Preparing for the First CRA Deadline: Resources for the Open Source Community
By Juan Rico
The first compliance deadline under the European Union’s Cyber Resilience Act (CRA) is approaching. Starting 11 September 2026, manufacturers and stewards will be required to report actively exploited vulnerabilities and severe incidents affecting the security of products with digital elements.
Under the CRA, an early warning must be submitted within 24 hours of becoming aware of an actively exploited vulnerability or severe incident, followed by a more complete notification within 72 hours. Additional reporting requirements apply after those initial notifications. Reports will be submitted through the CRA Single Reporting Platform established by ENISA.
A number of resources have been published or updated in recent weeks by the European Commission, ENISA, standards organisations, national cybersecurity authorities, and open source organisations. With so much to wade through, we have collected some of the most relevant resources to get you started.
Start with the CRA guidance and reporting requirements
The European Commission has published its implementation guidance on the CRA, providing clarification on a range of topics including manufacturers, products with digital elements, open source software, open source software stewards, vulnerability reporting, and other aspects of implementation.
For the open source community, the guidance is particularly relevant because it provides further clarification on how the CRA applies to open source development and the different roles within the software supply chain.
We recently published a summary of the key points for open source following the release of the final guidance.
For the September deadline specifically, the Commission has also published a dedicated page on CRA reporting obligations. It explains which vulnerabilities and incidents must be reported, the applicable timelines, how notifications are distributed, and the role of the Single Reporting Platform.
The ORC CRA FAQ is also a useful starting point for questions about how the CRA applies to developers, maintainers, manufacturers, and other actors in the open source ecosystem. It brings together community FAQs, the European Commission’s official FAQs, and topics where further clarification is still pending.
Prepare for vulnerability and incident reporting
From 11 September, CRA notifications will be submitted through the Single Reporting Platform (SRP) established by ENISA.
Manufacturers will use the platform to report actively exploited vulnerabilities and severe security incidents. The notification is addressed to the relevant Computer Security Incident Response Team (CSIRT), with information also made available to ENISA and, in most circumstances, shared with other relevant CSIRTs.
ENISA has published information to help organisations understand how the platform and reporting process will work, including an SRP factsheet and supporting guidance. The Commission states that the platform will be operational when the reporting obligations begin on 11 September. ORC participated in the testing phase of the SRP and provided feedback on its early implementation, identifying several practical challenges that could not all be addressed before launch. ORC will continue to collect feedback from the community and share it with ENISA as the system is used in practice.
Organisations that expect to have reporting obligations may want to review these materials alongside their existing vulnerability management and incident response processes before the deadline.
Understand how the CRA applies to your role
Not everyone participating in open source has the same responsibilities under the CRA.
The regulation distinguishes between different actors, including manufacturers and open source software stewards, while people contributing to open source outside the course of a commercial activity are treated differently.
For those looking for a structured introduction to the CRA, the ORC Learning Hub currently provides two introductory courses.
Introduction to the CRA for the Open Source Community is designed for developers, maintainers, contributors, and open source project stewards. It covers how the CRA applies to open source projects, the distinction between open source actors and manufacturers, vulnerability handling, SBOMs, and secure-by-design concepts.
Introduction to the CRA for Manufacturers is intended for product teams, security and compliance professionals, OSPO leaders, and legal and regulatory teams. It covers manufacturer obligations, organisational responsibilities, supply-chain accountability, and security-by-design requirements.
Both courses are available for free through the ORC Learning Hub.
Full list of resources
- European Commission CRA implementation guidance
- European Commission: CRA reporting obligations
- ORC analysis: Key takeaways from the CRA implementation guidance
- ORC CRA FAQ
- ENISA: CRA Single Reporting Platform
- ORC’s feedback on the SRP
- ORC Learning Hub
The CRA implementation landscape will continue to evolve beyond the September reporting deadline, with most obligations becoming applicable in 2027. ORC will continue to develop and update implementation resources, including work on vulnerability management, due diligence, SBOMs, and security attestations, while tracking relevant guidance and standards. Visit our CRA Resources page for the latest deliverables and updates.
Join us in Brussels
You can also join us 27 October in Brussels for Code & Compliance, where we’ll continue these conversations in person. The programme will focus on practical approaches to developing compliant products, navigating evolving EU regulatory requirements including the CRA and AI Act, and sharing experiences across the open source, industry, policy, and standards communities. Registration is now open, and we hope to see you there.
