What’s in the SOSS? Podcast #71 – S3E23 Navigating the New Era: The EU Cyber Resilience Act Explained with Madalin Neag
Cybersecurity Classified by Officially
Summary
In this episode of What’s in the SOSS, host Sally Cooper is joined by Madalin Neag, EU Policy Advisor at the OpenSSF, to demystify the European Union’s Cyber Resilience Act (CRA). As the tech industry shifts from treating open source as a free buffet to navigating a new era of regulatory liability, Madalin explains how the CRA establishes a horizontal cybersecurity baseline for digital products. The conversation explores the innovative concept of “open source software stewards,” the importance of moving beyond passive consumption to active upstream contribution, and why compliance should be viewed as an outcome of good engineering rather than a separate checkbox exercise. Whether you are a manufacturer of smart devices or a volunteer maintainer, this episode provides essential insights into how the CRA will reshape the global software supply chain, encouraging a secure-by-design mindset that strengthens the entire digital ecosystem.
This episode is part 4 of a four-part series on the CRA:
1. CRA Readiness: Practical Strategies for Open Source Communities with Megan Knight
2. Watering the Community Garden: Navigating the EU CRA for Open Source with Roman Zhukov
3. Private Forks, CRA Deadlines, and the True Cost of Open Source Compliance with Dave Russo
Listen on Apple PodcastsListen on SpotifyListen on OvercastListen on Pocket CastsConversation Highlights
00:23 – Introductions and Madalin’s role at OpenSSF
03:42 – What is the Cyber Resilience Act (CRA)?
05:27 – The CRA in the global regulatory landscape
09:05 – Relevance to open source and the “Software Steward” concept
13:02 – Moving from passive consumption to upstream contribution
16:20 – Practical steps for organizational readiness
20:26 – Should open source maintainers be worried?
24:12 – Insights from the Linux Foundation CRA Readiness Report
31:32 – What to watch for in the coming year
34:07 – Rapid fire round and concluding thoughts
Episode Links
This is an extract. The publication continues at the source.
Read the original at the source: https://openssf.org/podcast/2026/09/01/whats-in-the-soss-podcast-71-s3e23-navigating-the-new-era-the-eu-cyber-resilience-act-explained-with-madalin-neag/
Officially imported this from Open Source Security Foundation’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Open Source Security Foundation — imported from official source
- Official source
- https://openssf.org/feed/ RSS
- Imported
- September 18, 2026 11:34
- Versions
- 1 recorded
- Identity
https://openssf.org/?p=11642