FOSS Backstage

Michael Weinberg – Lessons from 10+ Years of Certifying Open Source Hardware #FOSSBack

25:31 · 16 Mar 2026 – 17 Mar 2026 · YouTube

About this talk

This talk focuses on the certification program for open source hardware, presented by Michael Weinberg of the Engleberg Center at NYU Law School and Ashwa, the Open Source Hardware Association. The speaker discusses the challenges faced in defining and certifying open source hardware, particularly the issues of misaligned expectations in the community due to the lack of ownership over the term 'open source hardware.' He explains the community-driven certification process, its lightweight and free application system, and how it facilitates engagement among newcomers. The session also highlights the impact of the program, which includes over 3,000 certified projects, improved documentation, and a practical approach to handling user contributions while navigating the complex nature of hardware. Additionally, the talk touches on the upcoming Open Hardware Summit and encourages attendees to explore the resources available through the certification program.

Full transcript

Thank you all. Thank you so much. I know this is the last talk on the last day. So, we were saying we're going to drag everyone across the line and talk about something that's that's very related to open and open source software, but open source hardware. So, like a little twist uh for the end of the day. Uh I'm Michael Weinberg. I'm wearing kind of two hats

today for this presentation. Uh, one is, uh, I'm with the, uh, a research organization, uh, called the Engleberg Center on Innovation, Law, and Policy at New York University Law School, although I'm actually based here in Berlin. And I'm also a longtime board member of Ashawa, the Open Source Hardware Association. And so those two things kind of come together in the world of open hardware certification. Um so

quickly the Angleberg Center uh the reason that that is relevant for this conversation is that we are a research center at a law school in the US and so we do a lot of research on how open hardware works uh and how it kind of works in practice in law in policy and so if you are someone who thinks about open hardware or open software in those

contexts uh these are some reports that we've done we're kind of talking about it all the time and so I'm happy to chat about that later the probably more important Important part of this is uh my role at Ashwa, the open source hardware association. I don't know are people like familiar familiar-ish with Ashwa? Give you a good introduction. This is good. This is a good opportunity. So

Ashwa is the community organization for open source hardware. Uh it is what it sounds like it is. And Ashwa's been around for almost 15 years now. And we do a whole collection of things. Uh so one thing that we do is the open hardware summit every year. I'm going to talk about that again at the end, but the open hardware summit this year is actually here in

Berlin in May. And so if you are kind of excited about open hardware, that might be worth checking out. We're also we also are the home to the open hardware definition. This is the community definition of open hardware. It will feel very familiar for those of you who are familiar with the open software definition just ported to hardware. We run the open source hardware certification program that

I'm going to be talking about a little bit more today. We also do a regular kind of community showand tell to see what's going on uh in the world of open hardware. We run open hardware month which is in October which is a great time to kind of get engaged and get connected to open hardware. And then we also have this new initiative called open healthware which

is specifically for open hardware that's tied to the medical and health community. So obviously uh the theme running through this is open and hardware. All these things are open hardware related and this is sort of what Ashwa is all about right that's it's a role in the community to engage with opensource So this talk is all about the certification program and I'm going to talk about what

we've learned. But before I talk about what we've learned, I want to explain why we did this in the first place uh and what decisions we made along the way because there's a lot of decisions about kind of community management that I think is relevant in other spaces. So when we were thinking about putting together this certification program, we had kind of four main problems we were

trying to address. uh and these are problems in a specific context. They aren't necessarily problems in like the larger concept of openness, but they were problems for us. Uh one is no one owns the term open-source hardware. And so on one hand that's great, right? Anybody can say this is open source hardware. Uh but you can also you create problems where people have uh mismatch expectations. Uh

and relatedly there's an open gear logo that Ashwa actually is the steward of but Ashwa and no one controls the open gear logo and so similarly uh anyone can use it no matter what their relationship is to open hardware and the result of this is uh there's a kind of a good faith version of this problem and a bad faith version of this problem. The good faith

version is there were people who were creating what they thought of as open hardware and releasing it to the community under their expectations of open hardware and then community members were seeing it we're trying to use it we're trying to build on it and the community members expectation of open hardware was different right so there's a misalignment there's also a bad faith version of this problem I

actually just came from a talk on openw washing and so as you can imagine there were lots of people running around and continue to be lots of people running around saying this is open source hardware just don't ask me for any of the schematics like don't ask we're not it's not really that well you know we'll we'll after our successful Kickstarter we're going to be excited to

release all of the stuff and so there was just a problem where there were people who were saying this is open hardware and talking about open hardware in a way that was uh disrupting expectations in the community there was a related problem around inconsistent gatekeeping and this is not a kind of new problem for online communities not a new problem for open source communities where we had

