partially satisfied items
2027-03-23 (12 months after declaration)Re-run the annual gap analysis, update gap-analysis.md
2027-09-23 (18 months after declaration)Re-declare — re-register on the OpenChain site

Ad-hoc update triggers

When any of the following occurs, update the deliverables immediately and re-run the gap analysis:

TriggerDeliverables to update
Open source policy changeoss-policy.md, gap-analysis.md
Program Manager changerole-definition.md, raci-matrix.md
New Critical CVEcve-report.md, remediation-plan.md
New product/service launchsbom/*, distribution-checklist.md
New distribution channellicense-allowlist.md, oss-policy.md

Contacts

TypeContact
License compliance inquiriesopensource@techunicorn.example
Security vulnerability reportssecurity@techunicorn.example
OpenChain project (official)https://www.openchainproject.org

This document was prepared to fulfill the ISO/IEC 5230 §3.6.1 and ISO/IEC 18974 §4.4.1 requirements.