The EU Cyber Resilience Act (CRA) is no longer a future concern. As of September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents – the first hard obligation to come into force, ahead of full enforcement in December 2027. So where does this leave companies built on open source software?
This talk is a practical guide to navigating the CRA. We start with the essentials – is your project in scope, and when is your business a “manufacturer” versus an “OSS steward”, the new role the CRA created specifically to address open source?
We then walk the path to compliance, with a particular focus on third-party and open source due diligence: building an accurate picture of your software supply chain, assessing the health and security of the components you depend on, handling vulnerabilities, and meeting the new incident-reporting obligations. Crucially, we’ll look at why contributing fixes back upstream isn’t just good citizenship – it reduces your long-term compliance burden and strengthens the shared commons the whole ecosystem relies on.
Whether you publish open source, build commercial products on top of it, or steward a project others depend on, you’ll leave with a clear, actionable understanding of your CRA obligations – and a view of compliance not as a burden imposed on open source, but as a chance to make it more secure and sustainable.
