Open-Source Consulting
The shortcut: Don't sell "open source consulting" as a generic service. Sell one productized audit — like "AGPL risk scan for Series A SaaS startups" — at a flat $2,500. Niche down hard. Generalists lose to law firms; specialists win because nobody else does this work.
Industry: Software & Tech | Investment level: Small — $3,000-$10,000 | Time to launch: 6-10 weeks (one productized audit defined + FOSSA or ORT trial set up + first 2 referral clients gate the launch)
Best for: A senior engineer or maintainer who already reads license texts for fun, has shipped to production with GPL/AGPL/Apache/MIT dependencies, and can talk to a CTO without flinching. What you'll likely make: $1,500-$3,000 month 3, $4,000-$7,000 month 6, $7,000-$12,000 month 12. Math is in Section 4.
Market Opportunity
Walk into any engineering team's licensing review — even a careful one — and you'll find it somewhere in the dependency tree: an AGPL library buried three levels deep, pulled in by something that was pulled in by something else, and nobody on the team can tell you what it means for their hosted product. That gap is the business.
The market sits in a strange seam. Big enterprises hire white-shoe firms (Morrison & Foerster, Wilson Sonsini) at $700/hour or boutique vendors like FOSSA and Tidelift on enterprise contracts. The bottom of the market — Series A and B startups, indie SaaS companies, the YC batch from 18 months ago — has nobody. They can't afford a law firm and don't need a SaaS subscription. They need one person to run a scan, write a 6-page report, and tell them whether the AGPL library their backend engineer pulled in last quarter is going to wreck their acquisition diligence.
The trap is selling yourself as "an open source consultant." That phrase means nothing to a CTO. The pitch that lands is one specific deliverable: "I run a license audit on your codebase and hand you a remediation plan in 5 business days for $2,500." Productize first. Branch later.
Two tailwinds make right now better than two years ago. First, US Executive Order 14028 (2021) made Software Bill of Materials (SBOM) deliverables mandatory for federal contractors and pulled SBOM language into enterprise procurement contracts. Most companies being asked for SPDX or CycloneDX output don't know what either is. Second, AI/ML stacks have made license soup dramatically worse. A modern Python ML project pulls 80+ transitive dependencies with mixed Apache, MIT, GPL, BSD, and the occasional custom academic license. An audit on one of those codebases usually surfaces 3-5 license conflicts nobody on the team knew about.
Launch With AI
Pro tip: AI is the SBOM generator that turns 80 transitive dependencies into a 6-page audit a CTO can hand to their acquirer. The license interpretation is your judgment + a license-text reference (you're not a lawyer); the report-writing, the SBOM generation, the per-finding remediation copy — that's all what AI takes off your plate.
Upfront honesty: AI cannot give legal advice on whether a specific company's deployment of an AGPL library actually triggers source-disclosure obligations under §13. That's a question for an actual attorney, and your MSA must say so explicitly. What AI does brilliantly is the audit pipeline: parsing FOSSA/Snyk/ORT JSON output, generating SPDX or CycloneDX SBOMs, drafting per-finding remediation prompts (which OSI-approved alternative library to swap in), writing the productized audit report, and the cold-pitch outreach to Series A CTOs whose acquirer-diligence pain is 12 months out. The legal judgment is yours (with attorney backstop); everything else is AI's job.
AI Tools You'll Use
| Tool |
What it does for you |
Cost |
| ChatGPT (Plus) |
Audit report writing, MSA + SOW templates, cold-pitch emails to CTOs |
$20/mo |
| Claude (Free + Pro) |
Reading actual OSI license texts (GPL-2/-3, AGPL, Apache 2.0, MIT, BSD-2/-3) + flagging conflict patterns |
Free / $20/mo |
| FOSSA, Snyk, or OSS Review Toolkit |
Automated dependency + license scan with SBOM export |
Free tier / $99-$999/mo |
| Cursor or GitHub Copilot |
Generating SBOM-export scripts (SPDX 2.3, CycloneDX 1.5) per client repo |
$20/mo |
| Stripe + DocuSign |
Audit invoicing + MSA signing + per-engagement deliverable delivery |
2.9% + 30¢ / $15/mo |
The Workflow
Step 1: Run FOSSA/Snyk/ORT — let AI triage license risk in 30 min. Most consultants spend 8-10 hours hand-reading SBOM output. AI triages in 30.
