Getting started
OSS SSC Framework
The Open Source Software (OSS) Secure Supply Chain (SSC) Framework is a combination of processes and tools for any organization to adopt to help establish a secure OSS ingestion pipeline to protect developers from OSS Supply Chain threats, and to establish a governance program to manage your organization’s use of OSS.
Maturity Model
The OSS SSC Framework is made up of 8 practices, but not all practices can be done all at once. Adopting the OSS SSC Framework will go through levels of maturity so you can prioritize the requirements.
Open Source Software Threats
The OSS SSC framework provides the support to protect your supply chains from real-life threats from compromising your organization's software and development environment.
Consulting Services
Discover how Microsoft Industry Solutions can help you adopt and implement the OSS SSC Framework.
Community resources
As supply chain continuously evolves, so must the frameworks that
we use to properly secure them. For this effort, we want to make
this framework as contributable and open as possible. Please see
the Community Resources page to see how we plan to do this
with organizations such as the OpenSSF.

