Open Source Compliance, Audits and SBOM Management

Know exactly what open source is inside your software, what it obliges you to do, and what it exposes you to. BearingPoint Open-Source Management Services has delivered open source compliance audits and managed compliance operations for 15 years for leading global companies across industries.

Explore our services

Open source compliance is the process of identifying every open source component in your software, resolving the licence obligations those components create, and tracking their known vulnerabilities across the product lifecycle. BearingPoint delivers that work as an outcome rather than a tool. We scan your source code or your binaries, produce an SBOM in CycloneDX or SPDX format, review every licence obligation, document what has to be published or attributed, and hand your engineering team a remediation list they can act on. Engagements run as a one-off audit, as a transaction-driven due diligence review, or as a managed service that keeps the picture current release after release.

 

Why open source compliance stopped being optional

Why open source compliance stopped being optional

Almost every commercial product now ships open source components, and a large share of a modern application's code originates outside the organisation that sells it. That is an advantage, not a problem, until the obligations attached to those components go unmanaged. Copyleft licences such as GPL and AGPL can require you to publish source code you regard as proprietary. Missing attribution files breach even the most permissive licences. Unpatched components carry known vulnerabilities into your customers' environments.

Regulation has now put a date on the problem. Under the EU Cyber Resilience Act, Regulation (EU) 2024/2847, manufacturers of products with digital elements must report actively exploited vulnerabilities from 11 September 2026, and must meet the Act's full obligations from 11 December 2027. Non-compliance carries penalties of up to 15 million euro or 2.5 percent of global turnover and can mean removal of a product from the EU market. NIS2, the EU AI Act and US Executive Order 14028 push in the same direction: prove what is inside your software and prove you are managing it.

Open source management is not a core business process for most organisations, and it needs both specialist knowledge and sustained attention. That is the case for outsourcing it to a team that does nothing else.

Book a free 30-minute consultation with an open source compliance specialist.

Get in touch

What a BearingPoint open source code audit delivers

Every audit ends with the same four artefacts: a component inventory, an SBOM in CycloneDX or SPDX, a licence obligation register, and a prioritised remediation list. How we get there is what differs.

  • 1.

    Fixed price, fixed date

    You receive the price and the delivery date before the engagement starts, and both hold; there is no per-scan metering and no consumption surprise.

  • 2.

    Tool-agnostic scanning

    We combine several leading scanning engines rather than reselling one, because no single tool detects every component, and we tune the combination to your technology stack.

  • 3.

    Origin, not just declaration

    We trace where a component actually came from and which licence genuinely applies, instead of trusting the licence string a package declares about itself.

  • 4.

    Source or binary

    When source code is unavailable, for supplier deliveries or acquired products, we analyse the shipped binary and still return a component inventory and an SBOM.

  • 5.

    Your code stays protected

    Code is transferred over an encrypted channel, processed under NDA, and deleted once the analysis is complete.

  • 6.

    Findings explained to engineers

    Our specialists walk your developers through each finding, propose concrete remediations, and stay available while the fixes are made.

Preview image

BearingPoint FOSS Management Services in 95 seconds

Trusted by Industry Leaders

Respecting open source licensing terms is an integral part of Swisscom’s Corporate Responsibility Governance. BearingPoint has been a reliable partner for performing comprehensive Compliance Checks before software is released. The BearingPoint service is easy-to-use and delivers high-quality results, reliably and on-time. Its standardization, scalability, and flexibility enable us to manage open source compliance very efficiently.

Renato Chastonay, Enterprise Architecture & Innovation at Swisscom

Our collaboration with the BearingPoint team is in the premier league. We have built the highest level of trust and security, which is essential when dealing with one of a company's most valuable assets, its software technology. Working with BearingPoint allows us to conduct our software due diligence risk assessment completely digitally."

Thomas Bauer Senior Key Expert M&A Software Due Diligence at Siemens

Latest insights

What's new!

  • 2026 SBOM Minimum Elements: What Changed for Software Bill of Materials Compliance

    The new SBOM baseline raises expectations for software transparency, supply chain security, and regulatory readiness. Here’s what changed, why it matters, and how BearingPoint helps organizations meet the 2026 requirements.

    Read more
  • Open Source Compliance for Manufacturing

    Gain complete visibility into the open source software used within your products. Our experts create accurate SBOMs, identify license and security risks, support CRA compliance, and provide the evidence needed for audits, customer requests, and regulatory requirements.

    Read more
  • From SBOM to AI-BOM: The Evolution of AI Supply Chain Governance

    From SBOM to AI-BOM: learn how AI Bills of Materials extend software composition analysis to cover AI-generated code, models, datasets and EU AI Act transparency.

    Read more
  • New SBOM management and CRA compliance services to help organizations meet EU Cyber Resilience Act requirements

    Read more

Get in touch

Talk to our specialists and learn how our Open-Source Management Services can help your business.