Sign in

Open Regulatory Compliance

@orcwg.org
101 followers 63 following 193 posts

Global, industry-led collaboration helping organisations understand and implement open source compliance strategies under evolving regulations. Hosted by @eclipse.org Get free CRA training: orcwg.org/training/

PostsRepliesMedia
Open Regulatory Compliance @orcwg.org · 24/09/2026
📅 On 11 September 2026, mandatory reporting requirements for actively exploited vulnerabilities and incidents took effect. Understanding your role now will make compliance easier. That's why we built the new ORC Learning Hub: orcwg.org/training/
010
Open Regulatory Compliance @orcwg.org · 11/09/2026
📢 Today’s the day: The #CyberResilienceAct’s vulnerability reporting requirements are officially in effect across the EU. Compliance is no longer optional. Is your organisation ready? 🔗 Learn more: orcwg.org/cra #TechCompliance #ORCWG
000
Open Regulatory Compliance @orcwg.org · 10/09/2026
The first #CRA reporting obligations take effect tomorrow. A new free toolkit developed through the OCCTET project includes a CRA self-assessment portal, Eclipse Apoapsis for software composition analysis and SBOM generation. Explore it 👉 occtet.eu Read the PR 👉 newsroom.eclipse.org/news/announc...
000
Open Regulatory Compliance @orcwg.org · 09/09/2026
Guessing your way through complex EU #cybersecurity regulations? 🤔 You don't have to! Visit the ORC FAQ repository: cra.orcwg.org/faq/ ⭐️ Translates official European Commission responses into actionable realities. ⭐️ Is regularly updated by industry experts. ⭐️ Covers specialized categories.
000
Open Regulatory Compliance @orcwg.org · 08/09/2026
How does EU law explicitly define "Free and Open Source Software" in the context of the #CyberResilienceAct? Protecting this definition ensures non-commercial collaboration remains free from unmanageable legal burdens. 📜 Explore the legal definitions and annotations: cra.orcwg.org/faq/projects/
000
Open Regulatory Compliance @orcwg.org · 08/09/2026
As Cyber Resilience Act (CRA) obligations continue rolling out, understanding their impact has never been more important. The new ORC Learning Hub provides practical guidance built for the open source ecosystem. Start learning now: orcwg.org/training/
000
Open Regulatory Compliance @orcwg.org · 04/09/2026
The final #CRA Implementation Guidance offers greater clarity for the open source community. Turning that clarity into practical compliance is where organisations now need support. That's where ORC continues to help, through guidance and practical resources. 🔗 Read more: orcwg.org/blog/ec-cra-...
000
Open Regulatory Compliance @orcwg.org · 03/09/2026
Does your Software-as-a-Service (#SaaS) product fall under the scope of the #CyberResilienceAct? 🔎 Clarify your SaaS compliance boundaries: cra.orcwg.org/faq/remote-p...
000
Open Regulatory Compliance @orcwg.org · 02/09/2026
Regulatory challenges should not be solved in isolation. Meet us at #AutomotiveWorldJapan2026 and learn how we help organisations across the world prepare for evolving requirements. 📍 Where: Makuhari Messe, Japan 🗓️ When: 9 to 11 September 2026 Learn more: www.automotiveworld.jp/autumn/en-gb...
000
Open Regulatory Compliance @orcwg.org · 01/09/2026
How do the #NIS2 Directive and the #CyberResilienceAct interact? - NIS2: Focuses on organisational cyber-readiness. - CRA: Focuses on product-level security. Under NIS2, critical entities must secure their digital supply chains, prioritising CRA-compliant products. 🌐 cra.orcwg.org/faq/official/
110
Open Regulatory Compliance @orcwg.org · 31/08/2026
In “ORC’s impact in the first half of 2026,” Juan Rico reviews key milestones from 2026, including new #CRA guidance, #DueDiligence implementation, the ORC Learning Hub, and more. 📰 Read the full article for updates, highlights, and resources: orcwg.org/blog/h1-2026...
000
Open Regulatory Compliance @orcwg.org · 28/08/2026
Who is responsible when commercial products use open source software? According to the European Commission’s final CRA Implementation Guidance, commercial organisations integrating open source into their products remain responsible for CRA compliance. 🔗 Read more: orcwg.org/blog/ec-cra-...
orcwg.org
The European Commission Publishes CRA Implementation Guidelines. Key Takeaways for Open Source | Open Regulatory Compliance Working Group
The open source community is collaborating to establish common specifications for secure software development based on open source best practices.
