{"id":20353,"date":"2025-02-19T19:03:47","date_gmt":"2025-02-19T18:03:47","guid":{"rendered":"https:\/\/telecomkh.info\/?p=20353"},"modified":"2025-02-19T19:03:47","modified_gmt":"2025-02-19T18:03:47","slug":"linux-foundation-europe-and-openssf-launch-initiative-to-prepare-maintainers-manufacturers-and-open-source-stewards-for-implementing-global-cybersecurity-legislation","status":"publish","type":"post","link":"https:\/\/telecomkh.info\/?p=20353","title":{"rendered":"Linux Foundation Europe and OpenSSF launch initiative to prepare maintainers, manufacturers, and Open Source stewards for implementing global cybersecurity legislation"},"content":{"rendered":"<p><strong>Leading organizations support global cybersecurity legislation preparedness efforts for open source communities<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"color: #999999;\"><em>By Linux Foundation<\/em><\/span><\/p>\n<p>Linux Foundation Europe and OpenSSF are excited to announce a global joint-initiative to help prepare maintainers, manufacturers, and open source stewards for the implementation of the EU Cyber Resilience Act (CRA) and future cybersecurity legislation targeting jurisdictions around the world. This effort aims to help develop and formalize much needed cybersecurity standards and compliance frameworks, to help 100+ million open source communities understand and meet the regulatory requirements outlined in the CRA, with the goal of expanding efforts to address legislation around the world.<br \/>\nThe initiative builds on the discussions and outcomes of the recent Open Source Software Stewards and Manufacturers Workshop, where key stakeholders came together to address the critical work needed to align manufacturers, open source projects, and open source software stewards with the requirements outlined in the CRA.<br \/>\n\u201cAs software becomes increasingly regulated across the globe, and as the steward for some of the most critical open source projects in the world, we feel the responsibility to reduce friction for our maintainers and software manufacturers leveraging upstream open source to comply with these regulations,\u00bb said Mirko Boehm, Senior Director for Community Development at Linux Foundation Europe. \u00abWhile the CRA represents the most immediate priority, our global nature means we can support projects across jurisdictions and prevent the burden of a fragmented regulatory landscape through established community driven standards and tools like those in OpenSSF \u201d<br \/>\nWhile the initiative is driven by the immediate need to address the EU Cyber Resilience Act, its implications extend far beyond Europe. With cybersecurity now a global concern, the diverse participation from companies across regions, including the United States, APAC, and others, highlights the universal relevance of this effort. The goal is to equip open source communities and manufacturers worldwide with the tools they need to meet not only European requirements but also the evolving security standards in markets around the globe.<br \/>\n\u201cCybersecurity is a matter of global concern. I am excited to see efforts like the EU\u2019s CRA come online as it touches on topics we&#8217;ve been working to embed within organizations\u2019 cybersecurity practices for decades,\u00bb said Christopher \u201cCRob\u201d Robinson, Chief Security Architect of the OpenSSF. \u00abI firmly believe that the responsibility for these practices rightly falls upon commercial entities to perform and provide, not the upstream open source maintainers. Mature manufacturers should already be doing the majority of the legislated requirements, while those that are not doing them will still have a short runway until the CRA finally goes into effect in 2027.\u201d<br \/>\nThe EU Cyber Resilience Act sets new regulatory requirements for software security, placing a significant emphasis on the safety and security of digital products sold within the European market. As key players in the global open source community, Linux Foundation Europe and OpenSSF are taking proactive steps to provide compliance guidance and tooling for maintainers and manufacturers, ensuring they are fully prepared for the act\u2019s enforcement.<\/p>\n<p><strong>Key Deliverables and Next Steps<\/strong><br \/>\nThe initiative will focus on several core deliverables over the coming months to help EU policy makers, including:<br \/>\n\u2022 Discussing and formalizing cybersecurity specifications: Developing community-driven standards to ensure open source projects can meet the security requirements outlined in the CRA.<br \/>\n\u2022 Providing compliance guidance: Offering tools, processes, and best practices to help maintainers, manufacturers, and developers align with the new regulations.<br \/>\n\u2022 Implementing compliance processes and tooling: Creating resources to support the open source community in automating and managing compliance with the CRA across upstream projects.<\/p>\n<p><strong>Supporting Quotes<\/strong><br \/>\n\u00abAs regulatory standards for security continue to evolve, it\u2019s crucial that open source ecosystems remain resilient, secure and prepared to meet these requirements. With over 20 million software developers building their applications on the Arm compute platform, we recognize the critical role that open source plays in driving innovation and securing the digital ecosystem. Through Arm\u2019s involvement in this new initiative, our goal is to create resources that help open source projects, manufacturers, and developers understand their roles under the EU CRA, while offering tools and best practices to streamline compliance management.