Prompt (paste FOSSA/Snyk/ORT JSON output into Claude): "Triage this dependency + license report from a [language: JS/Python/Go/Rust/Java] codebase. For each license-flagged finding: (1) classify severity — CRITICAL (AGPL or copyleft in distributed code), HIGH (GPL in linked library, may trigger §3 source-disclosure), MEDIUM (license missing or unclear, attribution requirements not met), LOW (permissive license but missing NOTICE file), (2) identify the package + version + transitive parent (the package they depend on directly that pulled this in), (3) recommend specific remediation — swap to OSI-equivalent permissive alternative (name the package), add LICENSE/NOTICE attribution, comply with copyleft via source disclosure, or move to AGPL-incompatible deployment model, (4) flag risk to acquirer diligence — would this kill an acquisition or trigger a hold-back. IMPORTANT: this is a triage for engineering planning, NOT a legal opinion. Add a footer: 'License interpretation requires an attorney licensed in the relevant jurisdiction. This triage identifies patterns; final legal advice on contamination requires counsel.' Output as a triage table sorted by severity × business impact."
Step 2: Generate the productized audit report from triage output. The deliverable that justifies $2,500 isn't the scan — it's the polished 8-10 page report with executive summary + per-finding remediation + per-finding effort estimate.
Prompt: "Generate an 8-page open-source license audit report for [client name]'s [codebase name], audited [date]. Sections: (1) executive summary — 1 paragraph overview, headline finding (e.g., 'No AGPL exposure detected; 3 GPL-2 libraries require source-disclosure compliance check'), (2) methodology — FOSSA/Snyk/ORT scan version, dependency tree depth analyzed, license types flagged, (3) findings ranked Critical/High/Medium/Low with: package + version + license + recommended action + estimated engineer-hours, (4) SBOM-readiness — current state (SPDX 2.3 or CycloneDX 1.5 exportable yes/no), recommendations for SBOM-export pipeline integration into CI/CD, (5) acquirer-diligence summary — 1 paragraph framing finding for a future M&A (this is what acquirers' code-diligence vendors look for), (6) 30/60/90-day remediation roadmap. ALSO INCLUDE the disclaimer footer: 'This audit identifies license patterns and recommends remediation paths. Legal interpretation of copyleft contamination, particularly AGPL §13 network-distribution clauses, requires an attorney licensed in the relevant jurisdiction. This report is not legal advice and should not be relied upon as such for litigation, M&A diligence response, or licensing-strategy decisions without attorney review.' Format as markdown that converts cleanly to PDF. Tone: confident on engineering, deferential on law."
Step 3: Generate SPDX 2.3 or CycloneDX 1.5 SBOM per Executive Order 14028. Federal contractors + their downstream vendors need SBOM as part of procurement. AI writes the SBOM-export script.
Prompt: "Generate a Python script that takes the output of [FOSSA / Snyk / ORT] for a [client codebase language] and outputs both SPDX 2.3 + CycloneDX 1.5 format SBOMs. Required SPDX 2.3 fields per NTIA minimum elements: supplier name, component name, version, unique identifier (PURL or CPE), dependency relationship, author of SBOM data, timestamp. Required CycloneDX 1.5 fields: similar plus vulnerability database integration (cross-reference each component to NVD CVEs). Output: (1) the script, (2) a sample SBOM in both formats for a small Express.js app for the customer to validate, (3) instructions for adding the SBOM-export step to their CI/CD pipeline (GitHub Actions YAML or GitLab CI YAML). Reference: Executive Order 14028 + NTIA SBOM minimum elements (https://www.ntia.gov/SBOM)."
Step 4: Write the MSA + SOW that protects you (specifically: the 'I'm not a lawyer' carve-out). A solo OSS consultant gets sued when a client claims your audit missed an AGPL violation. The MSA is the firewall. AI writes it.
