Skip to main content
SourceTrustSign in

Help center

Guides for SourceTrust: Importing dependencies, reviewing licenses, external obligations, publishing attestation pages, billing, plain-language license explainers, and procurement-oriented explainers for common open-source licenses.

Creative Commons Attribution-NonCommercial 4.0

← All articles

Free for non-commercial purposes only. In a paid or ad-supported product the grant does not reach you, whatever the download page said.

What this license is

Creative Commons Attribution-NonCommercial 4.0 lets anyone use, adapt and share a work, for non-commercial purposes only. It is not an open source license and it is not open content under the usual definitions, because the limit lands on the use itself rather than on how you distribute. The license defines the boundary in its own words: nothing primarily intended for or directed toward commercial advantage or private monetary compensation. It shows up on icon packs, stock photography, sound libraries and academic data sets.

Why it matters for your product

This is the asset that stops a release. If your product is sold, ad-supported, or used to run a commercial business, the grant does not reach it, and no checklist item fixes that. Attribution does not cure it. Putting the credit in your about box does not cure it. The two paths that work are buying a commercial license from the creator, or replacing the asset. Internal use inside a company is argued both ways, and the cautious reading treats a commercial company's internal tooling as commercial.

You are meeting the terms when

  • You are inside the grant when the project using the work is genuinely non-commercial, and the credit carries the creator's name, the copyright and license notices, a link to the work and any change.
  • You are outside it when the product is sold, ad-supported, or used for commercial advantage, which is the license's own wording rather than a reading of it.
  • You resolve a commercial product when you buy a separate license from the creator and record that agreement against the component.
  • You resolve it the cheaper way when you replace the asset with one under CC-BY-4.0 or another license that carries no use restriction.
  • You keep internal use defensible when you get a written answer from counsel, because internal use at a commercial company is argued both ways.

Where teams get it wrong

  • A designer downloads an icon set marked free, the NC suffix goes unread, and it ships in a paid product. Check the suffix before the asset enters the repository.
  • Teams think attribution fixes it. The credit is a separate condition, and meeting it does not make commercial use permitted.
  • Teams assume the family members behave alike. CC BY-NC-SA adds share-alike on top, and CC BY-NC-ND forbids sharing adaptations at all.
  • Teams treat an internal tool as non-commercial by default. That reading is contested, so make the decision deliberately and write down who made it.

How SourceTrust handles this license

Two things happen, and neither of them is a non-commercial check. The identifier starts with CC-BY, so the attribution item appears on the project checklist in every deployment context and a person has to confirm it before you publish. The identifier also starts with CC-BY-NC, so the component page shows a restricted-use warning saying the license limits how the component may be used. There is no obligation in the product for the non-commercial limit itself: that decision is yours, and it belongs with counsel. Read Reviewing a component for the review flow.

Related guides

Practical guidance for procurement review, not legal advice. Confirm high-stakes use with counsel.

Handle this license in SourceTrust

A NonCommercial asset in a paid product is the kind of finding that surfaces during a customer's review rather than during yours. SourceTrust shows every component carrying one, with the license text attached, before the page goes out.

Importing, reviewing and drafting are free. Your first public attestation page is free too: one lifetime Community page per organization, plus open-source projects connected to a public GitHub repository (up to 10 activations a calendar month).

Free pages carry SourceTrust attribution and stay open to search engines. Paid plans start at $29 per active project a month and remove the attribution.

Use code LICENSEGUIDE at checkout for 90% off your first 3 months on the monthly plan.

See what is free and what is paid