Policy & Compliance

Opportunity, Standardization, Sovereignty and FOSS

Lessons on the Need and Value of FOSS from the CRA Standardization Process

Seminar 4

11:0035 mins13/11/2026

The EU Cyber Resilience Act of 2024 will be partially in effect as of this year’s SFSCON, but the reality of its implementation and enforcement will continue for many years. As one of the most visible and immediate efforts at EU technological sovereignty the CRA is a politically important regulation, but it is also an incredibly ambitious one on its own, adding safety regulation to the software industry. Most notably for the SFSCON audience the CRA is also a regulation where the FOSS community has provided a great deal of input, advice, and has had some success in shaping both the law and its implementation.

With the standardization and many of the other implementation necessities for the CRA drawing to a close, a look at their successes and failures, and FOSS’s role in them can provide a road map for the future of FOSS interactions with tech sovereignty regulation. This talk will point out some of the frictions and struggles of CRA implementation, noting the very real ways that FOSS contributions have mitigated them, and highlighting additional ways open source voices and values might further improve the standardization.

Beyond how FOSS can help the EU implement its cybersecurity, sovereignty, and privacy goals its equally important to understand how these goals can help open source projects, companies and developers. Again using the CRA as a model I hope to point out ways that its regulatory burden on manufacturers may benefit open source projects and communities both financially and provide them with a greater voice in future technology regulation.