Skip to content

Companies: buying and complying

This page is for the person who has to make a compliance state true and provable. The legal reasoning is in the OSPO and legal pack; this is the mechanics.

A dual test, measured across the whole consolidated group — the entity plus everything that controls it, is controlled by it, or is under common control with it, whether by ownership, votes, contract, or otherwise:

  • fewer than 100 individuals working as employees and independent contractors, counted together; and
  • total revenue below the published threshold figure for the prior tax year, in 2026 dollars, indexed to consumer prices, converted at that year’s average official rate.

Both must be true to be below the threshold. If they are, you owe nothing, register nothing, and hold no credential: the licence behaves permissively for you, and the coverage answer is no-entitlement-required-under-threshold.

If you are above it, you need a current credential to use versions published after you crossed — and crossing opens a 60-day cure window, so growth is never an overnight violation.

LaneScopeStatus
ProjectOne repositoryPurchasable at launch
PortfolioEvery repository of one administrator, flat regardless of countLaunch-ordered
the PassEvery registered repository, present and futureLaunch-ordered
Donation EntitlementSatisfies the condition on proof of a direct donationA compliance lane, not a priced product — see §8

Two ordering rules are published rather than left to be discovered:

  • the Pass always dominates at scale. No stack of single-lane Entitlements may cost less than the Pass for the same coverage. If you use more than a handful of registered projects, the Pass is the cheap answer, and it is meant to be.
  • One published schedule for everyone. Prices are set only in the versioned fee schedule. Nobody — not a repository administrator, not the Association — agrees a private price, a discount, or a side term (Art. 9 of the statutes). A request for bespoke terms is answered by pointing at the amendment process: propose a change for everyone.

Price depends on your band, which is a range of consolidated-group revenue. Multipliers between bands are published (2× / 5× / 10×) so the shape of the schedule is predictable rather than negotiable.

You state your own band: one binding, timestamped tick at checkout. That is the entire mechanism, and the things that are not part of it are the point:

  • No audit right. No inspection clause. No reporting duty. Not in the licence, not in the Entitlement terms. Their permanent exclusion is a never-reopen item (what we can never do) — an audit clause is a categorical procurement veto, and we would rather not have one than have one and promise not to use it.
  • Under-certification is a true-up. Certify low by mistake and the remedy is paying the difference for the period concerned. The Entitlement is voided only for a knowingly false certification, and a voided credential is recorded as voided, not deleted.
  • Growth mid-term does not reprice the term. Crossing into a higher band takes effect at renewal.
  • Nothing about your revenue is published. The registry publishes that your organisation holds an Entitlement, and its lane. Your band drives the price; it is not part of the public record.

At purchase, and at renewal, you declare which registered projects you use. This is what lets a Purpose Fee be attributed to the projects it came from, so the routing tiers have something to work with.

  • Declarations are used for routing and for aggregate reporting. A declaration is never published as a per-organisation list of dependencies — that would be a free dependency graph of your estate, which is nobody’s business.
  • A declaration you get wrong is not a violation; correct it at any time. Coverage does not depend on it: a Pass covers every registered repository whether or not you declared it.
  • An honest note on incentives: a Project Entitlement’s coverage does depend on naming the right repository. If you are unsure which repositories your build actually pulls in, the Pass removes the question, and that is a reason it exists.

The formula, identical in the licence text, the Entitlement terms, and on every certificate:

A version is vested if and only if its publication date falls on or before the end of the paid term.

  • At activation: the whole back catalogue of every covered project, plus everything published during the term.
  • Renewal extends the term end into the next year’s releases. Terms are annual, renew only on your action — no automatic renewal, no auto-charge — and a notice goes out before expiry.
  • Vesting is permanent. Non-renewal, project exit, delisting, waiver revocation, and the Association’s own failure cannot reach a vested version. Lapse acts only on versions published afterwards.
  • Grace: for 30 days after expiry the coverage answer is lapsed-in-grace rather than no; after that the licence’s own cure window governs.
  • Worst case, for the risk register: pin what you have vested and wait. Every version becomes Apache-2.0 on its own fourth anniversary, and the steward-lapse backstop turns the licence permissive if the Association stops operating. Your exposure does not scale with our survival odds.
  • Amnesty covenants on purchase. An Entitlement carries covenants not to sue for past use from the Association and from the project’s steward of record.
  • It cannot release other contributors’ claims, because nobody can release a claim they do not hold — the licence is granted per licensor. A broader release would need a voluntary contributor enforcement mandate, which does not exist today. Anyone telling you a purchase buys a total release of the past is describing something unbuilt.
  • A credential is expressly not a warranty that the registered code is non-infringing, and carries no IP indemnity. The Association holds no rights in any project’s code and audits no repository’s provenance. This is stated in the Entitlement terms rather than discovered later.