Prompt: "Generate a 2-page Master Services Agreement template for a solo open-source consulting practice. Critical clauses: (1) SCOPE OF SERVICES — I provide engineering analysis of open-source license patterns, automated scan triage, SBOM generation, and remediation recommendations. I am NOT a lawyer, do NOT provide legal advice, and my deliverables are NOT legal opinions. Client agrees to retain qualified counsel for any actual legal interpretation of license obligations, M&A diligence response, or litigation. (2) RELIANCE — Client may not rely on my deliverables for legal proceedings or M&A diligence response without attorney review. (3) LIABILITY — Limited to fees paid for the specific engagement, with carve-outs for gross negligence + willful misconduct. (4) WARRANTY DISCLAIMER — Services provided 'as-is,' no warranty that all license issues will be detected (some are computationally undecidable from static scans). (5) E&O INSURANCE — Confirm I carry $1M/$2M E&O + cyber liability with software-services endorsement, client may request COI naming them as additional insured. (6) PAYMENT — Net-15 default, late fee 1.5%/mo. (7) INDEMNIFICATION — Mutual; I indemnify against my gross negligence, client indemnifies against their misuse of my deliverables (e.g., representing my engineering report as a legal opinion to a third party). (8) GOVERNING LAW — my state, dispute resolution via JAMS arbitration. End with: 'This template should be reviewed by an attorney licensed in [my state] before execution. The 'not legal advice' clauses are essential — do not remove without attorney review.'"
Step 5: Cold-pitch Series A SaaS CTOs with the acquirer-diligence framing. The single best frame for OSS consulting outreach is 'this kills acquisitions.' AI writes the cold email.
Prompt: "Write a 4-line cold email to [CTO name] at [Series A / B SaaS company]. Hook: I noticed [signal — Series A round, hiring senior engineers, OSS-heavy stack visible from job listings or public repos]. Bridge: 'In the last 12 months, I've audited [X] codebases at YC-batch-N and Series-A-stage SaaS. Every single one had at least one license issue that would surface in M&A diligence — usually AGPL pulled in transitively, or stale dependencies with revoked licenses. The fix is cheap if you find it now; expensive if your acquirer's vendor finds it.' Offer: '$2,500 productized audit, 5 business days, 8-page report with specific remediation SQL — sorry, specific package swaps. Sample report (anonymized) attached.' Close: 'Want to see what the diligence finding pattern looks like?' Sign with name + cell + GitHub showing OSS contributions to credible projects (Postgres, Linux kernel, Kubernetes — whatever's real). Tone: peer-to-peer engineer, never sales-y. Avoid 'leverage' (corporate-speak) — use 'find' or 'identify.'"
Time Saved Per Week
- Audit triage from raw FOSSA/Snyk output: ~6 hrs saved per audit
- Audit report writing: ~8 hrs saved per audit
- SBOM-export script (per language stack, one-time): ~6 hrs saved per language
- MSA + SOW template (one-time): ~10 hrs saved overall
- Cold-pitch outreach (10 CTOs/wk): ~3 hrs/wk in steady-state
- Total: 10-12 hrs/wk back — that's 2-3 audits per month instead of 1 solo.
Total AI Stack Cost
- Budget tier: ChatGPT Free + Claude Free + Snyk Free + ORT Free = $0/mo to start
- Full tier: ChatGPT Plus ($20) + Claude Pro ($20) + FOSSA seat (~$300/mo at consultant tier) = $340/mo
- Compare: A boutique OSS license firm charges $500-$1,500/hr. One $4K consult = entire AI stack for a year.
Your First Win (30-min action)
Pick the closest 5 Series A SaaS companies you have a personal connection to (LinkedIn, your YC alumni list, your old company's portfolio). Find the CTO or VP of Engineering for each. Use Step 5's prompt to write personalized cold-pitch emails today.