\u201d<br \/>\n\u2013 Megan Knight, Awareness SIG Lead and Director of Software Communities at Arm<\/p>\n<p>\u201cThe Cyber Resilience Act will be both a challenge and an opportunity for the software industry and the global open source community. It is fundamentally important to prepare the entire ecosystem and all its participants in due time to meet the expectations set forth by the CRA. Ericsson welcomes the initiative of the Linux Foundation Europe and the OpenSSF to facilitate the development of crucial specifications, tools, and guidance to ensure CRA readiness. We look forward to collaborating with open source foundations, open source stewards, independent projects, and industry partners on this critical endeavour.\u201d<br \/>\n\u2013 Per Beming, Chief Standardization Officer, Ericsson<\/p>\n<p>\u201cAll open source projects stand to benefit from easily implementable cybersecurity practices,\u201d said Felix Reda, Director of Developer Policy at GitHub. \u201cGitHub continues to engage with the European Commission to advocate for and achieve the greatest level of regulatory clarity for open source developers, and initiatives like that of Linux Foundation and OpenSSF are crucial for preparing the community for compliance with the Cyber Resilience Act.\u201d<br \/>\n\u2013 Felix Reda, Director of Developer Policy at GitHub<\/p>\n<p>\u201cThe Cyber Resilience Act is a significant step toward ensuring digital products meet essential security standards. I\u2019m encouraged by its focus on placing liability on organizations that profit from open source software, not maintainers. I\u2019m also excited to see the OpenSSF advancing frameworks like the Security Baseline to support compliance. Cybersecurity is a team effort, and we look forward to collaborating with the EU and the broader community to build a safer world.\u201d<br \/>\n\u2013 Michael Lieberman, Co-Founder and CTO, Kusari<\/p>\n<p>\u201cCybersecurity readiness is critical for all open source projects, including those in the JavaScript ecosystem, which powers nearly a billion applications worldwide. The OpenJS Foundation fully supports this initiative to help open source maintainers, manufacturers, and stewards navigate evolving global regulations like the EU Cyber Resilience Act. By equipping developers with the right tools and frameworks, we can ensure that open source remains a secure and trusted foundation for innovation.\u201d<br \/>\n\u2013 Robin Ginn, Executive Director, OpenJS Foundation<\/p>\n<p>\u201cThe CRA represents a step forward in protecting the digital ecosystem. By enforcing strict cybersecurity measures, the CRA provides confidence that products entering the EU market are safer and more resilient, which can mean fewer vulnerabilities and reduced risks for businesses and their customers. However, these rules add new responsibilities and due diligence for organisations in the EU who are using open source projects in their in-scope products. Red Hat believes engaging with open source communities like the OpenSSF will be instrumental in furthering wide-spread adoption of open source software in Europe and globally, as vendors, communities and developers work together to create trustworthy software.\u201d<br \/>\n\u2013 Vincent Danen, Vice President of Product Security at Red Hat<\/p>\n<p>\u00abThe EU Cyber Resilience Act represents a real opportunity for Open Source to embed good security and development practices in our work for the benefit of consumers. We were pleased that the EU recognised the unique role of Open Source Stewards in the development of software, and we now need to rise to the challenge of implementing these forthcoming standards. The work of organisations such as OpenSSF and Linux Foundation Europe is critical in preparing Open Source Stewards for these changes, and their support and expertise will, I&#8217;m sure, enable the Open Source community to achieve successful compliance.\u00bb<br \/>\n\u2013 Rebecca Rumbul, Executive Director &amp; CEO, Rust Foundation<\/p>\n<p><span style=\"color: #999999;\"><em>Above, Mirko Boehm, Senior Director for Community Development at Linux Foundation Europe \/ image credited to Linux Foundation Europe<\/em><\/span><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Leading organizations support global cybersecurity legislation preparedness efforts for open source communities &nbsp; By Linux Foundation Linux Foundation Europe and OpenSSF are excited to announce a global joint-initiative to help prepare maintainers, manufacturers, and open source stewards for the implementation of the EU Cyber Resilience Act (CRA) and future cybersecurity legislation targeting jurisdictions around the &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/telecomkh.info\/?p=20353\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> \u00abLinux Foundation Europe and OpenSSF launch initiative to prepare maintainers, manufacturers, and Open Source stewards for implementing global cybersecurity legislation\u00bb<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":20354,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[24],"tags":[],"_links":{"self":[{"href":"https:\/\/telecomkh.info\/index.php?rest_route=\/wp\/v2\/posts\/20353"}],"collection":[{"href":"https:\/\/telecomkh.info\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/telecomkh.info\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/telecomkh.info\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/telecomkh.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=20353"}],"version-history":[{"count":1,"href":"https:\/\/telecomkh.info\/index.php?rest_route=\/wp\/v2\/posts\/20353\/revisions"}],"predecessor-version":[{"id":20355,"href":"https:\/\/telecomkh.info\/index.php?rest_route=\/wp\/v2\/posts\/20353\/revisions\/20355"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/telecomkh.info\/index.php?rest_route=\/wp\/v2\/media\/20354"}],"wp:attachment":[{"href":"https:\/\/telecomkh.info\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=20353"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/telecomkh.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=20353"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/telecomkh.info\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=20353"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}