diff --git a/CNCF-Fossa.md b/CNCF-Fossa.md
new file mode 100644
index 0000000..c0cf758
--- /dev/null
+++ b/CNCF-Fossa.md
@@ -0,0 +1,31 @@
+Work in Progress to record using CNCF Fossa to fulfil our license scanning requirement for onboarding
+
+- Request from @jeefy in CNCF access to Fossa for Confidential Containers
+- Accept invite to https://app.fossa.com/projects
+
+## Setup connection between Fossa and Github Organisation
+
+- [Integrating FOSSA with GitHub instructions](https://docs.fossa.com/docs/github)
+- Add Projects
+
+
+
+
+- Quick Import from Github
+
+From https://github.com/organizations/confidential-containers/settings/oauth_application_policy
+- Connect with Service (Choosing Proceed without linking)
+
+
+- Ensure Fossa is an approved third party application for confidential containers
+
+Fossa View
+
+
+
+Github View
+
+
+
+- Finally Authorise Fossa using your Github Account (??Should we eventually setup a service account for this??)
+