OpenSSF project

Best Practices Badge

A voluntary self-certification program that lets open source projects demonstrate they follow recognized development best practices.

How each persona uses Best Practices Badge

Software Developer / Maintainer Developer

Achieves the Best Practices Badge to voluntarily self-certify and demonstrate their adherence to secure development standards.

See everything for Developer →

Open Source Professional (OSPO) OSPO

Mandates the achievement of the badge across internal open source projects to demonstrate a commitment to security and quality.

See everything for OSPO →

Security Engineer / Architect Security

Uses the Best Practices Badge as a signaling mechanism to verify that a project adheres to good practices.

See everything for Security →

CI/CD DevOps & Tooling Integrator DevOps

Integrates badge status checks into the pipeline to block the inclusion of dependencies that fail to meet baseline security practices.

See everything for DevOps →

Package & Repository Manager Package Manager

Uses the badge as a metadata indicator to highlight secure and well-maintained packages to end users in the repository.

See everything for Package Manager →

Executive / End-User Consumer Executive

Uses the badge as a trust signal to make risk-aware procurement and enterprise decisions.

See everything for Executive →

Problems Best Practices Badge helps with

Measuring Security Posture Posture

Turns adherence to recognised practices into a single, comparable trust signal that consumers can read at a glance.

See everything for Posture →

Policy & Compliance Enforcement Compliance

Gives organizations a published bar that internal projects can be required to meet and demonstrate.

See everything for Compliance →