Prompt to generate the sample audit PDF you attach: "Generate a sample 6-page open-source license audit report for an anonymized Series A B2B SaaS company built on Node.js + Postgres. Realistic findings: (1) ONE GPL-3 library pulled in transitively via 4-deep dependency chain (the company didn't know it was there), (2) THREE Apache 2.0 libraries missing the required NOTICE file attribution in their distributed product, (3) TWO MIT-licensed libraries with stale versions where the maintainer changed the license to BSL — current code is technically out of compliance with BSL terms, (4) ONE library with NO LICENSE file at all (defaults to 'all rights reserved' = no usage rights, biggest acquirer-diligence red flag). For each: the package + version, the issue, the remediation (specific package swap or attribution add), the engineer-hours, the M&A diligence risk. Tone: confident on engineering, deferential on law. End with the disclaimer footer + a one-line 'next step' offer for retainer. Make it tight enough that a CTO reads the whole thing on the train."
That single sample PDF + 5 personalized cold pitches typically lands 1-2 paid audits within 14 days. From the audits, ~40% convert to a $1,500/mo retainer within 90 days. That's $2,500 + $1,500/mo MRR from one Tuesday afternoon of cold outreach.
Product / Service Offering
You sell one core product in three flavors. Pick one to start.
- OSS license audit (productized). Run FOSSA, Snyk Open Source, or the open-source OSS Review Toolkit (ORT) against the client's codebase. Identify GPL/AGPL/copyleft contamination, missing attributions, and license conflicts. Deliver a 6-10 page remediation report with specific library swaps. Flat $2,000-$3,500. 3-5 business days. Your bread and butter.
- Open-sourcing strategy advisory. A startup wants to release their internal tool as open source. You design the licensing model (MIT, Apache 2.0, AGPL dual-license, BSL with future-Apache conversion), set up a Contributor License Agreement using CLA Assistant or EasyCLA, draft contribution guidelines, and design governance. $3,500-$8,000 fixed-price, 2-3 weeks.
- Monthly compliance retainer. Ongoing dependency intake review for engineering teams that ship fast. New library proposed → you review the license, flag risks, log it in their SBOM. Quarterly SPDX SBOM regeneration. Policy updates. $1,000-$2,500/month. Where the income gets steady.
Pick the audit first. Shortest sales cycle (CTOs understand "I'll find your AGPL problems before your acquirer does"), cleanest scope, easiest path to repeat work — most audit clients convert to retainer within 90 days because the problems you found don't stay fixed.
Revenue Model
Unit economics for a solo open-source consultant running productized audits + a small retainer book, working from a laptop, no employees:
| Service |
Price |
Variable cost (tooling + payment fees) |
Your time |
Take-home per engagement |
| Productized license audit |
$2,500 |
$50 (FOSSA trial or ORT compute) + $72.80 (Stripe 2.9% + $0.30) |
20-25 hours |
~$2,375 |
| Open-sourcing strategy advisory |
$5,000 |
$25 + $145.30 |
35-50 hours |
~$4,830 |
| Monthly compliance retainer |
$1,500/mo |
$30 (FOSSA seat) + $43.80 |
4-6 hours/week |
~$1,425 |
| Custom feature / contribution sprint (you pay a maintainer to ship a fix in an OSS project for the client) |
$4,000 |
$1,500-$2,500 (passed to maintainer) + $116.30 |
10-15 hours coordination |
~$1,400-$2,400 |
Your first $1K month = one productized audit at $2,500, take-home ~$2,375 — but realistically you'll only close one in your first 60-90 days while you build referrals. Some months will be zero. Plan for it.
Your first $3K month = one audit ($2,500) plus one $1,500/month retainer that came out of the audit. Take-home ~$3,800 gross. About 25-30 hours of billable work that month.
The $7K-$12K/month path = 2 audits + 3 retainers at ~$1,500 each = $9,500/month gross. That's roughly 50-60 billable hours, which fits in a 4-day week. Past that, you either raise prices (audits go to $4,000-$5,000), bring on a subcontractor (1099-NEC, see Section 5), or productize further (a self-serve license-scanner SaaS, but that's a different business).
