OpenSSF Best Practices Badge Criteria
The OpenSSF Best Practices Badge criteria for open source projects at passing, silver and gold: 145 criteria, each MUST, SHOULD or SUGGESTED, covering project basics, change control, reporting, quality, security and analysis. Self-attested at bestpractices.dev; criterion text quoted from the official criteria.
OpenSSF Best Practices Badge Criteria is a compliance framework from International (open source ecosystem) with 17 domains and 145 controls that map to 1 other frameworks. The largest domains are Silver level: Quality – OpenSSF Best Practices Badge Criteria (19 controls), Silver level: Basics – OpenSSF Best Practices Badge Criteria (17 controls), Passing level: Security – OpenSSF Best Practices Badge Criteria (16 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (17)
Gold level: Analysis – OpenSSF Best Practices Badge Criteria
| Code | Title |
|---|---|
| openssf-best-practices-badge-criteria::gold.dynamic_analysis | dynamic_analysis (Gold, MUST) |
| openssf-best-practices-badge-criteria::gold.dynamic_analysis_enable_assertions | dynamic_analysis_enable_assertions (Gold, SHOULD) |
Gold level: Basics – OpenSSF Best Practices Badge Criteria
| Code | Title |
|---|---|
| openssf-best-practices-badge-criteria::gold.achieve_silver | achieve_silver (Gold, MUST) |
| openssf-best-practices-badge-criteria::gold.bus_factor | bus_factor (Gold, MUST) |
| openssf-best-practices-badge-criteria::gold.contributors_unassociated | contributors_unassociated (Gold, MUST) |
| openssf-best-practices-badge-criteria::gold.copyright_per_file | copyright_per_file (Gold, MUST) |
| openssf-best-practices-badge-criteria::gold.license_per_file | license_per_file (Gold, MUST) |
Gold level: Change Control – OpenSSF Best Practices Badge Criteria
| Code | Title |
|---|---|
| openssf-best-practices-badge-criteria::gold.repo_distributed | repo_distributed (Gold, MUST) |
| openssf-best-practices-badge-criteria::gold.require_2FA | require_2FA (Gold, MUST) |
| openssf-best-practices-badge-criteria::gold.secure_2FA | secure_2FA (Gold, SHOULD) |
| openssf-best-practices-badge-criteria::gold.small_tasks | small_tasks (Gold, MUST) |
Gold level: Quality – OpenSSF Best Practices Badge Criteria
| Code | Title |
|---|---|
| openssf-best-practices-badge-criteria::gold.build_reproducible | build_reproducible (Gold, MUST) |
| openssf-best-practices-badge-criteria::gold.code_review_standards | code_review_standards (Gold, MUST) |
| openssf-best-practices-badge-criteria::gold.test_branch_coverage80 | test_branch_coverage80 (Gold, MUST) |
| openssf-best-practices-badge-criteria::gold.test_continuous_integration | test_continuous_integration (Gold, MUST) |
| openssf-best-practices-badge-criteria::gold.test_invocation | test_invocation (Gold, MUST) |
| openssf-best-practices-badge-criteria::gold.test_statement_coverage90 | test_statement_coverage90 (Gold, MUST) |
| openssf-best-practices-badge-criteria::gold.two_person_review | two_person_review (Gold, MUST) |
Gold level: Security – OpenSSF Best Practices Badge Criteria
| Code | Title |
|---|---|
| openssf-best-practices-badge-criteria::gold.crypto_tls12 | crypto_tls12 (Gold, MUST) |
| openssf-best-practices-badge-criteria::gold.crypto_used_network | crypto_used_network (Gold, MUST) |
| openssf-best-practices-badge-criteria::gold.hardened_site | hardened_site (Gold, MUST) |
| openssf-best-practices-badge-criteria::gold.hardening | hardening (Gold, MUST) |
| openssf-best-practices-badge-criteria::gold.security_review | security_review (Gold, MUST) |
Passing level: Analysis – OpenSSF Best Practices Badge Criteria
Passing level: Basics – OpenSSF Best Practices Badge Criteria
Passing level: Change Control – OpenSSF Best Practices Badge Criteria
| Code | Title |
|---|---|
| openssf-best-practices-badge-criteria::passing.release_notes | release_notes (Passing, MUST) |
| openssf-best-practices-badge-criteria::passing.release_notes_vulns | release_notes_vulns (Passing, MUST) |
| openssf-best-practices-badge-criteria::passing.repo_distributed | repo_distributed (Passing, SUGGESTED) |
| openssf-best-practices-badge-criteria::passing.repo_interim | repo_interim (Passing, MUST) |
| openssf-best-practices-badge-criteria::passing.repo_public | repo_public (Passing, MUST) |
| openssf-best-practices-badge-criteria::passing.repo_track | repo_track (Passing, MUST) |
| openssf-best-practices-badge-criteria::passing.version_semver | version_semver (Passing, SUGGESTED) |