000
Open Regulatory Compliance @orcwg.org · 27/08/2026
The #CRA makes manufacturers responsible for every component integrated into their products, including #OpenSource software. When carrying out the required due diligence, they risk contributing to a denial-of-service attack on the maintainers. Learn more: orcwg.org/blog/due-diligence-dos-attack/
010
Open Regulatory Compliance @orcwg.org · 26/08/2026
Software supply chain readiness matters under the Cyber Resilience Act (CRA). Learn about Software Bills of Materials (SBOMs), vulnerability management, and due diligence on the new ORC Learning Hub. Access the free training today: orcwg.org/training/
000
Open Regulatory Compliance @orcwg.org · 25/08/2026
The #CyberResilienceAct is introducing new expectations for digital products — (in)directly affecting all software on the European market. One possible solution to navigate these requirements is to use “Voluntary Security Attestations.” 📊 Read more: orcwg.org/blog/voluntary-attestations-survey/
000
Open Regulatory Compliance @orcwg.org · 22/08/2026
In his article “ORC’s impact in the first half of 2026,” Juan Rico looks back on everything the ORC Working Group has accomplished this year and outlines upcoming initiatives. Read the full article now – orcwg.org/blog/h1-2026... 💻 Access free courses on #CRA compliance – orcwg.org/training/
ORC's impact in the first half of 2026 by Juan Rico text on dark teal background with red spots. Red read now button. New article text in red star in upper right corner.
000
Open Regulatory Compliance @orcwg.org · 21/08/2026
In the world of CRA compliance, if your security procedures aren't thoroughly documented, they don't count. Risk assessments, records of vulnerability testing, and more... 📚 Learn what a complete technical file must include: cra.orcwg.org/faq/attestat...
000
Open Regulatory Compliance @orcwg.org · 19/08/2026
How do you legally prove your software is “secure enough” for European regulators? The answer is "harmonised standards," built by organisations like CEN and CENELEC. Upon meeting them, products are granted “presumption of conformity.” 🌐 Access harmonised standards: cra.orcwg.org/faq/standards/
000
Open Regulatory Compliance @orcwg.org · 17/08/2026
What responsibilities do Open Source Software Stewards have under the CRA? The final implementation guidance by the European Commission clarifies that obligations depend on the steward's role. Our blog breaks down what these distinctions mean in practice: orcwg.org/blog/ec-cra-...
000
Open Regulatory Compliance @orcwg.org · 14/08/2026
Are you prepared for the #CyberResilienceAct? The ORC Working Group has created a free, online course in CRA fundamentals, designed specifically for the #OpenSourceCommunity. 🎓 Take the course: orcwg.org/training/
000
Open Regulatory Compliance @orcwg.org · 13/08/2026
Good news for open source contributors. One of the most important clarifications in the Cyber Resilience Act Implementation Guidance? Merely submitting code or patches to an open source project does not trigger obligations under the CRA. 🧵 (1/2)
100
Open Regulatory Compliance @orcwg.org · 12/08/2026
The Cyber Resilience Act (CRA) is becoming an operational reality. On 11 September 2026, reporting requirements take effect. By 11 December 2027, remaining CRA obligations become fully applicable. That's why you need the new ORC Learning Hub. Access the free training now: orcwg.org/training/
000
Open Regulatory Compliance @orcwg.org · 11/08/2026
⚠️ One month until the #CyberResilienceAct’s first major deadline! Vulnerability reporting requirements kick in on 11 September 2026. ⏱️ If you haven’t started, this is your last chance to act: orcwg.org/cra #CRA #ORCWG
000
Open Regulatory Compliance @orcwg.org · 07/08/2026
Not all software faces the same compliance pathway under the #CyberResilienceAct. Products are separated into three primary categories: 📦Default Products 🔐Important Products (Class A & B) ⚡Critical Products Map your software to the correct risk tier using our guide: cra.orcwg.org/faq/importan...
