← Back to feed
Policy & RegulationEmerging1 sourceSep 10, 2026 · 19:39via OpenSSF Blog

Tech Talk Recap: A Practitioner’s Guide to CRA Readiness

Brief

By Angelah Liu

The EU Cyber Resilience Act is no longer a distant regulatory concept. With vulnerability reporting obligations to ENISA arriving on September 11 and the full weight of the law landing in December 2027, open source maintainers, foundations, and the companies who build on top of open source all have real questions about what comes next.

OpenSSF brought together three practitioners for a Tech Talk to walk through exactly that: what the CRA requires, how supply chain security practices map to those obligations, and what manufacturers are actually building to get ready.

Moderated by Megan Knight, Director of Software Communities at Arm, the session featured Roman Zhukov from Red Hat, who works on open source security strategy and engagement and is involved with the EU CRA effort; John Kjell previously of ControlPlane (and now at Docker!)

Read more on OpenSSF Blog→