A company that has built an open source program (open source policy / process / tools / organization) that complies with all requirements of the ISO/IEC 5230 specification except Clause 6 may prepare and publish a document stating the following two items.
- That the company’s open source program meets all requirements of OpenChain Specification 2.1
- That the company’s open source program guarantees it has maintained compliance with all requirements of OpenChain Specification 2.1 for at least 18 months after obtaining conformance certification
A company can either include the above content in its open source policy or publish it on a publicly available website.
As shown in the image below, you can refer to how SK telecom published this content on its open source portal site.
https://sktelecom.github.io/compliance/iso5230/
By documenting in this way that all requirements of ISO/IEC 5230 are guaranteed to be met, a company can prepare the following evidence materials required by ISO/IEC 5230.
- 3.6.1.1 Documentation confirming that the program specified in Clause 3.1.4 meets all requirements of this specification
- 3.6.2.1 Documentation confirming that the program has met all requirements of this specification version (v2.1) for the past 18 months since obtaining conformance certification
| Self Certification 6.a | Do you have documentation confirming that your Program meets all the requirements of this specification? |
|---|---|
| Do you have documentation confirming that your Program meets all the requirements of this specification? | |
| Self Certification 6.b | Do you have documentation confirming that your Program conformance was reviewed within the last 18 months? |
| Do you have documentation confirming that your Program conformance was reviewed within the last 18 months? |
Once this is completed, a company finally meets all the requirements of ISO/IEC 5230.