Startup Costs
- OSS scanning tooling. Start with Snyk Open Source free tier and self-hosted OSS Review Toolkit (ORT) — both cover 80% of audit needs at $0. Upgrade to a FOSSA trial (typically 14-30 days free) when you land your first paid audit. Paid FOSSA seats run several hundred dollars per month at the consultant tier.
- License references. Free: TLDR Legal, Open Source Initiative license list, GNU license texts. Bookmark these.
- CLA tooling. CLA Assistant is free. EasyCLA requires Linux Foundation project sponsorship — relevant only if your client is donating to LF.
- OpenChain reference. OpenChain ISO/IEC 5230 standard text is free. Read it cover to cover before pitching enterprise retainers — regulated-industry clients will ask if your process is OpenChain-aligned.
- Delivery infra. GitHub Team at $4/user/month for client repo access. Notion or Coda ($0-$10/month) for deliverables. Loom free tier for walkthrough videos.
- LLC + EIN + insurance. $35-$500 LLC filing depending on state — LLC University 50-state table. EIN is free at IRS EIN Online — never pay a third party. Errors & omissions insurance for solo software consultants runs $800-$2,000/year via Hiscox or Insureon.
- Contracts. MSA + SOW templates from Bonsai — $200-$500 one-time legal review by a tech-savvy attorney before your first $5K+ engagement. Worth every dollar.
Realistic all-in: $3,000 if you defer FOSSA paid tier and use ORT/Snyk free, file the LLC, bind one year of E&O, and pay for one legal MSA review. $10,000 if you front-load FOSSA seats, OpenChain training, and a developer marketing site.
Legal & Formation
Business entity. Single-member LLC the moment you sign your first paying client — separates your personal accounts from a "your audit missed an AGPL violation and we got sued by Affero" claim. File via LLC University's 50-state table. Get your EIN free at IRS EIN Online — services that charge $50-$300 are reselling a free five-minute form. S-corp election (via IRS Form 2553) becomes worth running the math on once your net profit clears roughly $80K-$100K/year. For most solo consultants in year one, the LLC is plenty.
Licenses & sales tax. No professional license is required to do open-source consulting in any US state — you're not practicing law (and you must not pretend to). Custom advisory work is generally not taxable in most states, but the line gets fuzzy if you bundle a hosted SaaS dashboard or a recurring scan-as-a-service offering. Roughly 25 states tax SaaS as a taxable service. Once you cross $100K in sales or 200 transactions in a state post-Wayfair, you have economic nexus and may owe sales tax there. If you stay in pure advisory and project-based audits, sales tax is mostly a non-issue. If you productize into a recurring scanning product, use Stripe Tax or Avalara.
Industry-specific risk. This cluster has three legal landmines that will end your business if you ignore them, and you have to know all three.
License obligations and the "I'm not a lawyer" line. GPL v2 and v3 require source code disclosure for distributed binaries. AGPL extends that obligation to network-accessed software — meaning a single AGPL library in a SaaS backend can theoretically obligate the whole stack to be published under AGPL. See GPL v3 text and AGPL v3 text. Apache 2.0 and MIT are commercially safe and are the defaults you should recommend. You identify these issues. You don't give legal advice — every audit report carries a clear "this is a technical analysis, not legal advice; consult licensed counsel" disclaimer. Cross that line and you're practicing law without a license. Reference the Open Source Initiative license list as your authority.
License incompatibility in mixed stacks. The most expensive mistake in this work is mixing AGPL into a closed-source product or combining GPL with Apache 2.0 patent terms in incompatible ways. Your audit's job is to flag these before they hit a Series B diligence. The remediation is usually swapping the offending library for a permissively licensed alternative or negotiating a commercial license from the maintainer (most AGPL projects sell one — that's the business model).
CLA frameworks for client advisory work. When you advise a client on accepting contributions, recommend either CLA Assistant (lighter, GitHub-native) or EasyCLA (Linux Foundation, heavier, used by major projects) depending on whether the client wants relicensing rights or just contribution provenance. The Developer Certificate of Origin (DCO) used by the Linux kernel is fine for purely community projects with no relicensing intent. Pick the wrong framework and the client re-papers every contribution they've ever accepted.
