The CRA: A key to a more resilient FOSS ecosystem (mrmcd26) episode artwork

EPISODE · Sep 11, 2026 · 45 MIN

The CRA: A key to a more resilient FOSS ecosystem (mrmcd26)

from Chaos Computer Club - recent events feed (high quality) · host Gregor "Little Detritus" Bransky

With the Cyber Resilience Act FOSS projects are legally on the hook as part of software supply chain ecosystems. In order to address regulatory obligations and foster open collaboration within software supply chain ecosystems best practices, tooling and standards as well as established pathways for public benefit stewardship are needed. The talk will present current work in various Open Source Foundations, the IETF, as well the EU. Various supply chain regulations (EO 14028 [1], SSDF [2], SEC Cyber Rule [3], SLSA [4], NTIA [5]) and the currently developing Cyber Resilience Act (CRA) in the EU create obligations [6,7] for both software suppliers and dependents. For the first time, this includes Free and Open Source Software (FOSS) projects, with the CRA introducing the legal concept of the Open Source Software Steward in the EU framework. The talk will provide an overview of the work being done to ease the regulatory burden of these regulations on FOSS projects and their dependents (aka manufacturers). This includes: - Standards to enable compliance-critical communication within software supply chain ecosystems (e.g., the SCITT Working Group at the IETF [8]); - Machine-readable information about FOSS projects at the OpenSSF [9]; - The development of best practices for collaboration between FOSS projects and their dependents (aka manufacturers) under the CRA in the ORC Working Group [10]. Additionally, the talk will cover the current debate on recognizing public benefit status for the stewardship of Digital Commons (aka "Gemeinnützigkeit Open Source"), such as the recent policy paper by the German Association of Computer Scientists [11]. [1] https://www.nist.gov/itl/executive-order-14028-improving-nations-cybersecurity [2] https://csrc.nist.gov/projects/ssdf [3] https://www.sec.gov/rules-regulations/2023/07/s7-09-22 [4] https://slsa.dev/ [5] https://www.ntia.gov/page/information-quality-guidelines [6] https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng [7] https://digital-strategy.ec.europa.eu/en/factpages/cyber-resilience-act-implementation [8] https://datatracker.ietf.org/group/scitt/about/ [9] https://openssf.org/blog/2026/05/29/aligning-on-machine-readable-signals-as-the-foundation-for-due-diligence/ [10] https://orcwg.org/ [11] https://gi.de/fileadmin/GI/Allgemein/PDF/2026-06_GI_Policy_Brief_Anerkennung_und_Besserstellung_von_OSSS.pdf https://creativecommons.org/licenses/by-sa/4.0/ about this event: https://talks.mrmcd.net/2026/talk/9LHP77/

Episode metadata supplied by the publisher feed · Published Sep 11, 2026

Embed this episode

Ready to play

The CRA: A key to a more resilient FOSS ecosystem (mrmcd26)

0:00 45:24

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Chaos Computer Club - recent events feed (high quality)?

This episode is 45 minutes long.

When was this Chaos Computer Club - recent events feed (high quality) episode published?

This episode was published on September 11, 2026.

Can I download this Chaos Computer Club - recent events feed (high quality) episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!