ORC Monthly: FAQ Momentum, Code & Compliance, and EU Consultations
By Juan Rico
As we move into autumn, the momentum in our community continues to build. A particular highlight is the upcoming Code & Compliance Community Day 2025, taking place 22–23 October. The program is shaping up beautifully, with speakers being announced daily. This is your opportunity to connect with leading voices at the intersection of software compliance and open source. So now is the time to register and secure your spot.
We look forward to seeing many of you there as we continue to explore how open source can drive resilience, trust, and compliance across digital ecosystems.
Timo Perala and Dirk-Willem van Gulik
ORC co-chairs
What’s New
- Momentum Behind the CRA FAQ: The FAQ work has been revamped, with the proposal of an editorial structure and reorganization of the topics and processes, it will be easier to consume and contribute.
- Call for Events: Do you have an upcoming event of interest to the ORC community? Share it with us at news@eclipse.org.
- New Resources for New Members: A fresh “how to contribute” video and blog are now available to help onboard newcomers.
- OSS Stewards and the CRA White Paper: Work is progressing on the Open Source Software Stewards and CRA white paper, which will serve as a key reference for understanding responsibilities under the Cyber Resilience Act. Join the vulnerability handling task force meeting to get engage and contribute to it.
- ETSI launches early public consultations on draft CRA vertical standards: For the first time, ETSI is making drafts of standards available for public consultation much earlier than usual in the standardisation process. This pilot initiative puts into practice two key principles of international standardisation & ETSI’s values: openness and inclusiveness. STAN4CR.
- EU Survey on Critical Open Source Software – The European Commission conducted a survey on the governance and sustainability of critical open source software. It aims to identify best practices, shape future EU policies, and strengthen digital sovereignty. The survey was scheduled to close on 5 October 2025.
- Public Consultations: The European Commission has launched a consultation on the revision of the Standardisation Regulation. This is an opportunity to provide views on the future of European standardisation and its role in supporting innovation and competitiveness.
Overheard
In the news
Upcoming Events
- ETSI Security Conference 2025 | 6-9 October 2025
- CRA – Making the EU Market Resilient | 8 October 2025
- Code & Compliance Community Day | 22-23 October 2025
- Digital Resilience Forum | 29 October 2025
Recent Talks & Events
- CRA Mondays | Unlocking Software Supply Chain Security: Updates from Ecma TC54 and OWASP
- CRA Mondays | Why Do You Trust Software? Operationalizing CRA with the Eclipse Trustable Software Framework
Welcome ORC Members
The following members joined in September 2025: