This certificate confirms that your project integrates mature, sustainable, and traceable licensing and dependency management into its software development and delivery lifecycle. It applies to actively maintained, publicly or purposefully distributed software under consistent governance.
The certificate may cover a single software project or a group of products under unified ownership and management. It remains valid indefinitely, provided certified practices are maintained, and biennial audits are passed.
It is recommended to obtain Verified Software Licence Certificate before applying for this one.
A full specification of software licensing certificates is also available (the document is available for GÉANT participants).
Ensure your project:
Ensure that your development practices include:
Inbound licences (allowed third-party licences)
Outbound licensing (especially where multiple licences apply)
Contribution terms (e.g. CONTRIBUTING or CLA), and contribution and version management
Licence management and conflict remediation
Ensure the team understands and follows these policies.
Create and maintain the following artefacts and documents, making them available to team members and auditors:
README, LICENSE, COPYRIGHT, and, if applicable, NOTICE, CONTRIBUTING, and CHANGELOG for all included softwareUp-to-date list of all dependencies with licences and security status
Records of compliance decisions, approvals, and reviews
Records of known vulnerabilities and their remediation
Records of monitoring alerts and responses
Records of code testing or review, including external contributions where applicable
CI/CD compliance tool rules and configuration files
Software Bill of Materials (SBOM) for each software (recommended)
Onboarding and training materials for licensing, security, and IPR management
Contribution guidelines
Maintain records on:
Approving new dependencies before integration
Monitoring licence changes and vulnerabilities in all dependencies
Send a request to the Licence Management Team, including:
Contact details of the Licence Compliance Officer
Results of the SLA or equivalent review
README, LICENSE, COPYRIGHT, NOTICE, CHANGELOG, etc.)Governance and compliance policies, including dependency and licence management guidelines
Exemplary records of dependency management and compliance decisions
Exemplary records associated with one or several contributions
Exemplary records of known vulnerabilities and their remediation
Records of compliance reviews and audits
See Contact Us for instructions on communicating with the team.
Cooperate with the Licence Management Team to:
Use of SCA and SLA services to verify compliance and practice performance may be required.
Upon approval, your project and associated software will receive the Software Licence Assurance Certificate, which will be visible at certificates.software.geant.org and in the GÉANT Software Catalogue.
You may reference the certificate in your documentation, metadata, project page, or communications. The Licence Management Team will provide guidance on how to do this, and will also provide a review report.
To keep the certificate valid:
Contact the Licence Management Team proactively when significant changes occur to determine if recertification is needed.
The certificate is valid indefinitely, unless revoked.