Case Study: Conquering the EU Cyber Resilience Act (CRA) with 1,400 Upstream Security Fixes
Brief
Ericsson Software Technology successfully met the stringent obligations of the EU Cyber Resilience Act by fundamentally changing their engineering strategy. Instead of maintaining private forks, the team engaged in upstream collaboration guided by OpenSSF principles.
They contributed 214 direct security fixes and over 1,400 dependency updates to open source communities, significantly lowering lifecycle costs and strengthening the global supply chain against vulnerabilities.
This case study is based on the YouTube presentation “Upstream Collaboration for the Win (of the CRA)!” delivered by Georg Kunz and Jan Melen. Links to the presentation and resources are provided at the end of this page.
What were the challenges with Cyber Resilience Act compliance?