E&O insurance is non-negotiable here. Your written report is exactly the deliverable a client will wave at an attorney if a license claim later surfaces. Cap your liability at fees paid in the prior 12 months in your MSA — never accept uncapped liability.
Marketing & First Customers
Your first 5 clients come from your existing network — engineering managers, founders, and former coworkers who already trust your judgment on technical risk. Cold outreach in this niche is brutal because the buyer (CTO, head of legal, head of engineering) gets pitched relentlessly. Warm intros close. Cold doesn't.
The order that actually works:
- Write one specific public artifact. A blog post or talk titled something like "What an AGPL audit on a Series A SaaS codebase actually looks like" — with screenshots, a fake-but-realistic SBOM, and a 6-step remediation playbook. Post on dev.to and Hacker News (Show HN works for tools and case studies). One good post that ranks for "AGPL SaaS compliance" generates more inbound in 90 days than 200 cold emails.
- Direct outreach to your warm list. Message 30 engineering leaders you've worked with. Pitch the productized audit at $2,500 with a 5-day turnaround. Aim for 2 paid audits in your first 60 days.
- Conference talks and OSS community engagement. Speak at FOSDEM, All Things Open, KubeCon, or any vertical event where your target buyer hangs out. A 20-minute talk on a real audit case study (anonymized) is the highest-ROI marketing in this category. Talk acceptances also build LinkedIn credibility you can't fake.
- Referrals from law firms. Tech-focused law firms (Gunderson Dettmer, Cooley, Wilson Sonsini) regularly see clients who need technical OSS analysis their attorneys can't do. Email three IP partners at mid-tier firms with a one-page summary of your service. One referral relationship can produce $30K+ in annual work.
Don't bother with Upwork or freelance marketplaces for this work. The buyers aren't there.
First 90 Days
- Week 1. File LLC. Get free EIN. Pick your productized audit's exact scope (codebase size cap, deliverable format, 5-day SLA). Write a 1-page service description.
- Week 1-2. Set up OSS Review Toolkit (ORT) on your laptop. Run it against 3 open-source codebases you know well (a Next.js app, a FastAPI service, a Rust CLI). Get fluent with the output format before you take money.
- Week 2-3. Bind E&O insurance ($800-$2,000/year via Hiscox). Buy MSA + SOW templates from Bonsai and pay $200-$500 for an attorney review before first use.
- Week 3-4. Write your one public artifact (blog post or Show HN entry). Post it. Pin it to your LinkedIn.
- Week 4-6. Direct outreach to 30 warm contacts. Aim for 2 paid audits signed by week 6 at $2,000-$2,500 each.
- Week 6-8. Deliver your first 2 audits. Capture written testimonials. Ask each client whether they want to convert to a $1,500/month compliance retainer.
- Week 8-10. Pitch retainer conversion to both audit clients. Realistic close rate is 1 of 2 — that's $1,500/month recurring on top of new audit work.
- Week 10-12. Submit a conference talk proposal for All Things Open or FOSDEM next cycle. Email three IP partners at mid-tier law firms with your service description. Target by day 90: 3 audits delivered, 1 retainer signed, ~$8,500 revenue booked.
Common Pitfalls
- Pitching "open source consulting" instead of one specific audit. Generic pitches lose every time to a productized $2,500 license audit with a 5-day SLA. Pick one deliverable. Sell only that for the first 6 months.
- Crossing the line into legal advice. You analyze technical license obligations. You do not interpret legal enforceability or give compliance opinions. Every report carries the "not legal advice, consult counsel" disclaimer in the first paragraph and on every page. Cross this line and you risk an unauthorized-practice-of-law complaint.
- Skipping E&O insurance to save $1,500/year. Your written report gets waved at attorneys later. Bind coverage before you sign your first MSA.
- Accepting uncapped liability in client contracts. Cap your total liability at 12 months of fees paid. Push back on any client who insists on uncapped — those are the clients most likely to sue when an AGPL violation surfaces in a Series C diligence two years later.
Get your full launch plan — take the free 60-second quiz.