LICENSEWARE

Implementing ISO/IEC 19770-2 software identification tags

Learning resource: migrated from the LICENSEWARE Notion wiki (ISO/IEC 19770, Educational Modules, last edited 2024-12-17). It is training material, not a cited encyclopedia article; for the cited reference see ISO/IEC 19770 and Software asset management.

On This Page

In today’s complex software ecosystem, maintaining an accurate and up-to-date inventory of software assets is a critical aspect of effective Software Asset Management (SAM). The ISO/IEC 19770-2:2015 standard on Software Identification (SWID) tags was established to help organizations enhance software visibility, improve data accuracy, and streamline compliance and licensing processes.[1] By embedding standardized metadata directly into software products, SWID tags act as a “digital fingerprint,” enabling more efficient software discovery, usage tracking, and compliance verification.

This guide provides a practical roadmap for implementing ISO/IEC 19770-2:2015 in your SAM strategy. Whether you’re starting from scratch or looking to improve existing processes, we’ll cover what SWID tags are, why they matter, how to integrate them into your environment, and the steps to achieve a smoother, more transparent, and automated SAM practice.

Introduction to ISO/IEC 19770-2:2015 and SWID tags

Understanding SWID tags

Software Identification (SWID) tags are standardized XML-based files that contain essential information about a software product, such as the publisher, product name, version, edition, and unique identifiers. They’re typically installed alongside the software product or integrated into the software itself, acting as a reliable and consistent reference point.

Why SWID tags?

  • Enhanced Discovery and Inventory: SWID tags provide an authoritative data source, reducing reliance on less accurate discovery methods.
  • Streamlined Compliance: With consistent product data, reconciliation against entitlements (supported by ISO/IEC 19770-3) becomes more efficient.
  • Improved Data Accuracy: High-quality asset data allows for better decision-making, cost optimization, and risk mitigation.
  • Automation and Integration: Machine-readable tags support automated data collection and integration into SAM tools, ITSM systems, and asset repositories.

The business value of adopting SWID tags

Benefit Description 
Cost Optimization and Control Accurate inventories mean fewer wasted licenses, reduced surplus software spending, and a more strategic approach to vendor negotiations. 
Reduced Audit Risk With standardized identifiers for all your software, you can quickly demonstrate compliance during vendor audits, mitigating risks and avoiding potentially hefty penalties. 
Operational Efficiency Clean, reliable data helps streamline workflows, reduce manual reconciliation efforts, and support more informed strategic decisions about your software portfolio. 
Continuous Improvement By aligning with ISO/IEC 19770-2, you establish a foundation for iterative improvements. It’s easier to scale your SAM capabilities as your organization grows and your IT environment evolves. 

Step-by-step roadmap for implementing SWID tags

Step 1: Gain executive and stakeholder buy-in

What’s needed:

  • Executive Sponsorship: Support from C-level executives ensures alignment with broader ITAM and SAM strategies.
  • Cross-Functional Collaboration: Involve software vendors, IT operations, procurement, and security stakeholders early to ensure everyone understands the benefits and requirements.

Actionable tip: Develop a compelling business case highlighting cost savings, reduced audit complexity, and enhanced security. This narrative can encourage stakeholders to invest time and resources.

Step 2: Conduct a readiness assessment

What’s needed:

  • Current Inventory Maturity: Assess your current software inventory processes. Do you rely on spreadsheets, partial scanning, or legacy discovery tools?
  • Identification Gaps: Identify where SWID tags are missing and which key software vendors do not provide SWID-tagged products.

Actionable tip: Use a simple checklist or leverage automated discovery tools to pinpoint existing challenges. Some tools can even highlight which installed software already provides SWID tags.

Step 3: Develop a SWID tag strategy and policy

What’s needed:

  • Policy Framework: Define how SWID tags will be created, maintained, updated, and managed throughout the software lifecycle.
  • Alignment with ISO/IEC 19770-1 and -3: Ensure your SWID tag strategy fits into a broader ITAM framework. ISO/IEC 19770-1 sets the overall requirements for ITAM,[2] while ISO/IEC 19770-3 deals with entitlement tags, complementing SWID tags.[3]

Actionable tip: Create a policy that mandates SWID tag adoption for any new software procurement. Integrate these requirements into vendor contracts and RFPs to ensure compliance from the start.

