OpenSSF is hosting a virtual Tech Talk on August 20 focused on EU Cyber Resilience Act (CRA) compliance for software manufacturers, open source stewards, and commercial entities. With the September 2026 reporting deadline approaching and full compliance required by December 2027, the session covers empirical findings from the 2026 CRA Awareness and Readiness Report, real-world case studies from OpenSSF member companies on SBOM and provenance practices, and an overview of the newly launched Launchpad SIG under the Global Cyber Policy Working Group. Speakers include representatives from Arm, Red Hat, ControlPlane, and Microsoft.

3m read timeFrom openssf.org
Post cover image
Table of contents
What will you learn?What’s in this Tech Talk?Who are the speakers?Secure Your Spot Today

Questions this post answers

What are the key CRA compliance deadlines for software manufacturers?

The EU Cyber Resilience Act has two critical deadlines: a reporting obligation deadline in September 2026 and a full compliance deadline in December 2027. Organizations that build, distribute, or commercialize software with digital elements must be operationally ready by these dates, not merely familiar with the policy requirements. Teams navigating CRA timelines track regulatory milestones and peer implementation strategies on daily.dev.

159 Impressions