people and we had companies who said I want to do open hardware but it's complicated and my concern is that if I if I mistakenly mess something up even if it's in good faith the community is just going to come after me and I'd rather just stay away and so that was keeping people out of the community and this was a problem so we had these these

sort of no shared expectation with this this expectation mismatch and we this expect we this uh inconsistent gatekeeping that we were trying to resolve and so we thought to ourselves okay uh well one thing that we do have as ashua is this definition right is this open hardware definition that the community helped develop that the community stands behind so it's a single point of reference that kind

of a majority of people in the community feel comfortable with and so what if We use that definition to build out a certification program. The certification program will use a new logo that Ashawa controls and issue some information that is within Ashua space. And so what that allowed us to do is to say okay um we have a shared definition. So it makes it easy to understand

what this version of open hardware is. Ashwa someone Ashua controls the use of it and so if someone is trying to use it in a way that breaks the rules something can happen. Also if you're a new entrant to the community and you go through the certification program and someone from the community starts saying oh you're doing it wrong or there's a problem. Ashua can be your

ally and say at a minimum they went through this process in good faith and we're gonna help resolve the issue. And then the final piece was, you know, a certification program only matters as much as anyone cares about it. And so the downside risk was pretty low. Like if it turns out this wasn't a good idea and no one cared about it, like who cares? We'll all

just walk away and pretend it never happened. So we moved forward. We did about it was actually about a excuse me about a year-long uh consultation process with the community. We had a lot of questions we asked about the shape and the size and there was some really core design decisions that we made in rolling it out. One that it was it was free. So we talked

about different fee structures. We talked about different ways to be able to to structure it. And we ultimately decided it's better if it's free. Anyone can do it. Anyone can jump in. we're not going to worry about like paying to to be able to use the The second one was that there were no tiers. So I mean many of us are familiar with kind of lead certified

or other certification programs where it's like you know silver well they're like platinum super platinum triple diamond whatever it is and you can think about a lot of different like what parts of open hardware would be open to match those tiers. But ultimately we decided that was just too complicated both to administer and from a messaging standpoint. So, we wanted people to know like what does it

mean when they see the open hardware logo. We also knew that it needed to be lightweight to run. Ashwa is mostly volunteer-driven organization. We have some staff, but we're we're a small organization that kind of punches above our weight. And we knew if this required a giant infrastructure with a bunch of permanent employees, it might not work. I mean, especially C, like it's free, And so finally

we decided not to implement expert review. And this is something that's very specific. It is each application is reviewed by someone who's an expert in open-source hardware but not a subject area specialist because open hardware is incredibly vast. You know there are microcontrollers that are open hardware. There are robots that open hardware. There's camping gear that's open hardware. There's knitwear that's open hardware. There's perfume that's open

hardware. And so to have subject area experts on call for every single one of those areas wasn't going to be sustainable. We have another way to deal with it. But we decided that would make it uh the opposite of lightweight to And so if you're thinking right now like okay uh this more or less makes sense but hardware is different than software because there's a lot of

components in hardware that aren't necessarily open source and don't necessarily come from uh someone who creates an there aren't open source alternatives. So what does it mean to be open and how do you handle that problem? And this was something that was a big part of the community discussion and ultimately we decided on this idea of the user contribution. So the idea of the user contribution is

if you are creating hardware the things that you do have to be open you created them. You have the legal ability to openly license them to make the documentation available. You have to do that for everything else. that is outside of your control, right? You can't go and force somebody to open source a microcontroller or an LED or whatever else it is. You have to document it

well enough that someone else can find it and it has to be generally available, which in practice means you have to be able to access it without signing an NDA. And so this user contribution allowed us to kind of allow open hardware to work in the real world, right? the contribution, the design that you do, you have to open source, but we live in the real world

with closed components. And so, as long as those are documented and available, that's totally fine. So, how does this program work? Uh, it's pretty straightforward. There is an application. It takes less than five minutes hopefully to fill out on the Ashwa site. So, you fill out information about, you know, where is your documentation, what licenses do you use, uh, you know, who are you, how do we

contact you, things like that. It goes into a review queue. If everything is fine, then it just moves right through the review queue. But very often, there are questions that the review team will have and they'll send they'll email back and forth with the creator to get things straightened out. And this has turned out to have a really great side effect of being a good entry point

for people into the community because if you're new to open hardware and you submit your certification, you might get an email from someone on the team that says, "Hey, this project looks great, but you're missing this kind of documentation or like you're missing a license or you're missing this thing." And it allows you to kind of meet the community expectations without uh having to kind of do

