<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/what-s-in-the-soss-navigating-the-eu-cyber-resilience-act-with-madalin-neag-51ysfd9dr" -->

---
title: What’s in the SOSS? Navigating the EU Cyber Resilience...
description: An OpenSSF podcast episode features EU Policy Advisor Madalin Neag explaining the Cyber Resilience Act (CRA), the EU&#x27;s horizontal cybersecurity regulation for...
canonical: https://daily.dev/posts/what-s-in-the-soss-navigating-the-eu-cyber-resilience-act-with-madalin-neag-51ysfd9dr
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: What’s in the SOSS? Navigating the EU Cyber Resilience Act with Madalin Neag | daily.dev
og:description: An OpenSSF podcast episode features EU Policy Advisor Madalin Neag explaining the Cyber Resilience Act (CRA), the EU&#x27;s horizontal cybersecurity regulation for...
og:url: https://daily.dev/posts/what-s-in-the-soss-navigating-the-eu-cyber-resilience-act-with-madalin-neag-51ysfd9dr
og:image: https://api.daily.dev/og/posts/51ySfd9Dr.png
og:image:alt: What’s in the SOSS? Navigating the EU Cyber Resilience Act with Madalin Neag
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# What’s in the SOSS? Navigating the EU Cyber Resilience Act with Madalin Neag

**[OpenSSF](https://daily.dev/sources/openssf)** · 27 min read · 0 upvotes · 0 comments

## Summary

An OpenSSF podcast episode features EU Policy Advisor Madalin Neag explaining the Cyber Resilience Act (CRA), the EU's horizontal cybersecurity regulation for products with digital elements. Topics covered include the new 'open source software steward' concept, why individual volunteer maintainers generally are not liable under CRA, practical readiness steps for manufacturers (role identification, SBOMs, secure development practices, automation), findings from the Linux Foundation's 2026 CRA Awareness and Readiness Report showing roughly two-thirds of organizations are unfamiliar with or unsure whether CRA applies to them, and the importance of shifting from passive open source consumption to active upstream contribution.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://openssf.org/podcast/2026/09/01/whats-in-the-soss-podcast-71-s3e23-navigating-the-new-era-the-eu-cyber-resilience-act-explained-with-madalin-neag>

## Questions this post answers

### Does the EU Cyber Resilience Act make individual open source contributors legally liable?

No. Contributors remain contributors, and legal responsibility cannot be pushed upstream to people writing code in their spare time. Simply publishing free and open source software under an open license is generally not considered placing a product on the market. Responsibility generally falls on the entity that publishes, controls releases, and governs the software commercially.

_Teams tracking regulatory shifts like the CRA can follow open source policy developments on daily.dev._

### What is an open source software steward under the EU Cyber Resilience Act?

It is a legal concept recognizing organizations, such as foundations, that systematically support the development and long-term sustainability of open source software intended for commercial use. Stewardship is determined on a project-by-project basis, so the same entity could be a steward for one project while acting as a manufacturer with full CRA obligations for another if it commercially places that product on the EU market.

_daily.dev helps engineers stay current on regulatory concepts like open source stewardship shaping supply chain decisions._

### How prepared are organizations for the EU Cyber Resilience Act deadlines?

Roughly two-thirds of organizations surveyed in the Linux Foundation's 2026 CRA Awareness and Readiness Report either weren't familiar with the CRA or didn't know whether it applied to them, despite the regulation's broad scope covering most hardware and software products with digital elements sold in the EU, with key deadlines in September and December.

