Skip to main content

What is the purpose of this new initiative?

The Open Regulatory Compliance Working Group (ORC WG) aims to facilitate compliance of all open source actors with regulatory requirements. To achieve this, the ORC WG:

The ORC WG strives to develop artefacts and best practices that help open source actors comply with regulatory requirements across jurisdictions.

What is the main focus of this initiative?

Initially, the ORC WG is focusing on the European Cyber Resilience Act (CRA). However, the working group members will continue to expand its work to include other global regulations and legislation as they develop.

Who is this initiative for?

This initiative is aimed at all participants within the open source ecosystem, including foundations, maintainers, vendors, users (including non software vendors using open source), package managers, and other related entities.

Why host this initiative at the Eclipse Foundation?

As Europe’s largest open source foundation, based in Brussels, the Eclipse Foundation AISBL is a natural home for this effort. The foundation supports a well established, robust open specification process and will host and promote the working group’s open specifications. The governance of the working group will follow the Eclipse Foundation’s usual member-led model, augmented by explicit representation from the open source community to ensure diversity and balance in decision-making.

Key benefits of this approach include:

What are the ultimate deliverables of this initiative?

The deliverables will consist of one or more process specifications made available under a liberal specification copyright licence and a royalty-free patent licence. The group’s initial effort is to enumerate the respective open source foundations’ security policies and procedures and similar documents describing best practices. With these as our starting point, we aim to accelerate the development of cohesive cybersecurity processes required for regulatory compliance while offering a neutral environment for hosting technical discussions with both industry and the open source community at large.

How can I get involved?

Participation is easy. Here are some links to help you get started:

Back to the top