Open-Source Management Services
Protect your business from risks with our software compliance services
Open source compliance is the process of identifying every open source component in your software, resolving the licence obligations those components create, and tracking their known vulnerabilities across the product lifecycle. BearingPoint delivers that work as an outcome rather than a tool. We scan your source code or your binaries, produce an SBOM in CycloneDX or SPDX format, review every licence obligation, document what has to be published or attributed, and hand your engineering team a remediation list they can act on. Engagements run as a one-off audit, as a transaction-driven due diligence review, or as a managed service that keeps the picture current release after release.
Regulation has now put a date on the problem. Under the EU Cyber Resilience Act, Regulation (EU) 2024/2847, manufacturers of products with digital elements must report actively exploited vulnerabilities from 11 September 2026, and must meet the Act's full obligations from 11 December 2027. Non-compliance carries penalties of up to 15 million euro or 2.5 percent of global turnover and can mean removal of a product from the EU market. NIS2, the EU AI Act and US Executive Order 14028 push in the same direction: prove what is inside your software and prove you are managing it.
Open source management is not a core business process for most organisations, and it needs both specialist knowledge and sustained attention. That is the case for outsourcing it to a team that does nothing else.
Book a free 30-minute consultation with an open source compliance specialist.
Every audit ends with the same four artefacts: a component inventory, an SBOM in CycloneDX or SPDX, a licence obligation register, and a prioritised remediation list. How we get there is what differs.
You receive the price and the delivery date before the engagement starts, and both hold; there is no per-scan metering and no consumption surprise.
We combine several leading scanning engines rather than reselling one, because no single tool detects every component, and we tune the combination to your technology stack.
We trace where a component actually came from and which licence genuinely applies, instead of trusting the licence string a package declares about itself.
When source code is unavailable, for supplier deliveries or acquired products, we analyse the shipped binary and still return a component inventory and an SBOM.
Code is transferred over an encrypted channel, processed under NDA, and deleted once the analysis is complete.
Our specialists walk your developers through each finding, propose concrete remediations, and stay available while the fixes are made.