it in public and and get uh maybe get someone yelling at you on the internet. Once you move through the process, then you get issued a license to use this certification logo and you get a unique identifier for your And that unique identifier can be used in the directory that houses all of the open hardware to be able to find it. And so if you're holding open

hardware that's certified in your hand, very often they will be the unique identifier there which points to the directory. The directory is not a repository. We don't hold all your we don't say you have to use this platform to do your documentation. We don't hold all your documentation. It's just pointers to where the documentation is. So again, lightweight to run, easy to use. So that's how the

system works. Uh what what have we finally getting to the point of this talk? Like what have we learned about doing it for now a decade? The first thing we've learned is open source hardware is really is everywhere at this point. This screenshot is actually from the website from yesterday. So this is a pretty accurate number. We have over 3,000 pieces of certified open source hardware from

over 60 countries on every continent except Antarctica. And I always mention that when I'm talking about open source hardware because someday someone in the audience is going to be like, I know somebody in Antarctica that is making open source hardware and so then we can get that certified and like I could knock that talking point off. So if you know somebody, uh, come find me. I love

the chat, help them do it. Um, and you can also track this on the on the actual website. So this is like great. It's an easy way to see and if you're wondering, if you're new to open source hardware and trying to understand what open source hardware is and what are examples, this creates a great entry point for you because you can explore what's happening in it.

uh you know on the map if you want to go by country but also the directory has all sorts of information about all sorts of different types of open source hardware and open hardware really is an incredibly broad category I think you know when open hardware started a lot of people were thinking uh you know PCBs 3D printers kind of electronics there is a lot of electronics

in open source hardware there's a lot of many other things right we've got jewelry uh we've got people who are doing knitting. I mentioned perfume, camping equipment, musical equipment, all sorts of environmental sensors that people are doing for research, lab equipment, exercise things. Basically, if it is physical, if it's made of atoms and it is open, it is Another thing that we've learned is that sort of

the system that we built to not have to have experts has worked really well. So the way this system is intended to work is, as I mentioned, you know, you submit your application. It gets reviewed by someone who is an open source hardware expert, but isn't necessarily a subject area expert. They get it all sorted out, you get certified, you go in the directory, it goes out

in the world. If someone is trying to use your documentation to actually modify, build upon, use your hardware, who's an expert in the space and finds a problem, they reach out to Ashwa and says, "Hey, I'm trying to use this this this documentation for this piece of hardware. I think there's a problem." At that point, Ashwa will bring in an expert to ask them to take a

look. If the expert agrees that it might be a problem, we reach out to the creator and we say, "Hey, someone's trying to use your hardware. That's great. They've raised this concern. What do you think?" And sometimes the creator will say, "Uh, you're right. It's missing this thing. I've updated the repo. Everything is cool." Sometimes the creator will say, "I think you're wrong. I think actually it

doesn't need this." and we'll actually like mediate the conversation to make it a kind of a civil and decide sometimes the creator is right, sometimes the the user is right, but we actually investigate it and make it do it in a way that people feel like they have been heard and we've gone through a process and you know sometimes people just say you're right uh it's not

enough and I'm just going to I'm going to withdraw. I don't want to be involved in this which is also fine, right? Which is great. So this has worked as a as like a civil dispute resolution process as opposed to other internetbased methods of uh resolving conflict which have a a variable track record I think we're all familiar with. It has definitely resulted in improved documentation because

it's a mechanism for user feedback and we also have revoked certification which I think is a good thing. I mean it's sort of bad in the moment but the fact that we re we revoke certification every it happens like once every year or 18 months that means that when you see the certification logo it means something right it means that it's like it's real because if it

wasn't real then it may have been revoked something that people talk about a lot is this idea of like I'm gonna build a GitHub for hardware right because GitHub is is is has has its its strengths and weaknesses is not optimized for hardware. Um, one thing that we have learned is at this point, GitHub is the GitHub for hardware. Um, there's a really long tale of where

people put So, I don't want to suggest that everything is on GitHub, but when you look, uh, GitHub is where things are clustering. And that's not a surprise, right? A lot of people are comfortable in that space. It's a way to easily and, you know, like post your stuff publicly. So even GitHub may not even be your primary kind of working space but it's a primary sharing

space. Uh so that's kind of where we are right now but people do all sorts of things to share their We had this idea when we started the program that one of the benefits of it would be to kind of offload the evaluation of open hardware. And this kind of works you can imagine this like this works with uh software licenses too right? If you want to

know if some software is open source, you ask yourself kind of two questions, right? Can I find the source and does it use a license that I think is open? And then you can kind of stop looking. And hardware openness is a little bit more complicated. You have to like look a little bit deeper. The legal parts are a little bit more complicated. The documentation parts are

