Skip to main content

ORC Monthly: CRA Expert Group, Recent Workshops, and More

By Juan Rico

The Open Regulatory Compliance WG has created new resources on GitHub for those who are just getting started or who want to learn how to contribute. We hosted our first workshop in Brussels, joined the EU Open Source Policy Summit and attended the first CRA Expert Group meeting, had multiple community members present during FOSDEM, and developed a deliverables plan that better defines next steps and how others can contribute.

Timo Perala and Dirk-Willem van Gulik
ORC co-chairs

What’s New

Top Conversations

[open-regulatory-compliance] ENISA 2025-2027 Programming Document Posted by Roman Zhukov

What are the timelines for standards drafting and compliance? Manufacturer FAQ

So I “monetise” on an open source project, what does it mean for me? FAQ – During the CRA Expert Group meeting in Brussels, ORC shared this question as an example of maintainer concerns about the CRA.

Overheard

Christopher Jenkins's LinkedIn post: Another great example of cooperation between Red Hat and the wider open source communities. Many thanks to the Open Regulatory Compliance Working Group for hosting such a lively day of collaboration and workshops around the Cyber Resilience Act in Brussels. This image sums up quite a lot … we’re here but we really need to understand what’s next and how we (projects, stewards and manufacturers) can really work together to understand and harmonise the standards together. Did you noticed that I used the word “together“ twice? That’s because we can’t do this in separate, disparate solos - collaboration is key.

Upcoming Events

Cyber Resilience SIG | Monday, March 3 (Occurs Biweekly)

Embedded World 2025 | Tuesday, March 11 - ORC will be part of the Eclipse Foundation booth, stop by to chat with Juan Rico, ORC Program Manager.

9th Cybersecurity Standardisation Conference | Thursday, March 20 - Tobie Langel is speaking on the panel “Overarching cybersecurity by standards”.

CVE/FIRST VulnCon 2025 & Annual CNA Summit | April 7-10 - Collaborate with various vulnerability management and cybersecurity professionals to develop forward leaning ideas that can be taken back to individual programs for action to benefit the vulnerability management ecosystem.

View all events

In the News

What the EU’s new software legislation means for developers - Felix Reda, GitHub Blog

Neues vom Cyber Resilience Act – Ein Blick hinter die Kulissen - Open Source Business Alliance

2024 end-of-year review: policy and standards - Open Source Initiative

Recent Talks

Screenshot of the recording 'The CRA has landed. Now what?'

Watch: The CRA has landed. Now what? | View all talks

Welcome ORC Members

The following members joined in January and February 2025:

How to Participate

Back to the top