_Teams assessing their own CRA readiness can track ongoing compliance guidance and analysis on daily.dev._

## Similar posts on daily.dev

- [What’s in the SOSS? Podcast \#69 – S3E21 Watering the Community Garden: Navigating the EU CRA for Open Source with Roman Zhukov – Open Source Security Foundation](https://daily.dev/posts/what-s-in-the-soss-podcast-69-s3e21-watering-the-community-garden-navigating-the-eu-cra-for-ope-ela77x7o0) · OpenSSF · 0 upvotes · 0 comments
- [CRA Readiness for Open Source Communities](https://daily.dev/posts/cra-readiness-for-open-source-communities-txer6gy10) · OpenSSF · 0 upvotes · 0 comments

---

Tags: [#open-source](https://daily.dev/tags/open-source), [#compliance](https://daily.dev/tags/compliance), [#sbom](https://daily.dev/tags/sbom)

[View this post on daily.dev](https://daily.dev/posts/what-s-in-the-soss-navigating-the-eu-cyber-resilience-act-with-madalin-neag-51ysfd9dr)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"What’s in the SOSS? Navigating the EU Cyber Resilience Act with Madalin Neag","url":"https://daily.dev/posts/what-s-in-the-soss-navigating-the-eu-cyber-resilience-act-with-madalin-neag-51ysfd9dr","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/what-s-in-the-soss-navigating-the-eu-cyber-resilience-act-with-madalin-neag-51ysfd9dr"},"datePublished":"2026-09-01T13:21:21.369Z","dateModified":"2026-09-01T13:21:49.310Z","description":"An OpenSSF podcast episode features EU Policy Advisor Madalin Neag explaining the Cyber Resilience Act (CRA), the EU's horizontal cybersecurity regulation for...","image":"https://media.daily.dev/image/upload/s--OHB84bZF--/f_auto/v1722860399/public/Placeholder%2010","thumbnailUrl":"https://media.daily.dev/image/upload/s--OHB84bZF--/f_auto/v1722860399/public/Placeholder%2010","isAccessibleForFree":true,"articleSection":"OpenSSF","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"OpenSSF","logo":"https://media.daily.dev/image/upload/s--l6RJ5uPj--/f_auto,q_auto/v1774959959/logos/openssf?_a=BAMAMiWQ0","url":"https://daily.dev/sources/openssf"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/what-s-in-the-soss-navigating-the-eu-cyber-resilience-act-with-madalin-neag-51ysfd9dr","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"open-source,compliance,sbom","timeRequired":"PT27M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"OpenSSF","item":"https://daily.dev/sources/openssf"},{"@type":"ListItem","position":3,"name":"What’s in the SOSS? Navigating the EU Cyber Resilience Act with Madalin Neag"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/what-s-in-the-soss-navigating-the-eu-cyber-resilience-act-with-madalin-neag-51ysfd9dr#faq","mainEntity":[{"@type":"Question","name":"Does the EU Cyber Resilience Act make individual open source contributors legally liable?","acceptedAnswer":{"@type":"Answer","text":"No. Contributors remain contributors, and legal responsibility cannot be pushed upstream to people writing code in their spare time. Simply publishing free and open source software under an open license is generally not considered placing a product on the market. Responsibility generally falls on the entity that publishes, controls releases, and governs the software commercially. Teams tracking regulatory shifts like the CRA can follow open source policy developments on daily.dev."}},{"@type":"Question","name":"What is an open source software steward under the EU Cyber Resilience Act?","acceptedAnswer":{"@type":"Answer","text":"It is a legal concept recognizing organizations, such as foundations, that systematically support the development and long-term sustainability of open source software intended for commercial use. Stewardship is determined on a project-by-project basis, so the same entity could be a steward for one project while acting as a manufacturer with full CRA obligations for another if it commercially places that product on the EU market. daily.dev helps engineers stay current on regulatory concepts like open source stewardship shaping supply chain decisions."}},{"@type":"Question","name":"How prepared are organizations for the EU Cyber Resilience Act deadlines?","acceptedAnswer":{"@type":"Answer","text":"Roughly two-thirds of organizations surveyed in the Linux Foundation's 2026 CRA Awareness and Readiness Report either weren't familiar with the CRA or didn't know whether it applied to them, despite the regulation's broad scope covering most hardware and software products with digital elements sold in the EU, with key deadlines in September and December. Teams assessing their own CRA readiness can track ongoing compliance guidance and analysis on daily.dev."}}]}
```