000
Open Regulatory Compliance @orcwg.org · 06/08/2026
📅 On 11 September 2026, mandatory Cyber Resilience Act (CRA) reporting requirements take effect. The new ORC Learning Hub helps developers, maintainers, manufacturers, security professionals, and compliance practitioners prepare. Start preparing now: orcwg.org/training/
010
Open Regulatory Compliance @orcwg.org · 05/08/2026
Get a sneak peek 👀 of our CRA training course for manufacturers on our YouTube channel. 📺 “Security Management for Manufacturers | ORC Learning Hub” 💭 Do you know your responsibilities as a manufacturer under the Cyber Resilience Act? 🔔 Don’t forget to subscribe: youtu.be/KLSGEPiHY24?...
000
Open Regulatory Compliance @orcwg.org · 04/08/2026
The European Commission has published the final #CRA Implementation Guidance, providing clarification for the #OpenSource ecosystem. In this blog, we break down key takeaways and explain what they mean for organisations preparing for CRA compliance. 🔗 Read the full blog: orcwg.org/blog/ec-cra-...
020
Open Regulatory Compliance @orcwg.org · 03/08/2026
Failure to comply with the #CyberResilienceAct risks fines up to €15 million or 2.5% of global annual turnover, plus immediate removal from retail and digital shelves. 📜 Understand the legal mechanics of non-compliance and protect your firm: cra.orcwg.org/faq/official/
000
Open Regulatory Compliance @orcwg.org · 31/07/2026
⚠️ Under the #CRA, integrating a broken or insecure third-party component into your software counts as a compliance failure for your company. 🌐 Read the community guidelines for executing #SoftwareDueDiligence: cra.orcwg.org/faq/due-dili... #SecOps
000
Open Regulatory Compliance @orcwg.org · 30/07/2026
We are pleased to announce the launch of the Open Regulatory Compliance YouTube channel! 🔔 Subscribe to stay up-to-date with webinars, courses, and regulatory compliance content. ▶️ Now playing: “Security Management for Manufacturers | ORC Learning Hub” Watch now: youtu.be/KLSGEPiHY24?...
021
Open Regulatory Compliance @orcwg.org · 29/07/2026
The hardest part of the Cyber Resilience Act (CRA) isn't reading the regulation, it's knowing where to begin. Explore the new ORC Learning Hub with courses for developers, manufacturers, maintainers, contributors, and security professionals. Start learning for free now: orcwg.org/training/
000
Open Regulatory Compliance @orcwg.org · 28/07/2026
Under the #CRA, the “Conformité Européenne” (#CEmark) will be required on digital products with software elements before they can be legally made available on the European market. Prepare your software for CE compliance: cra.orcwg.org/faq/official/faq_6-8/
000
Open Regulatory Compliance @orcwg.org · 23/07/2026
Beginning September 2026, a vulnerability in your commercial software won’t be just an internal issue — it will trigger a regulatory countdown under the #CRA. Building these response networks requires months of preparation. Start now. Review the expectations: cra.orcwg.org/faq/official/reporting/
000
Open Regulatory Compliance @orcwg.org · 22/07/2026
This team analysed over 350 organisations and 3,600 repositories within #EclipseFdn projects to learn whether their #CyberResilienceAct compliance solution could be applied to a large #OpenSource organisation. 📺 Watch the full session on our new YouTube channel: youtu.be/KN3dKD38S9U?...
010
Open Regulatory Compliance @orcwg.org · 21/07/2026
☁️ Are cloud-based products within the scope of the #CyberResilienceAct? In short, yes. The CRA explicitly covers Remote Data Processing Solutions (#RDPS) that are integrated into a product with digital elements or support its direct operation. Learn more: cra.orcwg.org/faq/remote-p...
010
Open Regulatory Compliance @orcwg.org · 20/07/2026
The new ORC Learning Hub helps turn Cyber Resilience Act (CRA) requirements into practical action. Learn about: • Security by design • Vulnerability management • SBOMs • Software supply chain responsibilities Start preparing now: orcwg.org/training/
000
Open Regulatory Compliance @orcwg.org · 17/07/2026
Not all #OpenSource projects are built the same way, and the #CRA knows it. Understand your classification to implement smart governance: 🔹 Independent Community Projects 🔹 Steward-Supported Projects 🔹 Commercial open source products (COSS) Evaluate your project: cra.orcwg.org/faq/projects/
010
Open Regulatory Compliance @orcwg.org · 16/07/2026
This #CRAMondays session features key findings from an analysis of #OpenSource projects across technology ecosystems and compares ORT Server results with GitHub advisory data, showcasing differences in coverage and vulnerability detection. 📺 Watch the full clip on YouTube: youtu.be/KN3dKD38S9U?...
