← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 11, 2026 · 16:04via OpenSSF Blog

A Community Guide to the EU CRA September 11 Deadline for Manufacturers

Brief

By Madalin Neag, Sally Cooper, and Steve Winslow

If you are a maintainer, steward, or manufacturer, you might have heard about the EU Cyber Resilience Act (CRA) and wondered how it impacts your day-to-day work. The CRA requirements for Stewards do not take effect until December 11, 2027, but the requirements for Manufacturers take effect today, on September 11, 2026.

The CRA introduces new cybersecurity requirements for products with digital elements, with responsibilities that differ across the software ecosystem. Most of the open source software community will qualify under the CRA’s Steward framework, but knowing how the CRA will impact your downstream commercial ecosystem, who will be classified as Manufacturers, will be important.

Read more on OpenSSF Blog→