|
This certificate confirms that a project integrates mature, sustainable, and traceable licence and dependency management practices into its software development and delivery lifecycle. It indicates that licensing and dependency management processes have been implemented, verified, and appropriately documented. It also confirms readiness for compliant, continuous governance and distribution.
It may cover a single project or a group of related software products under unified ownership and management.
The certificate remains valid indefinitely, provided certified practices are maintained and biennial audits are passed. It does not cover patents or legal liability, although patent concerns may be addressed during the Software Licence Assurance (SLA) review.
It requires your team to sustain licensing and dependency management practices, maintain compliance artefacts, implement governance and automation measures, document relevant processes, and conduct regular audits.
The certificate builds on the Verified Software Licence Certificate by adding structured governance, compliance automation, and continuous auditing.
You may use this document as a checklist template for your project's certification process.
Closely related to the Verified Software Licence Certificate
Additional Requirements
Governance policies are established and enforced, covering inbound and outbound licences, dependency management, contributions, conflict resolution, compliance tools, and audits
Automated compliance tools are integrated into the CI/CD pipeline, with alerts for licence, version, and security issues
Team onboarding and training are implemented, with up-to-date materials available
Contribution guidelines or policies are established and followed
Compliance records are maintained for dependency approvals, licensing decisions, contributions, reviews, known vulnerabilities, and their remediation
Send a request to the Licence Management Team, including:
Results of the SLA or equivalent review for exemplary software
README, LICENSE, COPYRIGHT, NOTICE, CHANGELOG, etc.)Governance and compliance policies, including dependency and licence management guidelines
Exemplary records of dependency management and compliance decisions
Records of compliance reviews and audits
Clarifications or supporting notes, if needed
Reference the certificate in your documentation, metadata, project page, or communications.
See Contact Us for information on how to communicate with the Licence Management Team.
Create and maintain artefacts and documents that manage, support, and track licence, dependency, and security governance:
README, LICENSE, COPYRIGHT, NOTICE, CHANGELOG, etc.) for all included softwareSBOM) for each software (recommended)Upon approval, your project and associated software will receive the Software Licence Assurance Certificate, visible at certificates.software.geant.org and in the GÉANT Software Catalogue.
Maintain ongoing compliance, governance, automation measures, and licensing compliance for each software included in the project.
The Licence Management Team validates issuance and may review certificate status.
A biennial audit is required, either as an internal audit by the development team or as an external audit arranged with the Licence Management Team.
An internal review is required following governance or leadership changes, major changes to compliance processes, or serious compliance concerns raised by users.
The certificate is valid indefinitely, unless revoked.
Further details are available in the Detailed Guide: Software Licence Assurance Certificate.