What’s in the SOSS? Podcast #71 – S3E23 Navigating the New Era: The EU Cyber Resilience Act Explained with Madalin Neag

Imported from official source

Cybersecurity Classified by Officially

Summary

In this episode of What’s in the SOSS, host Sally Cooper is joined by Madalin Neag, EU Policy Advisor at the OpenSSF, to demystify the European Union’s Cyber Resilience Act (CRA). As the tech industry shifts from treating open source as a free buffet to navigating a new era of regulatory liability, Madalin explains how the CRA establishes a horizontal cybersecurity baseline for digital products. The conversation explores the innovative concept of “open source software stewards,” the importance of moving beyond passive consumption to active upstream contribution, and why compliance should be viewed as an outcome of good engineering rather than a separate checkbox exercise. Whether you are a manufacturer of smart devices or a volunteer maintainer, this episode provides essential insights into how the CRA will reshape the global software supply chain, encouraging a secure-by-design mindset that strengthens the entire digital ecosystem.

This episode is part 4 of a four-part series on the CRA:

1. CRA Readiness: Practical Strategies for Open Source Communities with Megan Knight

2. Watering the Community Garden: Navigating the EU CRA for Open Source with Roman Zhukov

3. Private Forks, CRA Deadlines, and the True Cost of Open Source Compliance with Dave Russo

Listen on Apple PodcastsListen on SpotifyListen on OvercastListen on Pocket Casts

Conversation Highlights

00:23 – Introductions and Madalin’s role at OpenSSF
03:42 – What is the Cyber Resilience Act (CRA)?
05:27 – The CRA in the global regulatory landscape
09:05 – Relevance to open source and the “Software Steward” concept
13:02 – Moving from passive consumption to upstream contribution
16:20 – Practical steps for organizational readiness
20:26 – Should open source maintainers be worried?
24:12 – Insights from the Linux Foundation CRA Readiness Report
31:32 – What to watch for in the coming year
34:07 – Rapid fire round and concluding thoughts

Episode Links

This is an extract. The publication continues at the source.

Read the original at the source: https://openssf.org/podcast/2026/09/01/whats-in-the-soss-podcast-71-s3e23-navigating-the-new-era-the-eu-cyber-resilience-act-explained-with-madalin-neag/

Officially imported this from Open Source Security Foundation’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
Open Source Security Foundation — imported from official source
Official source
https://openssf.org/feed/ RSS
Imported
September 18, 2026 11:34
Versions
1 recorded
Identity
https://openssf.org/?p=11642

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.