011
Open Regulatory Compliance @orcwg.org · 15/07/2026
How can an "intent to monetise" drag #OpenSource projects into CRA compliance? ✅ Intent: Providing a software product for a fee or paid support. ❌ No intent: Charging for educational material, or accepting non-binding philanthropic donations. Learn more: cra.orcwg.org/faq/cra-itse...
010
Open Regulatory Compliance @orcwg.org · 09/07/2026
Our latest white paper breaks down the new “Stewards” legal tier introduced in the #CyberResilienceAct and the expectations that accompany it. If you are at all involved with #OpenSource projects, this knowledge will be crucial. 📝 Learn more in our white paper: hubs.la/Q040T4mT0
010
Reposted by Open Regulatory Compliance
FreeBSD Foundation @freebsdfoundation.bsky.social · 07/07/2026
New free CRA training is now available from the Open Regulatory Compliance (ORC) Working Group. Start learning:  orcwg.org/training/ Learn more about the Foundation's CRA Readiness Project:  buff.ly/bfp8xkQ #FreeBSD #OpenSource #CyberResilienceAct #CRA #SoftwareSecurity
051
Open Regulatory Compliance @orcwg.org · 07/07/2026
Will individual open source maintainers be penalised under the #CRA? ➡️ Those who simply contribute code to #OpenSource or maintain a project without monetisation are not in scope. ➡️ However, the indirect impact involves a rising industry standard. Learn more: cra.orcwg.org/faq/maintain...
010
Open Regulatory Compliance @orcwg.org · 07/07/2026
Not everyone experiences the CRA the same way. That's why we built the new ORC Learning Hub to start with your role, not the regulation. Start with our free courses providing an introduction to the Cyber Resilience Act (CRA) for open source communities and manufacturers: orcwg.org/training/
000
Open Regulatory Compliance @orcwg.org · 06/07/2026
The EU Cyber Resilience Act (CRA) is changing software development and distribution. 📅 Mandatory reporting starts 11 September 2026, now is the time to prepare. Get up to speed with free, practical training from the new ORC Learning Hub: orcwg.org/training/ #CyberResilienceAct #OpenSource
046
Open Regulatory Compliance @orcwg.org · 02/07/2026
🔍 Did you know the #CyberResilienceAct created a dedicated legal tier for #OpenSource Software Stewards? If your foundation or organisation acts as a digital hub, check out the tailored open source Steward FAQs to learn more: cra.orcwg.org/faq/stewards/
100
Open Regulatory Compliance @orcwg.org · 29/06/2026
If you build software outside of Europe but sell to European clients, you are a "Manufacturer" under the #CyberResilienceAct. 🚩 Read the specific breakdown of manufacturer obligations: cra.orcwg.org/faq/manufact... #SoftwareDevelopment
020
Open Regulatory Compliance @orcwg.org · 25/06/2026
Key dates for the EU #CyberResilienceAct are fast approaching. - 11 September 2026: Mandatory actively exploited vulnerability and incident reporting rules take effect. - 11 December 2027: Remaining CRA obligations become fully applicable. ⏰ Don't miss vital deadlines: cra.orcwg.org/faq/official/
000
Open Regulatory Compliance @orcwg.org · 23/06/2026
📦 Up to 76% of modern commercial software applications contain #OpenSource dependencies. What does this mean for commercial organisations? Check out the specialised breakdown on open source supply chains: cra.orcwg.org/faq/projects/
020
Open Regulatory Compliance @orcwg.org · 19/06/2026
The #CyberResilienceAct affects all organisations who develop, distribute, and/or sell software in the European market. It addresses #cybersecurity across products and a lack of information available to users regarding security postures. Visit the #ORC FAQs for community guidance: cra.orcwg.org
000
Open Regulatory Compliance @orcwg.org · 17/06/2026
Know you need to be CRA compliant but don’t know where to start? The ORC Working Group is on a mission to raise awareness around the #CyberResilienceAct (CRA) and showcase how these regulations will affect both closed and #OpenSource organisations. 🧰 Explore resources: orcwg.org/cra/resources/
010