A podcast episode features Roman Zhukov, co-chair of the OpenSSF Global Cyber Policy Working Group and Security Communities Lead at Red Hat, explaining the EU Cyber Resilience Act (CRA) using a community garden analogy to define maintainers, stewards, and manufacturers. The conversation covers findings from the 2026 CRA Awareness and Readiness Report, including that 66% of organizations remain unaware of the regulation, over 70% of North American software producers are unfamiliar with it, and maintaining private forks costs organizations over $250,000 per release cycle in engineering overhead. Key CRA deadlines are discussed: vulnerability reporting obligations begin September 2026, with full compliance required by December 2027. The discussion also touches on AI-generated vulnerability report spam, the end of the 'consume and forget' open source model, and free OpenSSF resources like OSPS, SLSA, Gemara, GUAC, and a free CRA training course.
Questions this post answers
When do the EU Cyber Resilience Act vulnerability reporting obligations take effect?
Organizations subject to the EU Cyber Resilience Act must begin reporting vulnerabilities and severe incidents to authorities starting September 2026, ahead of the full compliance deadline of December 2027, after which non-compliant hardware and software vendors will be unable to sell products in the EU market. daily.dev helps teams tracking regulatory deadlines like the CRA stay ahead of compliance work.
How much does maintaining a private fork of an open source project cost compared to contributing upstream?
Maintaining private forks costs organizations more than $250,000 per release cycle in engineering labor, according to the 2026 CRA Awareness and Readiness Report. This 'rebase tax' comes from manually porting patches over every new upstream release, whereas upstreaming changes lets the community inherit maintenance and reduces long-term legal risk exposure under the CRA. engineers weighing forking versus upstreaming can follow this trade-off discussion on daily.dev.
Who is exempt from the EU Cyber Resilience Act as an open source maintainer?
Independent maintainers doing non-commercial open source work are completely exempt from the CRA and fall out of scope of the regulation. Obligations instead fall on stewards, such as foundations like OpenSSF or Linux Foundation that set baseline policies for hosted projects, and manufacturers, companies that sell commercial products built on open source code, who bear the full legal liability. daily.dev surfaces regulatory shifts like this for developers navigating open source compliance roles.