Linux Foundation Europe and OpenSSF Launch Initiative to Help Prepare for Implementation of CRA and Future Global Cybersecurity Legislation

Author photo: Chantal Polsonetti
ByChantal Polsonetti
Category:
Acquisition or Partnership

Linux Foundation Europe and the Open Source Security Foundation (OpenSSF) announced a joint global initiative to help prepare maintainers, manufacturers, and open-source stewards for the implementation of the EU Cyber Resilience Act (CRA) and future cybersecurity legislation targeting jurisdictions around the world. This effort aims to help develop and formalize cybersecurity standards and compliance frameworks and help 100+ million open-source communities understand and meet the regulatory requirements outlined in the CRA, with the goal of expanding efforts to address legislation around the world.

The EU Cyber Resilience Act sets new regulatory requirements for software security, placing a significant emphasis on the safety and security of digital products sold within the European market. While the initiative is driven by the immediate need to address CRA, its implications extend far beyond Europe. With cybersecurity now a global concern, the diverse participation includes companies across regions, including the US, APAC, and others. The goal is to equip open-source communities and manufacturers worldwide with the tools they need to meet not only European requirements but also the evolving security standards in markets around the globe.

Key Deliverables and Next Steps

The initiative will focus on several core deliverables over the coming months to help EU policy makers, including:

  • Discussing and Formalizing Cybersecurity Specifications: Developing community-driven standards to ensure that open-source projects can meet the security requirements outlined in the CRA.

  • Providing Compliance Guidance: Offering tools, processes, and best practices to help maintainers, manufacturers, and developers align with the new regulations.

  • Implementing Compliance Processes and Tooling: Creating resources to support the open-source community in automating and managing compliance with the CRA across upstream projects.

Learn more about Industrial Cybersecurity Challenges and Solutions. 

Engage with ARC Advisory Group

Representative End User Clients
Representative Automation Clients
Representative Software Clients