
With the first obligations under the European Union’s Cyber Resilience Act (CRA) set to take effect in September 2026, organizations face a narrowing window to prepare. The Cyber Resilience Act introduces mandatory cybersecurity requirements for products with digital elements sold in the EU, including those built with or dependent on open source software. It places new responsibilities on manufacturers and distributors of such products in the European market. The CRA also introduces new actors, open source software stewards, which must adopt secure development practices, ensure transparency, and manage vulnerabilities across the entire software supply chain.
The Eclipse Foundation, in collaboration with the Open Regulatory Compliance (ORC) Working Group, announced the launch of the ORC Learning Hub, a free global education initiative designed to help the people responsible for building, maintaining, securing, and governing open source software prepare for these pending obligations. The program is intended to provide practical, role-specific training for open source developers, maintainers, contributors, project stewards, product teams, security and compliance professionals, OSPO leaders, and legal teams.
While the CRA is a European regulation, its impact is global. Any organization that distributes or commercializes software-enabled products in the EU market, including those built on open source software, must comply with its requirements. Open source software is now nearly universal in modern software.
Developed by the ORC Working Group and hosted by the Eclipse Foundation, the ORC Learning Hub brings together expertise from across the open source ecosystem, industry, and regulatory domains. It delivers open source-focused training to help organizations understand how the CRA applies in real-world scenarios and what actions they need to take.
At the core of the ORC Learning Hub is a modular training program designed to guide organizations through CRA readiness step by step. The full program includes:
Module 1: Introduction to the CRA for Open Source Software.
Module 2: Introduction to the CRA for Manufacturers.
Module 3: SBOMs and Vulnerability Management in Open Source.
Module 4: CRA Due Diligence and Open Source Usage.
Module 5: Vulnerability Management in Practice.
The Learning Hub launched with Modules 1 and 2, providing tailored entry points for open source developers, maintainers, contributors, and project stewards, as well as product teams, security and compliance professionals, OSPO leaders, and legal teams. Additional modules covering SBOMs, due diligence, and vulnerability management will soon be released.
The ORC Learning Hub is designed to:
Help developers, maintainers, project stewards, and software teams understand what the CRA means for their work.
Clarify how CRA obligations apply to open source software, communities, and downstream product development.
Provide role-specific guidance for manufacturers, developers, maintainers, OSPOs, security teams, and legal and compliance professionals.
Help organizations operationalize CRA readiness across modern, open source-based software supply chains.
Support global collaboration on emerging regulatory best practices.
The ORC Learning Hub is free and available globally. Organizations and open source stakeholders are encouraged to begin preparing now, ahead of the September 2026 deadline, and to stay engaged as new modules and guidance are released.
The program is available at https://orcwg.org/training/.
Learn more about the markets for industrial cybersecurity challenges and solutions.