Tech Talk Recap: A Practitioner’s Guide to CRA Readiness
Cybersecurity Classified by Officially
By Angelah Liu
The EU Cyber Resilience Act is no longer a distant regulatory concept. With vulnerability reporting obligations to ENISA arriving on September 11 and the full weight of the law landing in December 2027, open source maintainers, foundations, and the companies who build on top of open source all have real questions about what comes next. OpenSSF brought together three practitioners for a Tech Talk to walk through exactly that: what the CRA requires, how supply chain security practices map to those obligations, and what manufacturers are actually building to get ready.
Moderated by Megan Knight, Director of Software Communities at Arm, the session featured Roman Zhukov from Red Hat, who works on open source security strategy and engagement and is involved with the EU CRA effort; John Kjell previously of ControlPlane (and now at Docker!), co-chair of CNCF’s TAG Security and an OpenSSF Ambassador; and Nicole Bates from Microsoft’s Azure Office of the CTO, who co-chairs both the IETF’s Supply Chain Integrity Working Group and OpenSSF’s Supply Chain Integrity Working Group along with the ORBIT Launchpad SIG.
The recording is now live on YouTube. Download the presentation deck.
What Is the EU Cyber Resilience Act (CRA) and How Does It Affect Open Source Software?
Roman opened the Tech Talk with a sobering statistic from the newly released 2026 CRA Awareness and Readiness Report: 66% of respondents said they were still unfamiliar with the regulation, even with the first reporting deadline less than a month away. Only 41% of manufacturers expect to be fully compliant by the December 2027 deadline, and 39% said they simply don’t know when they will achieve compliance.
This is an extract. The publication continues at the source.
Read the original at the source: https://openssf.org/blog/2026/09/10/tech-talk-recap-a-practitioners-guide-to-cra-readiness/
Officially imported this from Open Source Security Foundation’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Open Source Security Foundation — imported from official source
- Official source
- https://openssf.org/feed/ RSS
- Imported
- September 18, 2026 11:34
- Versions
- 1 recorded
- Identity
https://openssf.org/?p=11738