KEMBAR78
OpenChain Global Update @ Open Source Tech Day 2025 | PDF
ShaneCoughlan
OpenChain General Manager,
The Linux Foundation
Open Chain Global Update
CONTENTS
01
02
03
ReferenceMaterial
Keeping It Simple
In Conclusion
Our vision is a trusted supply chain
Our mission is to make that happen
Project Charter:
https://github.com/OpenChain-Project/Project-Charter-And-Agreements/blob/master/Project-Charter/OpenChain-Charter-March2020.pdf
Our standards are the international baseline for quality in open
source license compliance and security assurance programs.
Our guides and reference material helps people solve
compliance challenges.
Our community provides a space to share knowledge.
Platinum Members (Governing Board)
Members Represent Trillions In USD Market Value
Automotive Banking Cloud Consumer Industrial SaaS Service Silicon Telco
Example Verticals Impacted by OpenChain
This is a snapshot based on membership and select conformant organizations currently listed on our website. Total conformant numbers are far higher.
Example: PwC Survey shows 20% of companies in Germany with over 2,000 employees already used ISO/IEC 5230.
Trillions More In Market Value Touched
(Lockheed co-chairs our spec development)
This is a non-exhaustive list of participants on some of our community lists
Our Community Work Groups
Regional User Groups
China (Sept 2019~)
Germany (Jan 2020~)
India (Sept 2019~)
Japan (Dec 2017~)
Korea (Jan 2019~)
Meridian 22 (Sept 2025~)
Taiwan (Sept 2019~)
UK (June 2020~)
Core Work Groups
Education (Autumn 2020~)
Specification (Spring 2016~)
Community Work Groups
AI (January 2024~)
Automation (Summer 2019~)
SBOM (July 2024~)
Industry-Specific Work Groups
Automotive (Summer 2019~)
Telco (Spring 2021~)
24 Global Ambassadors Supporting Our Work
General Project News
● We launched the Ambassador program in September:
https://openchainproject.org/news/2025/09/18/welcoming-the-openchain-ambassador-program
● Update on OpenChain ISO/IEC 18974 and the CRA:
https://openchainproject.org/news/2025/09/18/update-on-openchain-iso-iec-18974-and-the-cra
● RECORDING: OpenChain SBOM Work Group – Meeting – 2025-09-24:
https://openchainproject.org/news/2025/09/25/sbom-work-group-2025-09-24
AI Compliance Coming in October
Our OpenChain AI Work Group completed work on an AI System Bill of Materials
Compliance Guide in 1H 2025. This guide will officially be released on the 20th of
October.
The Draft AI SBOM Compliance Guide:
https://docs.google.com/document/d/1XHztgMALwnu2D02bmWYyXeW3wE_Jw19
9/edit#heading=h.x3i92tls8mld
AI BOM Compliance in the Supply Chain Guide
SBOM Study Group Update
The SBOM Study Group has continued its discussion around SBOM Quality.
There are two key documents being talked about:
1. Version 1.1 of the Telco SBOM Quality Guide:
https://openchainproject.org/featured/2025/05/09/openchain-telco-sbom-
guide-version-1-1-now-available
2. A new document designing a cross-industry, cross-format SBOM quality guide:
https://docs.google.com/document/d/1iuXX8j10N70dfce1-CZFWhW6S2jEqc--
flcCgXMMdjg/edit?tab=t.0#heading=h.xtogtsbrin0p
Cross-Industry SBOM Quality Guide Concept
Telco SBOM
Quality Guide
Telco SBOM Quality Work … EXPANDED
Official
Validator
ByteDance
Schemas
Third-Party
Tooling
ByteDance
Case Study
Reference Material
01
Updates to Policy Template + Training Course
Example Policy template
Reference training links (as shown last call) committed to master
"Require a procedure to create a SBOM" text updated, see:
https://github.com/OpenChain-Project/Reference-Material/issues/112
LFC193 Training
Proposed updated Ch4 diagrams - intention is that for the LF Training hosted course
an AI presenter can talk the text with accompanying video animated diagrams. See
latest version :
https://github.com/OpenChain-Project/Reference-Material/tree/master/OpenChain-
Training/en/Online-Training-Courses/LFC193%20Course%20Content
Free Online Compliance Management Training
4.5 out of 5 star rating!
