Research
This is a collection of analysis on the regulatory and policy landscape of open source management and on compliance practice, grounded in primary sources. The topics covered are as follows.
- Open source license compliance
- Open source security management and the software supply chain
- Open Source Program Office (OSPO) operations
- Open source governance frameworks
- International standards and certification (ISO/IEC 5230, ISO/IEC 18974, and others)
- EU and US open source regulation and policy trends
Each article states its sources and references, and new analysis is added continuously.
CISA 2026 SBOM Minimum Elements: What to Prepare and Which Tools Fill the Gaps
An analysis of the revised SBOM minimum elements published on July 29, 2026 by CISA and 17 other agencies. The data fields grew from 7 to …
Enterprise AI BOM Field Requirements Matrix — Required and Optional Fields Defined by Standards and Regulatory Grounds
Weighs the 50 elements of the G7 “SBOM for AI — Minimum Elements” against authoritative standards — SPDX 3.0.1, CycloneDX 1.6, …
A Look at the 2026 Software Supply Chain Security Roadmap
An analysis of the software supply chain security roadmap the government released on June 24, 2026. Covers the SBOM transparency management …
G7 "Software Bill of Materials for AI — Minimum Elements": AI Supply Chain Transparency Guidance by Cluster and Element
Analyzes, from primary sources, “Software Bill of Materials for AI — Minimum Elements,” published by the G7 Cybersecurity …
OpenChain AI SBOM Compliance Management Guide: Minimum Requirements for an AI Supply Chain Compliance Program
Analyzes, from primary sources, the AI SBOM Compliance Management Guide written by the AI Work Group of the OpenChain Project under the …
What the US AI Executive Order (2026-06-02) Means for Corporate Open Source Managers
A primary-source analysis of the US AI executive order (Promoting Advanced Artificial Intelligence Innovation and Security) signed on June …
EU Open Source Strategy: Institutionalizing Open Source for Technological Sovereignty
An analysis of the EU Open Source Strategy (COM(2026) 503), published by the European Commission on June 3, 2026, based on primary sources. …
EU Cyber Resilience Act (CRA) Vulnerability Reporting Obligations — A Research Report on Preparing for the September 11, 2026 Effective Date
The EU Cyber Resilience Act (CRA) brings its Article 14 reporting obligations into effect on September 11, 2026. This report, grounded in …