# Research

> Analysis of open source regulation, policy, and compliance practice grounded in primary sources. Covers recent developments such as the EU Cyber Resilience Act, the US AI executive order, and the EU open source strategy.

---

LLMS index: [llms.txt](/llms.txt)

---

This is a collection of analysis on the regulatory and policy landscape of open source management and on compliance practice, grounded in primary sources. The topics covered are as follows.

- Open source license compliance
- Open source security management and the software supply chain
- Open Source Program Office (OSPO) operations
- Open source governance frameworks
- International standards and certification (ISO/IEC 5230, ISO/IEC 18974, and others)
- EU and US open source regulation and policy trends

Each article states its sources and references, and new analysis is added continuously.

---

Section pages:

- [CISA 2026 SBOM Minimum Elements: What to Prepare and Which Tools Fill the Gaps](/en/research/2026-cisa-sbom-minimum-elements/): An analysis of the revised SBOM minimum elements published on July 29, 2026 by CISA and 17 other agencies. The data fields grew from 7 to 17, and licensing entered the minimum baseline for the first time. Covers what an OSPO must decide before selecting a tool, how SBOM formats differ in their support, and how far the open source tool BomLens gets today.
- [Enterprise AI BOM Field Requirements Matrix — Required and Optional Fields Defined by Standards and Regulatory Grounds](/en/research/2026-ai-bom-requirements/): Weighs the 50 elements of the G7 "SBOM for AI — Minimum Elements" against authoritative standards — SPDX 3.0.1, CycloneDX 1.6, NTIA 2021, OpenChain AI V1 — and regulatory grounds including the CRA, the AI Act, and FDA guidance, to determine which AI BOM fields are required and which are optional. Part of a five-part series that also applies the same matrix to production, ingestion, and supplier contexts and covers toolset strategy.
- [A Look at the 2026 Software Supply Chain Security Roadmap](/en/research/2026-sw-supply-chain-roadmap/): An analysis of the software supply chain security roadmap the government released on June 24, 2026. Covers the SBOM transparency management model, testbeds and consulting, pilot certification, a rapid detection-and-response system, and burden reduction for small and medium-sized enterprises, and their practical impact on exporting, public-sector, and small and medium-sized software companies.
- [G7 "Software Bill of Materials for AI — Minimum Elements": AI Supply Chain Transparency Guidance by Cluster and Element](/en/research/2026-g7-sbom-for-ai/): Analyzes, from primary sources, "Software Bill of Materials for AI — Minimum Elements," published by the G7 Cybersecurity Working Group on May 12, 2026. Covers the structure, background, regulatory alignment, and implications for Korean companies of the first G7 joint guidance to define, at the level of 7 clusters and 50 elements, what an SBOM applied to AI systems must contain.
- [OpenChain AI SBOM Compliance Management Guide: Minimum Requirements for an AI Supply Chain Compliance Program](/en/research/2026-openchain-ai-sbom/): Analyzes, from primary sources, the AI SBOM Compliance Management Guide written by the AI Work Group of the OpenChain Project under the Linux Foundation. Covers the structure, requirements, regulatory trends, significance, and limitations of the document, which extends the ISO/IEC 5230 methodology to the AI supply chain to define the minimum requirements a compliance program must meet.
- [What the US AI Executive Order (2026-06-02) Means for Corporate Open Source Managers](/en/research/2026-us-ai-eo-ospo/): A primary-source analysis of the US AI executive order (Promoting Advanced Artificial Intelligence Innovation and Security) signed on June 2, 2026. Covers what the AI Cybersecurity Clearinghouse and the voluntary frontier model framework mean for corporate open source managers, the contrast with EU CRA mandatory reporting, and what to do now versus what to watch.
- [EU Open Source Strategy: Institutionalizing Open Source for Technological Sovereignty](/en/research/2026-eu-open-source-strategy/): An analysis of the EU Open Source Strategy (COM(2026) 503), published by the European Commission on June 3, 2026, based on primary sources. Covers the four goals, €2 billion over seven years, the governance structure, civil society criticism, and practical implications for Korean public agencies and companies.
- [EU Cyber Resilience Act (CRA) Vulnerability Reporting Obligations — A Research Report on Preparing for the September 11, 2026 Effective Date](/en/research/2026-eu-cra-vulnerability-reporting/): The EU Cyber Resilience Act (CRA) brings its Article 14 reporting obligations into effect on September 11, 2026. This report, grounded in primary sources, sets out how Korean companies should prepare for the 24-hour, 72-hour, and 14-day notification deadlines and for SBOM and conformity assessment requirements.
