Get a sneak peek 👀 of our CRA training course for manufacturers on our YouTube channel. 📺 “Security Management for Manufacturers | ORC Learning Hub” 💭 Do you know your responsibilities as a manufacturer under the Cyber Resilience Act? 🔔 Don’t forget to subscribe: youtu.be/KLSGEPiHY24?...
Open Regulatory Compliance
@orcwg.org
Global, industry-led collaboration helping organisations understand and implement open source compliance strategies under evolving regulations. Hosted by @eclipse.org Get involved: orcwg.org/participate/
The European Commission has published the final #CRA Implementation Guidance, providing clarification for the #OpenSource ecosystem. In this blog, we break down key takeaways and explain what they mean for organisations preparing for CRA compliance. 🔗 Read the full blog: orcwg.org/blog/ec-cra-...
Failure to comply with the #CyberResilienceAct risks fines up to €15 million or 2.5% of global annual turnover, plus immediate removal from retail and digital shelves. 📜 Understand the legal mechanics of non-compliance and protect your firm: cra.orcwg.org/faq/official/
⚠️ Under the #CRA, integrating a broken or insecure third-party component into your software counts as a compliance failure for your company. 🌐 Read the community guidelines for executing #SoftwareDueDiligence: cra.orcwg.org/faq/due-dili... #SecOps
We are pleased to announce the launch of the Open Regulatory Compliance YouTube channel! 🔔 Subscribe to stay up-to-date with webinars, courses, and regulatory compliance content. ▶️ Now playing: “Security Management for Manufacturers | ORC Learning Hub” Watch now: youtu.be/KLSGEPiHY24?...
The hardest part of the Cyber Resilience Act (CRA) isn't reading the regulation, it's knowing where to begin. Explore the new ORC Learning Hub with courses for developers, manufacturers, maintainers, contributors, and security professionals. Start learning for free now: orcwg.org/training/
Under the #CRA, the “Conformité Européenne” (#CEmark) will be required on digital products with software elements before they can be legally made available on the European market. Prepare your software for CE compliance: cra.orcwg.org/faq/official/faq_6-8/
Beginning September 2026, a vulnerability in your commercial software won’t be just an internal issue — it will trigger a regulatory countdown under the #CRA. Building these response networks requires months of preparation. Start now. Review the expectations: cra.orcwg.org/faq/official/reporting/
This team analysed over 350 organisations and 3,600 repositories within #EclipseFdn projects to learn whether their #CyberResilienceAct compliance solution could be applied to a large #OpenSource organisation. 📺 Watch the full session on our new YouTube channel: youtu.be/KN3dKD38S9U?...
☁️ Are cloud-based products within the scope of the #CyberResilienceAct? In short, yes. The CRA explicitly covers Remote Data Processing Solutions (#RDPS) that are integrated into a product with digital elements or support its direct operation. Learn more: cra.orcwg.org/faq/remote-p...
The new ORC Learning Hub helps turn Cyber Resilience Act (CRA) requirements into practical action. Learn about: • Security by design • Vulnerability management • SBOMs • Software supply chain responsibilities Start preparing now: orcwg.org/training/
Not all #OpenSource projects are built the same way, and the #CRA knows it. Understand your classification to implement smart governance: 🔹 Independent Community Projects 🔹 Steward-Supported Projects 🔹 Commercial open source products (COSS) Evaluate your project: cra.orcwg.org/faq/projects/
This #CRAMondays session features key findings from an analysis of #OpenSource projects across technology ecosystems and compares ORT Server results with GitHub advisory data, showcasing differences in coverage and vulnerability detection. 📺 Watch the full clip on YouTube: youtu.be/KN3dKD38S9U?...
How can an "intent to monetise" drag #OpenSource projects into CRA compliance? ✅ Intent: Providing a software product for a fee or paid support. ❌ No intent: Charging for educational material, or accepting non-binding philanthropic donations. Learn more: cra.orcwg.org/faq/cra-itse...