a little bit more complicated. But if you see the certification logo, you can say, "Great, I'm just going to assume that it's open and I'm going to do something else that I'm gonna I'm going to focus on a different part that I care about. This has worked. Okay. Um there's a journal, academic journal, hardware X that is focused on open source hardware and they say if you

come to us with certified hardware, we're just going to assume that it's open and kind of move on with our review. Similarly, we're we're deep working in deep collaboration with the with the Dinsspec folks uh here in Germany who are doing a much more intensive level of review. And one things that one thing that we're collaborating with them about is kind of offloading the easy initial review

to the Ashwa certification program so they can focus on their much more in-depth review. And then the last thing is this open healthware program that I mentioned at the top. This is a new area for Ashwa where we're really focused on medical supplies, medical devices and that is a much more intensive subject area specific review. And one of the things that we're looking at building that for

is to say look step one is to do the is it open hardware review and that's what the certification program does. And then step two is is it open healthware? Does it have the additional documentation? Does it have the additional testing? Have all the additional things that we need for open healthare and allows you to kind of separate those two analyses and separate the teams. So that's

working kind of like reasonably well at this point. We do have citations built into the directory and people do use those. They don't use them as much as we thought when we built it, but people will say, "Oh, this is my hardware and maybe this is version three of something that I built and here's version one and version two." Or they will say, "This is my hardware

and it's building off of these other pieces of hardware, some certified, some not." And so you can use that information to kind of build a little bit of a web and an evolutionary tree of open hardware. A couple years ago, we built this API that I think is great. Um, it's a read write API. So if you want to build applying for certification into your workflow, you

can do that and submit your your application automatically. And we do see some people who are doing that, especially companies who kind of certify at scale. It allows them to sort of submit as part of their workflow. It's been really effective. There's also a read API where people can uh explore all the certification directory and kind of see what's been done. People use it a little bit.

Uh and usually when I'm talking about it, I'm kind of like the API is good, but it's not lighting the world on fire. But I will say that I actually had a conversation uh yesterday with somebody with a platform that is interesting in interested in using the API to kind of integrate their platform more directly with the certification program. Uh if that turns out to work then

I will say the API is a roaring success and I will have to like change this. I will stop talking about it being not that popular. But even if it, you know, however it's used for the application side, we have found it to be super useful on the data analytics side because it really does allow you to just pull down information about all 3,000 plus pieces of

certified hardware and do all sorts of digging. And so we've started kind of poking around and and publishing. I think we published a kind of an initial review at the end of last year. We'll probably do uh a new kind of deeper dive into the data for open hardware month in October, but the API just makes that really possible and really straightforward to do. And then I'll

also say uh one thing that we have learned, this is nothing to do with hardware, but like static site architecture is amazing. Uh you know, one of the key goals was to make it lightweight to run. So we built this certification. This is actually version two of the certification infrastructure. We built that in 2018 and have basically spent zero dollars on maintaining it since and it just

like works. It's so beautiful to have a piece of software that you can kind of build once people use all the time and it just kind of runs. So, uh big endorsement for static sites as a structure. Uh we love it. We use it for everything now. And you can see then also uh you know I mentioned the directory, right? Like this is the information that's in

a directory. You can do all sorts of filtering by country, by product type, by license. Uh you can do kind of plain text search. And so it's a real way to kind of explore what's going on. Um so I'm I'm running out of time. So I will say first uh maybe it's time if you're here to think about certifying. It is free. It is fast. certification.ashwa.org or

in addition to the directory and the certification process, there's a lot of documentation about how to do documentation, how to think about licensing, there are lots of examples of hardware that do that. So if you want to learn more about open hardware and kind of as a practice, the site's a great place to do that. And then I will also mention um as I said at the

top, Open Hardware Summit is coming to Berlin uh in just a few months. It's here at the 23rd and 24th of May. And so if you have not started looking at open at the open hardware summit, this is a really good opportunity to check it out. Uh 2026.ashwa.org. Um it's like an amazing two days of people who are just doing all open hardware. You got people who

are doing it uh in academia, you've got artists, you've got people who are doing it uh in industry, just like the whole space of open hardware. There's usually someone talking about putting collars on uh elephants to track them through the wild or counting how many moths are in the jungle. There's just like all sorts of crazy stuff that is happening at the Open Hardware Summit. Um so

that's it. Uh I've got maybe a minute or two for questions if people have questions, but uh I will say thank you all so much for for coming to this last talk on the last day. I really appreciate it. Yeah, thanks. Uh, Michael Weineberg, thank you.

From event

FOSS Backstage

16 Mar 2026 – 17 Mar 2026

All event videos
Back to Watch