4.6 out of 5 star rating!
Open Source Policy Template
A Reference Library
Of 1,500+ Documents
100+
Webinars about open source
management and governance
OpenChain has
Keeping It Simple
02
Our Workflow
We Study
We Brainstorm
We Make a Guide (if useful)
We Make a Specification (if useful)
We Make a Standard (if useful)
Sister Standards - Processes for Programs
ISO/IEC 5230 (License Compliance) ISO/IEC 18974 (Security Assurance)
Flexible program size
Covering:
● Inbound processes
● Internal processes
● Outbound processes
Standards about process points
Not about process content
Self-Certification Checklists
In Conclusion
03
There Is A Steady Trend:
Open source is becoming more professional
Open source is becoming more accountable
Open source is becoming more sustainable
OpenChain Has A Plan
1. We will assist in the professionalization of the supply
chain
2. We will continue to grow our reference material
3. We will also support discussion in new area like AI
Compliance
Our Message: You Are Always Welcome!
New in Korea: Makkoli Study Group
It Has Been A Long Journey…
● 2006, FSFE creates a legal task force with
support from Harald Welte
● 2007, FSFE creates a network for lawyers
● 2008, the legal network hosts its first major legal
conference
● 2015, OpenChain concept by people who were
part of the legal network and also LF
● 2016, OpenChain officially launched as an LF
Project
Participate In OpenChain
● Our calls are open and publicly listed.
● We publish a recording of every
meeting not under Chatham House
Rule.
● We provide access to work groups,
special interest groups and local
work groups by mailing list.
● We also use Slack and WeChat.

OpenChain Global Update @ Open Source Tech Day 2025

  • 1.
    ShaneCoughlan OpenChain General Manager, TheLinux Foundation Open Chain Global Update
  • 2.
  • 3.
    Our vision isa trusted supply chain Our mission is to make that happen Project Charter: https://github.com/OpenChain-Project/Project-Charter-And-Agreements/blob/master/Project-Charter/OpenChain-Charter-March2020.pdf
  • 4.
    Our standards arethe international baseline for quality in open source license compliance and security assurance programs. Our guides and reference material helps people solve compliance challenges. Our community provides a space to share knowledge.
  • 5.
    Platinum Members (GoverningBoard) Members Represent Trillions In USD Market Value
  • 6.
    Automotive Banking CloudConsumer Industrial SaaS Service Silicon Telco Example Verticals Impacted by OpenChain This is a snapshot based on membership and select conformant organizations currently listed on our website. Total conformant numbers are far higher. Example: PwC Survey shows 20% of companies in Germany with over 2,000 employees already used ISO/IEC 5230.
  • 7.
    Trillions More InMarket Value Touched (Lockheed co-chairs our spec development) This is a non-exhaustive list of participants on some of our community lists
  • 8.
    Our Community WorkGroups Regional User Groups China (Sept 2019~) Germany (Jan 2020~) India (Sept 2019~) Japan (Dec 2017~) Korea (Jan 2019~) Meridian 22 (Sept 2025~) Taiwan (Sept 2019~) UK (June 2020~) Core Work Groups Education (Autumn 2020~) Specification (Spring 2016~) Community Work Groups AI (January 2024~) Automation (Summer 2019~) SBOM (July 2024~) Industry-Specific Work Groups Automotive (Summer 2019~) Telco (Spring 2021~)
  • 9.
    24 Global AmbassadorsSupporting Our Work
  • 10.