| openssf-best-practices-badge-criteria::passing.version_tags | version_tags (Passing, SUGGESTED) |
| openssf-best-practices-badge-criteria::passing.version_unique | version_unique (Passing, MUST) |
Passing level: Quality – OpenSSF Best Practices Badge Criteria
Passing level: Reporting – OpenSSF Best Practices Badge Criteria
| Code | Title |
|---|---|
| openssf-best-practices-badge-criteria::passing.enhancement_responses | enhancement_responses (Passing, SHOULD) |
| openssf-best-practices-badge-criteria::passing.report_archive | report_archive (Passing, MUST) |
| openssf-best-practices-badge-criteria::passing.report_process | report_process (Passing, MUST) |
| openssf-best-practices-badge-criteria::passing.report_responses | report_responses (Passing, MUST) |
| openssf-best-practices-badge-criteria::passing.report_tracker | report_tracker (Passing, SHOULD) |
| openssf-best-practices-badge-criteria::passing.vulnerability_report_private | vulnerability_report_private (Passing, MUST) |
| openssf-best-practices-badge-criteria::passing.vulnerability_report_process | vulnerability_report_process (Passing, MUST) |
| openssf-best-practices-badge-criteria::passing.vulnerability_report_response | vulnerability_report_response (Passing, MUST) |
Passing level: Security – OpenSSF Best Practices Badge Criteria
Silver level: Analysis – OpenSSF Best Practices Badge Criteria
| Code | Title |
|---|---|
| openssf-best-practices-badge-criteria::silver.dynamic_analysis_unsafe | dynamic_analysis_unsafe (Silver, MUST) |
| openssf-best-practices-badge-criteria::silver.static_analysis_common_vulnerabilities | static_analysis_common_vulnerabilities (Silver, MUST) |
Silver level: Basics – OpenSSF Best Practices Badge Criteria
Silver level: Change Control – OpenSSF Best Practices Badge Criteria
| Code | Title |
|---|---|
| openssf-best-practices-badge-criteria::silver.maintenance_or_update | maintenance_or_update (Silver, MUST) |
Silver level: Quality – OpenSSF Best Practices Badge Criteria
Silver level: Reporting – OpenSSF Best Practices Badge Criteria
| Code | Title |
|---|---|
| openssf-best-practices-badge-criteria::silver.report_tracker | report_tracker (Silver, MUST) |
| openssf-best-practices-badge-criteria::silver.vulnerability_report_credit | vulnerability_report_credit (Silver, MUST) |
| openssf-best-practices-badge-criteria::silver.vulnerability_response_process | vulnerability_response_process (Silver, MUST) |
Silver level: Security – OpenSSF Best Practices Badge Criteria
Maps to 1 other framework
Coverage is not the same as your position
This page shows what OpenSSF Best Practices Badge Criteria overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.
The Compliance Position Diagnostic, $5,000 fixed, ten business daysWhat is OpenSSF Best Practices Badge Criteria and who does it apply to?
OpenSSF Best Practices Badge Criteria is a compliance framework from International (open source ecosystem) with 17 domains and 145 controls. The OpenSSF Best Practices Badge criteria for open source projects at passing, silver and gold: 145 criteria, each MUST, SHOULD or SUGGESTED, covering project basics, change control, reporting, quality, security and analysis. Self-attested at bestpractices.dev; criterion text quoted from the official criteria. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does OpenSSF Best Practices Badge Criteria actually require?
OpenSSF Best Practices Badge Criteria has 145 controls organised across 17 domains. The largest domains are Silver level: Quality – OpenSSF Best Practices Badge Criteria (19 controls), Silver level: Basics – OpenSSF Best Practices Badge Criteria (17 controls), Passing level: Security – OpenSSF Best Practices Badge Criteria (16 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of OpenSSF Best Practices Badge Criteria do I already cover?
OpenSSF Best Practices Badge Criteria maps to 1 other compliance frameworks. The top mapping partners are NIST SP 800-218 (34% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement OpenSSF Best Practices Badge Criteria?
Start your OpenSSF Best Practices Badge Criteria compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about OpenSSF Best Practices Badge Criteria requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 145 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 868 frameworks.
Get Started Free →Free forever — no credit card required