ISO/IEC 18974 Conformance Guide

A conformance guide that explains the 25 Verification Material items of ISO/IEC 18974 clause by clause.

This guide explains each requirement clause of ISO/IEC 18974 (OpenChain Security Assurance) one by one. It describes what Verification Materials each clause requires, how to comply, and what sample documents can be used immediately.

Author : OpenChain Korea Work Group / CC BY 4.0

Target Audience

  • Security managers and open source program managers at organizations establishing an open source security assurance framework for the first time
  • Engineers building open source vulnerability management processes in DevSecOps environments
  • Organization staff preparing to add ISO/IEC 18974 certification after obtaining ISO/IEC 5230 certification

Relationship with ISO/IEC 5230

How to Use This Guide

Full Clause Checklist

ISO/IEC 18974 consists of a total of 11 clauses and 25 Verification Material items. Items marked with ★ are added or changed from a security perspective compared to ISO/IEC 5230.

§4.1 Program Foundation

ClauseTitleVerification MaterialsDetails
§4.1.1Policy2 itemsGo
§4.1.2Competence ★6 itemsGo
§4.1.3Awareness1 itemGo
§4.1.4Program Scope ★3 itemsGo
§4.1.5Standard Practice Implementation ★1 itemGo

§4.2 Relevant Tasks

ClauseTitleVerification MaterialsDetails
§4.2.1Access2 itemsGo
§4.2.2Effectively Resourced4 itemsGo

§4.3 Content Review and Approval

ClauseTitleVerification MaterialsDetails
§4.3.1SBOM2 itemsGo
§4.3.2Security Assurance ★2 itemsGo

§4.4 Conformance

ClauseTitleVerification MaterialsDetails
§4.4.1Completeness1 itemGo
§4.4.2Duration1 itemGo

Total: 11 clauses / 25 Verification Material items

Summary of 18974 Additional Items Compared to ISO/IEC 5230

ClauseAdded ContentNumber of Added Items
§4.1.2 CompetenceList of participants (4.1.2.3), evidence of periodic review (4.1.2.5), alignment with internal best practices (4.1.2.6)+3 items
§4.1.4 Program ScopePerformance metrics (4.1.4.2), evidence of continuous improvement (4.1.4.3)+2 items
§4.1.5 Standard Practice ImplementationDocumented procedures for all 8 vulnerability handling methods (4.1.5.1)New clause
§4.3.2 Security AssuranceVulnerability detection and resolution procedure (4.3.2.1), vulnerability and action records (4.3.2.2)New clause

ISO/IEC 18974 Certification Process

There are three ways to officially have ISO/IEC 18974 conformance recognized.

Step 1. Self-Certification

Complete the online checklist provided by the OpenChain Project to self-declare conformance. There is no cost and you can start immediately.


Step 2. Independent Assessment

An external expert or consulting organization evaluates the security assurance program. This is used to demonstrate the level of conformance to supply chain partners.


Step 3. Third-party Certification

A certification body approved by OpenChain conducts an audit and issues an official certificate. This is suitable for meeting global supply chain requirements.

  • Approved certification bodies (as of 2024): ORCRO, PwC, TÜV SÜD, Synopsys, Bureau Veritas