This page describes the OpenChain Security Compliance standards and provides guidance on how to adopt them in companies with all sizes and sectors.
You can download the Security Compliance Specification directly from OpenChain Github (free version). see below:
You can also download the standards directly from the ISO website (paid version).
ISO/IEC 18974
ISO/IEC 18974 is the International Standard for open source security assurance. ISO/IEC 18974 helps organizations check open source for known security vulnerability issues like CVEs, GitHub dependency alerts or package manager alerts.ISO/IEC 18974 is lightweight, easy to read and is supported by our global community with free reference material and conformance resources.
ISO/IEC 18974 identifies:
- The key places to have security processes
- How to assign roles and responsibilities
- And how to ensure sustainability of the processes
Why organizations adopt ISO 18974
- Meet regulatory requirements. Compliance helps organizations satisfy regulations such as the EU Cyber Resilience Act (CRA), NIS2, and other national cybersecurity laws, reducing legal and financial risks.
- Reduce cybersecurity risk. A structured compliance program helps identify, assess, and mitigate vulnerabilities before they become security incidents.
- Protect customers and products. Secure products and services increase customer confidence and reduce the likelihood of data breaches or product compromises.
- Strengthen software supply chain security. Compliance encourages better management of third-party software, open source components, SBOMs, and vulnerabilities throughout the software lifecycle.
- Improve incident response. Organizations with mature compliance processes can detect, respond to, and recover from cyber incidents more quickly and effectively.
- Increase customer trust. Many enterprise customers and governments now expect suppliers to demonstrate cybersecurity compliance before doing business.
How to Adopt These Standards
You can choose between self-certification (see the checklist below), independent assessment or third-party certification for either standard. Our recommendation is to start with self-certification and a narrowly-scoped program. We provide free short, simple checklists or questionnaires to do this with “yes” or “no” questions. If you can answer yes to everything in the forms below it means you are self-certified. If you answer no to a few questions, it means you can focus resources on key areas of process improvement.
Self Certification Checklist:
Third-Party Certification
Certification partner information: https://openchainproject.org/partners
How to Apply for OpenChain Conformance
If you would like to add your company to our list of conformant organisations, Please complete the online application form.
Which companies have already adopted OpenChain Standards?
Till today, over 100+ companies have adopted OpenChain Standards, for more information, see here.
Q&A
If you have any questions, please contact support@openchainproject.org.
see our FQA page