Our latest white paper breaks down the new “Stewards” legal tier introduced in the #CyberResilienceAct and the expectations that accompany it. If you are at all involved with #OpenSource projects, this knowledge will be crucial. 📝 Learn more in our white paper: hubs.la/Q040T4mT0
New free CRA training is now available from the Open Regulatory Compliance (ORC) Working Group. Start learning: orcwg.org/training/ Learn more about the Foundation's CRA Readiness Project: buff.ly/bfp8xkQ #FreeBSD #OpenSource #CyberResilienceAct #CRA #SoftwareSecurity
Will individual open source maintainers be penalised under the #CRA? ➡️ Those who simply contribute code to #OpenSource or maintain a project without monetisation are not in scope. ➡️ However, the indirect impact involves a rising industry standard. Learn more: cra.orcwg.org/faq/maintain...
Not everyone experiences the CRA the same way. That's why we built the new ORC Learning Hub to start with your role, not the regulation. Start with our free courses providing an introduction to the Cyber Resilience Act (CRA) for open source communities and manufacturers: orcwg.org/training/
The EU Cyber Resilience Act (CRA) is changing software development and distribution. 📅 Mandatory reporting starts 11 September 2026, now is the time to prepare. Get up to speed with free, practical training from the new ORC Learning Hub: orcwg.org/training/ #CyberResilienceAct #OpenSource
🔍 Did you know the #CyberResilienceAct created a dedicated legal tier for #OpenSource Software Stewards? If your foundation or organisation acts as a digital hub, check out the tailored open source Steward FAQs to learn more: cra.orcwg.org/faq/stewards/
If you build software outside of Europe but sell to European clients, you are a "Manufacturer" under the #CyberResilienceAct. 🚩 Read the specific breakdown of manufacturer obligations: cra.orcwg.org/faq/manufact... #SoftwareDevelopment
Key dates for the EU #CyberResilienceAct are fast approaching. - 11 September 2026: Mandatory actively exploited vulnerability and incident reporting rules take effect. - 11 December 2027: Remaining CRA obligations become fully applicable. ⏰ Don't miss vital deadlines: cra.orcwg.org/faq/official/
📦 Up to 76% of modern commercial software applications contain #OpenSource dependencies. What does this mean for commercial organisations? Check out the specialised breakdown on open source supply chains: cra.orcwg.org/faq/projects/
The #CyberResilienceAct affects all organisations who develop, distribute, and/or sell software in the European market. It addresses #cybersecurity across products and a lack of information available to users regarding security postures. Visit the #ORC FAQs for community guidance: cra.orcwg.org
Know you need to be CRA compliant but don’t know where to start? The ORC Working Group is on a mission to raise awareness around the #CyberResilienceAct (CRA) and showcase how these regulations will affect both closed and #OpenSource organisations. 🧰 Explore resources: orcwg.org/cra/resources/
🚦 We’re in the final stretch: 3 months until #CyberResilienceAct reporting requirements hit. According to ONEKEY, 37% of companies see the 24-hour reporting rule as their number 1 challenge. Are you ready? 👉 Learn more: orcwg.org/cra #CRA #ORCWG
Mike Milinkovich explores why AI-enabled open source security matters for Europe’s digital resilience and autonomy. The #EclipseFdn has been part of Anthropic’s Project Glasswing since its inception & is the only EU foundation participating in the initiative: blogs.eclipse.org/post/mike-mi...
🔍 This recap covers the OC for Compliance track at #OCX26, with sessions focused on the Cyber Resilience Act (CRA), SBOMs, open source governance, and what compliance actually requires from engineering teams. Check out this blog and watch the recordings 👉 blogs.eclipse.org/post/daniela...
The ORC panel at #OCX26 explored how the #CRA is being implemented across different ecosystems. The discussion highlighted the complexity of aligning regulatory requirements with diverse technical environments. 🎥 Watch the recording: hubs.la/Q04fXP250 ⭐ Read the highlights: hubs.la/Q04fXLkX0 #ORCWG
The recordings from OC for Compliance at #OCX26 are available on YouTube. Catch up on sessions covering the #CRA, compliance as code, SBOMs, open source governance, and regulatory collaboration. 🎥 Watch the recordings: www.youtube.com/playlist?lis...