Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The CII Best Practices Badge was a free, project-level way for open-source software projects to document security and development practices. It still exists under a new name: the program was formally renamed the OpenSSF Best Practices Badge on December 24, 2021. Projects now use BadgeApp to answer criteria and receive automated checks; the badge is not an individual certification. OpenSSF Best Practices Badge

What was the CII Best Practices Badge?

The CII Best Practices Badge was a public badge program for Free/Libre and Open Source Software (FLOSS) projects. A project used the BadgeApp web application to describe how it developed and secured its software. Its answers and justifications were public, so users could review the practices behind the badge rather than relying only on a label. The Linux Foundation described it as a free, self-service program designed with the open-source community. Linux Foundation program introduction

The badge was awarded to a project, not to a maintainer or developer as an individual. It was intended to help consumers assess whether a FLOSS project followed practices associated with higher-quality, more secure software. Linux Foundation explanation OpenSSF program page

Is the CII badge still available?

Yes. The program continues as the OpenSSF Best Practices Badge and is maintained by the OpenSSF Best Practices Working Group. The formal rename occurred on December 24, 2021. The current BadgeApp remains free and self-service. BadgeApp OpenSSF Best Practices Badge

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How does a project get a badge?

  1. Open BadgeApp. Visit the OpenSSF BadgeApp and start a project profile.
  2. Choose a criteria family and level. BadgeApp supports the traditional Passing, Silver, and Gold levels as well as OpenSSF Baseline levels.
  3. Answer the criteria with explanations. Provide the requested project information and justify answers. The public responses make the project’s claims reviewable.
  4. Address automated checks. BadgeApp automatically checks many criteria; a project must also maintain the underlying practices and evidence as its software and processes change.

What do Passing, Silver, Gold, and Baseline mean?

Passing, Silver, and Gold are increasing levels in the original metal series: Silver and Gold add more demanding practices to the foundation established at Passing. Baseline is a separate criteria family supported by the current site, not another metal level. The specific Baseline criteria are not detailed in the cited program summary, so compare them in BadgeApp rather than assuming they map one-to-one to a metal tier.

Option Criteria family Assurance depth and examples Evidence and scope
Passing Metal series Foundation-level criteria include a stable project website, an explicit FLOSS license, HTTPS, secure installation and API documentation, public version control and release notes, tracked bugs and vulnerability reporting, working builds, static analysis, automated tests, dynamic checks such as fuzzing or web scanning, and developers familiar with secure software. Project answers and justifications are public; many criteria receive automated checks.
Silver Metal series Adds documented governance, a bus factor of at least two, security requirements, dependency monitoring, at least 80% statement coverage, signed releases, input validation, and hardening. Project practices, not individual credentials.
Gold Metal series Adds two unassociated significant contributors, two-factor authentication, review of at least 50% of modifications, reproducible builds, continuous integration, at least 90% statement coverage, at least 80% branch coverage, modern TLS, and a security review. Project practices, not individual credentials.
OpenSSF Baseline Separate Baseline family The program supports Baseline levels, but the cited program summary does not enumerate their criteria. Use BadgeApp’s current criteria for the applicable Baseline level.

Criteria and thresholds above describe the program summary, not a guarantee that every project or software ecosystem can satisfy them in the same way. Coverage percentages refer to the stated statement- or branch-coverage criteria; they are not by themselves a security certification.

What does the badge prove—and what does it not?

The badge makes a project’s reported practices easier to inspect and provides automated checks for many criteria. It is a useful signal about development and security processes, not proof that software is vulnerability-free, a guarantee of quality, or a personal qualification for a developer. Readers evaluating a project should inspect its answers and justifications, including how it handles vulnerability reports, testing, releases, and governance.

The OpenSSF repository says that 10% of projects pursuing a Passing badge achieve it. That figure is presented as an average program-level estimate, not as a current success-rate measurement. An older Linux Foundation BadgeApp description reported 94% statement coverage and more than 3,000 checked assertions for the service; those are historical descriptions of BadgeApp, not current performance measurements or requirements for badge applicants. OpenSSF Best Practices Badge repository Linux Foundation BadgeApp description

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What should a project consider before pursuing one?

Badge pursuit is most useful when a project is willing to make its practices and explanations public and keep them current. Higher levels entail more ongoing work: documentation, testing and coverage, dependency monitoring, vulnerability response, review, release signing, and other operational practices. The badge is free, but meeting and maintaining its criteria takes contributor time.

  • Use it as a transparency tool: clear, accurate responses are more valuable than treating the badge as a marketing label.
  • Match ambition to capacity: begin with criteria the team can sustain, then address gaps before targeting a more demanding level.
  • Keep evidence aligned with reality: development workflows, dependencies, contributors, and security processes change, so revisit answers when project practices change.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.