    General Project News ●We launched the Ambassador program in September: https://openchainproject.org/news/2025/09/18/welcoming-the-openchain-ambassador-program ● Update on OpenChain ISO/IEC 18974 and the CRA: https://openchainproject.org/news/2025/09/18/update-on-openchain-iso-iec-18974-and-the-cra ● RECORDING: OpenChain SBOM Work Group – Meeting – 2025-09-24: https://openchainproject.org/news/2025/09/25/sbom-work-group-2025-09-24
  • 11.
    AI Compliance Comingin October Our OpenChain AI Work Group completed work on an AI System Bill of Materials Compliance Guide in 1H 2025. This guide will officially be released on the 20th of October. The Draft AI SBOM Compliance Guide: https://docs.google.com/document/d/1XHztgMALwnu2D02bmWYyXeW3wE_Jw19 9/edit#heading=h.x3i92tls8mld
  • 12.
    AI BOM Compliancein the Supply Chain Guide
  • 13.
    SBOM Study GroupUpdate The SBOM Study Group has continued its discussion around SBOM Quality. There are two key documents being talked about: 1. Version 1.1 of the Telco SBOM Quality Guide: https://openchainproject.org/featured/2025/05/09/openchain-telco-sbom- guide-version-1-1-now-available 2. A new document designing a cross-industry, cross-format SBOM quality guide: https://docs.google.com/document/d/1iuXX8j10N70dfce1-CZFWhW6S2jEqc-- flcCgXMMdjg/edit?tab=t.0#heading=h.xtogtsbrin0p
  • 14.
  • 15.
  • 16.
    Telco SBOM QualityWork … EXPANDED Official Validator ByteDance Schemas Third-Party Tooling ByteDance Case Study
  • 17.
  • 18.
    Updates to PolicyTemplate + Training Course Example Policy template Reference training links (as shown last call) committed to master "Require a procedure to create a SBOM" text updated, see: https://github.com/OpenChain-Project/Reference-Material/issues/112 LFC193 Training Proposed updated Ch4 diagrams - intention is that for the LF Training hosted course an AI presenter can talk the text with accompanying video animated diagrams. See latest version : https://github.com/OpenChain-Project/Reference-Material/tree/master/OpenChain- Training/en/Online-Training-Courses/LFC193%20Course%20Content
  • 19.
    Free Online ComplianceManagement Training 4.5 out of 5 star rating! 4.6 out of 5 star rating!
  • 20.
  • 21.
    A Reference Library Of1,500+ Documents
  • 22.
    100+ Webinars about opensource management and governance OpenChain has
  • 23.
  • 24.
    Our Workflow We Study WeBrainstorm We Make a Guide (if useful) We Make a Specification (if useful) We Make a Standard (if useful)
  • 25.
    Sister Standards -Processes for Programs ISO/IEC 5230 (License Compliance) ISO/IEC 18974 (Security Assurance) Flexible program size Covering: ● Inbound processes ● Internal processes ● Outbound processes Standards about process points Not about process content
  • 26.
  • 27.
  • 28.
    There Is ASteady Trend: Open source is becoming more professional Open source is becoming more accountable Open source is becoming more sustainable
  • 29.
    OpenChain Has APlan 1. We will assist in the professionalization of the supply chain 2. We will continue to grow our reference material 3. We will also support discussion in new area like AI Compliance
  • 30.
    Our Message: YouAre Always Welcome! New in Korea: Makkoli Study Group
  • 31.
    It Has BeenA Long Journey… ● 2006, FSFE creates a legal task force with support from Harald Welte ● 2007, FSFE creates a network for lawyers ● 2008, the legal network hosts its first major legal conference ● 2015, OpenChain concept by people who were part of the legal network and also LF ● 2016, OpenChain officially launched as an LF Project
  • 32.
    Participate In OpenChain ●Our calls are open and publicly listed. ● We publish a recording of every meeting not under Chatham House Rule. ● We provide access to work groups, special interest groups and local work groups by mailing list. ● We also use Slack and WeChat.