Cyber Resilience Act (CRA) and impact on open source actors
Schedule: June 17, afternoon.
Room: February Room
How to get there? : See Orange Gardens practical information

Abstract
Cybersecurity is a major challenge for modern organizationsThe CRA (Cyber Resilience Act) is an ambitious regulation aimed at improving the cybersecurity and cyber resilience of digital products marketed within the European UnionEconomic players have until September 2026 to comply with certain critical obligations, and then until December 2027 to adapt to all the other requirements
In this session we are aiming at moving forward on the preparation of OW2 members and open source actors in general to the new regulations.
Guides and supports are available, including: the CRA guide co-produced by CNLL (French Association of Open Source Businesses) with inno³ (consulting firm specializing in open models) and the open source governance handbook proposed by the OSPO AllianceBoth documents will be used as the main resources to start discussions.
Resources:
The anticipated topics discussed during the session include:
- who is concerned by the CRA and to which extent?
- how does this impact open source processes? at which step of a project development or life cycle should it be considered?
- how will actors be accompanied? what support? from who?
And the expected results include:
- Proposals to move forward in the processes to accompany the actors;
- Enrich the practical guide from CNLL/Inno³ in the perspective of a future version with feedback from real-life users;
- Enrich the practical methodology of the GGI handbook in order to contribute to the improvement of cybersecurity practices within open source governance.
We consider this work to be done in a collaborative and collective manner, involving all actors with a common aim to support the European open source ecosystem

Content and program
15:00-15:10 : 1) Welcome & Setting the Scene
- Speaker: Stefane Fermigier
- Content: Introduction to the workshop, revised objectives (prepare, discuss specific challenges, contribute to solutions)Why OW2 is hosting thisRoles of CNLL, APELLAcknowledge co-organizers: inno³, CNLL, OSPO Alliance.
15:10-15:50 : 2) CRA Deep Dive: The Regulation, Guide, OS Impact & Initiatives
- Speakers: Stefane Fermigier & Benjamin Jean (Inno³)
- Content:
CRA Essentials (15 mins): Purpose, scope (commercial activity focus), key definitions (Manufacturer, Steward, etc.), core obligations, critical timelines (Sept 2026, Dec 2027).
Reference: CNLL/Inno³ Guide (Ch 3), EC Slides.
Impact on OS & Scenarios (20 mins): Specifics for Open Source (“commercial activity,” OS Stewards)Walk through 2-3 key scenarios from the CNLL/Inno³ Guide (e.g., OS Publisher, Integrator, Contributor).
Reference: CNLL/Inno³ Guide (Ch 5).
Navigating Compliance - Initial Thoughts (10 mins): Brief on SBOMs, Vulnerability Management, Secure Development Lifecycle (SDL) – setting the stage for breakout discussions.
Reference: OWASP SAMM concepts, Olle Johansson’s points.
Overview of Key Support Initiatives (5 mins): Briefly introduce ORC WG, OCCTET, Cyberstand.eu as resources that will be explored more in breakouts or that offer tools.
Reference: ORC WG, OCCTET slides.
15:50-16:00 : 3) The Standardization Landscape & EU Policy Context
- Speaker: Sebastian Raible (APELL)
- Content:
Quick overview of the CEN/CENELEC/ETSI standardization process for CRAImportance of the “Public Enquiry” phase for OS community inputAPELL’s role in representing SME interestsBrief on EU implementation activities (Expert Group, ENISA platform, upcoming guidance).
Reference: CEN/CENELEC Slides, EC Slides.
16:00-16:30: Coffee Break
16:30-16:40: 4) OW2 & the CRA Ecosystem
- Speaker: Pierre-Yves Gibello
- Content: OW2’s perspective on the CRA, support planned for members, and OW2’s role in the broader open source response (e.g., collaboration with other foundations/initiatives).
16:40-16:50: 5) OSPO Alliance: Governance for CRA Compliance
- Speaker: Frédéric Aatz (TBC)
- Content: How the OSPO Alliance and the Good Governance Initiative (GGI) Handbook can help organizations, especially those with OSPOs, establish the processes and governance structures needed for CRA compliance (e.g., vulnerability management policies, role definitions).
16:50-17:30: 6) Breakout Groups: Addressing Key CRA Challenges
- Objective: Allow participants to dive deeper into specific areas of concern, share experiences, and generate actionable feedback/proposalsEach group addresses one topic.
Group 1: Am I Concerned? Understanding My Role & Obligations.
Focus Questions: How do I determine if the CRA applies to my OS activities? Which economic operator role(s) might I fit (Manufacturer, Steward, Importer, Distributor, or outside scope)? What are the immediate vslong-term obligations for that role? Using CNLL/inno³ scenarios as a starting point.
Facilitator: Benjamin Jean (or other inno³ expert).
Group 2: Technical Deep Dive: Adapting OS Processes & Tooling.
Focus Questions: What practical changes are needed in development lifecycles (SDL)? How to effectively implement SBOMs (tools, standards like SPDX/CycloneDX)? Best practices for vulnerability management and coordinated disclosure in an OS context? What tools are emerging (e.g., from OCCTET) or needed?
Facilitator: Stefane Fermigier (or technical expert).
Group 3: CRA Implementation: Ecosystem Impact & Advocacy.
Focus Questions: How will CRA enforcement and market surveillance work for OS? What is the role of notified bodies? How can the OS ecosystem (foundations, projects, businesses) effectively engage with standardization bodies (CEN/CENELEC/ETSI) and the CRA Expert Group? What are the key messages for policymakers regarding OS specificities?
Facilitator: Sebastian Raible (or policy expert).
17:30-17:50 7) Collective Restitution & Plenary Discussion
- Facilitator: Stefane Fermigier
- Content: Each breakout group’s rapporteur shares their 2-3 key takeaways (3-4 minutes per group).
- Brief open Q&A and discussion based on the feedback.
17:50-18:00 8) Wrap-up, Call to Action & Next Steps
- Speaker: Stefane Fermigier
- Content:
Summarize key themes from presentations and breakouts, reiterate key CRA deadlines.
Call to Action:
Review CNLL/inno³ Guide & OSPO Alliance GGI Handbook.
Engage with ORC WG (review drafts, join TFs if relevant).
Explore OCCTET resources as they become available.
Prepare to participate in upcoming standardization public enquiries.
Contribute feedback from the workshop to enrich guides/handbooks (mechanism TBD by OW2/CNLL/OSPO Alliance).
Information on how OW2 will follow up and continue to support its members.
Call for Participation
Proposals of presentations in this Breakout Session can be done by sending your proposal to event-team@ow2.org
Co-organizers
This Breakout session is coordinated by OW2 with the support of inno³, the CNLL and the OSPO Alliance


