Overview
ISO/IEC 5230:2020 - the OpenChain Specification - defines the key requirements for a quality open source license compliance program. Published by ISO/IEC and adopted from the OpenChain initiative, the standard provides a practical benchmark to build trust between organizations that exchange software solutions containing open source components. It focuses on the “what” and “why” of compliance programs (policy, roles, artifacts) rather than prescribing specific tools or processes, enabling flexible implementation across different sizes and industries.
Key topics and technical requirements
- Program foundation
- A documented open source policy that is internally communicated.
- Defined program scope (single product line to enterprise-wide).
- Competence and awareness requirements: roles, responsibilities, training records and evidence of assessed competence.
- License obligations
- A process to review identified open source licenses to determine obligations, restrictions and rights.
- Verification materials (records) to demonstrate compliance activities.
- Relevant tasks and resourcing
- Publicly accessible contact method for external open source inquiries.
- Assigned accountability, allocated time and funding, and access to legal expertise for compliance decisions.
- Open source content review
- Procedures for creating and managing an open source bill of materials (BoM) listing components and identified licenses.
- Records showing identification, tracking, approval and archiving of component data.
- Compliance artifacts
- Delivery of outputs such as attribution notices, source code, license copies, written offers and SPDX documents as part of the compliance artifact collection.
- Conformance
- The specification defines verification materials required to demonstrate that a program is OpenChain conformant.
Keywords naturally integrated: ISO/IEC 5230, OpenChain Specification, open source license compliance, bill of materials, compliance artifacts, SPDX, open source policy.
Applications and who uses it
- Software development organizations seeking a repeatable, auditable approach to open source compliance.
- Legal, IP and compliance teams responsible for license risk management.
- Release engineers, product managers and DevOps teams producing distributed software (binary or source).
- Suppliers, distributors and integrators who need to build trust with customers by delivering consistent compliance artifacts.
- Companies engaging with open source communities and contributors who need defined processes for contributions and interactions.
Related standards and references
- SPDX (Software Package Data Exchange) - widely used format for exchanging BoM and license metadata; commonly used alongside ISO/IEC 5230.
- ISO/IEC JTC 1 adoption - ISO/IEC 5230 was adopted under the JTC 1 PAS procedure and originated from the Joint Development Foundation / OpenChain initiative.
ISO/IEC 5230 helps organizations standardize open source governance, reduce license risk, and streamline the delivery of compliance artifacts across the software supply chain.