CRA

Understanding Open Source Stewards and the Cyber Resilience Act

Tuesday, November 18, 2025 - 01:50 by Marta Rybczynska
The “Open Source Stewards and the Cyber Resilience Act” white paper explores a new role introduced by the EU Cyber Resilience Act (CRA): the open source steward. This is a newly introduced actor that doesn’t fit neatly into the existing categories of manufacturers or distributors but still carries specific obligations...

ORC Monthly: Deliverables Plan in Motion, New Task Force Forming and CRA Maintainers Recap

Wednesday, June 4, 2025 - 15:37 by Juan Rico
We’re pleased to share that we’ve moved from planning to execution. The Cyber Resilience SIG’s deliverables plan has been expanded with clear, actionable projects, which will each be supported by a dedicated task force. This marks a significant milestone in our collective efforts to operationalise our goals. We invite all...

Securing the Future of Open Source: Launching the Open Regulatory Compliance Working Group

Tuesday, September 24, 2024 - 07:00 by Mike Milinkovich
Today marks an important milestone for the open source community. As open source software continues to drive innovation across industries, ensuring its relevance and compliance with emerging regulations has never been more critical.  To address these challenges, the Eclipse Foundation is proud to announce the formal launch of the Open...

The Open Source Community is Building Cybersecurity Processes for CRA Compliance

Tuesday, April 2, 2024 - 03:00 by Mike Milinkovich
tl;dr – Apache Software Foundation, Blender Foundation, OpenSSL Software Foundation, PHP Foundation, Python Software Foundation, Rust Foundation, and Eclipse Foundation are jointly announcing our intention to collaborate on the establishment of common specifications for secure software development based on existing open source best practices. In an effort to meet the...

European Cyber Resilience Act: Potential Impact on the Eclipse Foundation

Sunday, January 15, 2023 - 21:22 by Mike Milinkovich
Europe has proposed new legislation intended to improve the state of cybersecurity for software and hardware products made available in Europe. The Cyber Resilience Act (“CRA”) will mandate that all manufacturers take security into account across both their development processes and the lifecycle of their products once in the hands...