Step 4: Tooling and automation

What’s needed:

  • SWID-Aware Discovery Tools: Invest in scanning tools and SAM platforms that recognize SWID tags out-of-the-box.
  • Integration with Existing Systems: Ensure that discovery data flows seamlessly into your ITSM, CMDB, license optimization, and reporting solutions.

Actionable tip: Prefer tooling that integrates with your current systems. Focus on automation to minimize manual tagging and reconciliation efforts.

Step 5: Engage with software vendors

What’s needed:

  • Vendor Collaboration: Encourage vendors to provide SWID tags or share metadata in a compatible format.
  • Contractual Clauses: Include SWID tag compliance in your vendor agreements, ensuring that new and updated software deployments come pre-tagged.

Actionable tip: Start with your top software vendors (those with the largest spend or compliance risk) to maximize initial impact. Vendor readiness will vary, so prioritize critical applications first.

Step 6: Training and awareness

What’s needed:

  • SAM and IT Operations Training: Ensure teams understand how SWID tags work and the benefits they deliver.
  • Broader Awareness: Help finance, procurement, and HR teams understand how SWID-enhanced inventory contributes to better financial and regulatory outcomes.

Actionable tip: Short, role-based training sessions with practical demonstrations are often more effective than lengthy theory sessions. Reinforce learning through periodic refreshers or simple handouts.

Step 7: Documentation and evidence

What’s needed:

  • Traceable Records: Maintain comprehensive documentation on how SWID tags are generated, integrated, and used.
  • Audit Trails: Ensure all changes and updates to tag data are logged for future reference and compliance checks.

Actionable tip: Leverage a document management system or integrated SAM solution to centralize evidence. This can help demonstrate compliance and readiness during external audits.

Step 8: Ongoing validation and continuous improvement

What’s needed:

  • Regular Reviews: Schedule periodic assessments to ensure that SWID tags remain current and accurate.
  • Refinement of Policies and Tools: As you gain experience, refine your approach, update your policies, and enhance tool configurations.

Actionable tip: Implement KPIs such as “percentage of discovered software with SWID tags” and “accuracy of software recognition.” Use these metrics to drive ongoing improvements and justify new investments in SAM capabilities.

Overcoming common challenges

Challenge How to overcome it 
Vendor Non-Compliance Not all vendors provide SWID tags. Overcome this by proactively engaging with vendors, using third-party tagging services, or employing discovery tools that can synthesize SWID-like data. 
Heterogeneous Environments Complex IT landscapes with on-premises, cloud, and hybrid deployments may complicate SWID tag adoption. Use robust discovery and inventory solutions that can operate seamlessly across multiple environments. 
Resistance to Change Teams accustomed to legacy methods may be hesitant. Highlight quick wins, such as reduced audit pain or freed-up budget from unused software, to build momentum and buy-in. 
Resource Constraints Limited budgets or small teams? Start with a pilot project. Focus on a high-value software vendor or a critical application family to demonstrate ROI and justify further expansion. 

Conclusion

ISO/IEC 19770-2:2015 provides a blueprint for enhanced software visibility, enabling organizations to discover and manage their software assets with unprecedented accuracy and efficiency. SWID tags serve as a foundational element of a modern SAM strategy, streamlining compliance management, reducing risk exposure, and driving cost optimization.

By following the roadmap outlined in this guide (from gaining executive buy-in and conducting readiness assessments, to engaging with vendors and continuously improving your processes) you can transform your SAM practices. Embracing SWID tags today sets the stage for a more automated, transparent, and strategically valuable software asset management function tomorrow.

References

  1. ISO/IEC 19770-2:2015 Information technology: IT asset management, Part 2: Software identification tagISO catalogue page (returns 403 to automated checks; canonical catalogue URL).Retrieved 2026-09-26.
  2. ISO/IEC 19770-1:2017 Information technology: IT asset management, Part 1: IT asset management systems, RequirementsISO catalogue page (returns 403 to automated checks; canonical catalogue URL).Retrieved 2026-09-26.
  3. ISO/IEC 19770-3:2016 Information technology: IT asset management, Part 3: Entitlement schemaISO catalogue page (returns 403 to automated checks; canonical catalogue URL).Retrieved 2026-09-26.

See also

Esc