7. Waivers — the free path, when a project offers it

Section titled “7. Waivers — the free path, when a project offers it”

A repository’s administrator may grant your organisation a gratis, public waiver for that repository. If you are asking whether to buy or to ask, ask first: it costs nothing to ask and the answer is public either way.

  • Waivers are always public and always gratis. Selling or brokering one is a delisting offence (Art. 8).
  • They are repository-scoped and revocable prospectively only, and they vest by the same formula with “term end” = revocation or expiry.
  • A waived organisation gets a licence-status certificate (“waiver”), never a supporter or impact certificate. You funded nothing on that path, and a certificate that implied otherwise would be a misleading claim.

Full rules and how to ask: waivers.

If your policy prefers giving directly, a Donation Entitlement satisfies the licence’s condition on proof of a documented direct donation, of the amount the published schedule states for your organisation, to a charity on the Association’s published list. The money never passes through the Association, which takes no fee on this path.

  • Recorded in the same registry, answering the same coverage question — so verification stays uniform across lanes (yes-via-donation).
  • The evidentiary standard for the proof is published in the registry’s own terms and is under counsel review; it is not stated here as though it were settled.
  • Certificates on this lane state the lane. A direct donor is not described as having paid a Purpose Fee, and a payer is not described as having donated.

For an internal register or an auditor’s request, the registry exports the coverage facts as CSV. The shape is stable and additive-only.

The sample below is illustrative — sample rows, not a record of any organisation — and no amount in it describes a real transaction:

# purpose-licenses.csv — illustrative sample, not a record of any organisation
entitlement_id,organisation,lane,band,period_start,period_end,status,fee_amount,fee_currency,repos_scope,certificate_id,verify_url,entitlement_record
ent_01j0000000000000000000000,Example Industries AG,pass,10-100M,2027-01-01,2027-12-31,active,12000,USD,*,cert_01j0000000000000000000001,https://purposesource.org/verify/cert_01j0000000000000000000001,https://api.purposesource.org/v1/entitlements/co_01j0000000000000000000002.jws
ent_01j0000000000000000000003,Example Industries AG,project,10-100M,2026-11-01,2027-10-31,active,2400,USD,R_kgDOEXAMPLE01,cert_01j0000000000000000000004,https://purposesource.org/verify/cert_01j0000000000000000000004,https://api.purposesource.org/v1/entitlements/co_01j0000000000000000000002.jws
ent_01j0000000000000000000005,Example Industries AG,waiver,,2026-09-15,,active,,,R_kgDOEXAMPLE02,cert_01j0000000000000000000006,https://purposesource.org/verify/cert_01j0000000000000000000006,

Column notes, because a CSV that needs a phone call is not an export:

ColumnMeaning
entitlement_idStable identifier of the credential
laneproject · portfolio · pass · donation · waiver
bandEmpty for a waiver, which has no price
period_endEmpty for a waiver, which ends on revocation rather than on a date
statusactive · lapsed-in-grace · expired · revoked
fee_amount / fee_currencyEmpty on the waiver and donation lanes; integer major units plus an ISO code
repos_scope* for the Pass, otherwise repository node ids, semicolon-separated
verify_urlThe one place a certificate is verified. verify only at purposesource.org/verify
entitlement_recordThe signed record a scanner can verify offline against the published key set
  • In an SBOM, record the project’s licence exactly as its LICENSE file states it. Until an SPDX identifier is listed, that means a LicenseRef- style custom identifier in SPDX documents, or the licence name plus the canonical text URL in CycloneDX. Do not map it onto a similar-looking identifier: a wrong identifier is worse than an unknown one, because it will be trusted.
  • Your entitlement is not an SBOM field. SBOM formats describe components, not your organisation’s credentials. Keep the signed entitlement record and the export above in your compliance register, and reference them from the policy exception rather than from the bill of materials.
  • Scanner policy. The signed entitlement record is designed to plug into a policy engine: it is a static, unauthenticated, ETagged document that answers “does this organisation hold a current credential?” without a key, an account, or a rate limit a normal review would notice. Guidance for configuring the exception, and the “unknown licence” flag you will see until listing, is in the OSPO and legal pack.