Key Concepts
- Cyber Resilience Act (CRA): EU legislation focused on protecting citizens from cybersecurity incidents.
- SBOM (Software Bill of Materials): A comprehensive list of ingredients or components that make up a software application.
- Open Source Steward: An entity (like a foundation) that supports open-source developers and projects, particularly with compliance and funding.
- Digital Sovereignty: A nation's ability to control its digital infrastructure and data.
- Secure by Design, Secure by Default: Principles emphasizing security considerations throughout the software development lifecycle.
- Open Source Project Security Baseline: A catalog of global compliance requirements and application security practices.
- Toil: Repetitive or manual tasks that can be automated.
The Cyber Resilience Act (CRA) and Its Impact on Open Source
The European Union's Cyber Resilience Act (CRA) aims to protect EU citizens from cybersecurity incidents by establishing cybersecurity requirements for products with digital elements. This law, going into effect October 11, 2026 (reporting obligations) and December 11, 2027 (full effect), places significant obligations on commercial enterprises that sell products within the EU. These obligations include reporting vulnerabilities, providing documentation, and adhering to secure development practices. Failure to comply can result in substantial fines, potentially reaching billions of euros.
- Example: A turbine company using open-source software in its turbine's operation must report the software components used.
- Dependency Issue: The average open-source project has around 160 dependencies, making it challenging to track and manage all components.
- Burden on Manufacturers: The CRA places the burden of compliance on manufacturers, not the upstream open-source maintainers.
The Existential Crisis Facing Open Source
The CRA creates an "existential crisis" for the open-source community because it imposes demands on upstream developers who often lack the resources, understanding, or legal obligation to meet them.
- Daniel Felman's Keynote: Illustrated the pressure from downstream entities demanding SBOMs, conformity assessments, and other documentation.
- Upstream vs. Downstream: Upstream developers focus on solving problems and contributing to the community, while downstream commercial entities use open-source software to reduce costs and build products.
- Lack of Relationship: Upstream developers often have no direct relationship with downstream users and are unprepared for legal demands.
Responsibilities of Upstream Engineers
Upstream engineers typically handle tasks such as managing mailing lists, reviewing contributions, approving pull requests, writing blog posts, and occasionally adding new features. The CRA adds potential "toil" without legal obligation, as the law allows open-source projects to receive donations but not make a profit (a gray area).
- Limited Resources: Most upstream projects are maintained by single individuals or small teams, unlike large projects like the Linux kernel or Kubernetes.
- Threats and Demands: Downstream customers, facing large penalties, may threaten or demand documentation and support that upstream developers are not equipped to provide.
The Funding Gap and the Role of Open Source Stewards
A significant gap exists between the expectations of commercial entities and the realities of open-source development. Businesses often misperceive open-source projects as corporations with dedicated resources.
- Funding Challenges: Funding open-source developers is complex, especially when dealing with individuals who may not be able to accept funding directly.
- Open Source Steward Role: The CRA created the "open source steward" role to encourage industry and nonprofit foundations to support developers through funding, infrastructure, and other resources.
- Examples of Support: Providing cloud credits, helping write test harnesses, and offering support infrastructure.
- Tech Sovereign Agency: Germany's Tech Sovereign Agency and the EU's consideration of a similar fund represent efforts to address the funding gap.
- Existing Initiatives: GitHub Sponsors and projects like Alpha-Omega also contribute to funding and supporting open-source projects.
Digital Sovereignty and Open Standards
The rise of digital sovereignty, where nations seek to control their digital infrastructure, can impact open source. While promoting local development is beneficial, creating isolated "stacks" can hinder collaboration and innovation.
- Global Asset: Open source is a global asset that benefits from open standards, protocols, and models.
- Siloed Development: Creating separate stacks for different regions can lead to incompatible standards and duplicated effort.
- Open Standards Advocacy: Maintaining open standards allows for global collaboration while enabling regional customization.
Recommendations for Open Source Engineers
Christopher Robinson provides three recommendations for open-source engineers:
- Educate Yourself: Take the free 90-minute class on the CRA (developers only need to watch 5 minutes).
- Utilize the Open Source Project Security Baseline: Implement the common application security practices outlined in the baseline to meet downstream requirements.
- Consider Working with a Steward: Partner with a foundation to gain access to funding, resources, and community support.
- Benefits of Stewards: Stewards can provide funding, handle enterprise-type tasks, and offer a larger community for collaboration.
- Protecting Against Nagging: Following the baseline and working with a steward can shield developers from downstream demands.
Conclusion
The Cyber Resilience Act and similar regulations in other regions (China, India, Korea) represent significant changes for the open-source world. Addressing the funding gap, promoting open standards, and supporting open-source engineers through education and stewardship are crucial for ensuring the continued success and security of open-source software. The key is to bridge the communication gap between businesses and engineers, fostering a collaborative environment that benefits both the open-source community and the broader digital ecosystem.
AI summaries can miss context or contain errors. Check important details against the original video.





