Favorite Summer is normally quiet in Brussels, but this year might just be the exception: over the last month, the EU has passed two milestones in implementing its Cyber Resilience (CRA) and AI acts. The OSI has been engaged with European policymakers over the past two years to ensure those laws don’t inadvertently harm Open…
All posts tagged cra
Open Source at the Heart of Europe’s (and the World’s) Digital Future
Favorite Every year, FOSDEM – the Free and Open Source Developers’ European Meeting – turns Brussels into a global meeting point for the Free and Open Source software community. In 2026, that energy extended well beyond the university halls, as policymakers, foundations, developers, and civil society gathered to confront a shared reality: Open Source is…
Help us improve the EU Cyber Resilience Act Standards!
Favorite As the deadline for the application of the CRA draws closer, thanks to the efforts of the OSI and other organisations, for the first time, the Open Source community will have the opportunity to directly participate in the standardisation process, shaping the standards that will apply to many crucial types of software. Over the…
State of the Source at ATO 2025: Cybersecurity
Favorite In October, the OSI hosted the State of the Source Track at All Things Open designed to connect developers with the big policy conversations shaping our ecosystem. Katie Steen-James, Jeremy Stanley, Barry Peddycord III, and Bob Callaway led the panel Policy: Cybersecurity, with updates on SBOMs, the Cyber Resilience Act, and what developers need…
Investing in Open Source sustainability: OSI supports Open Forum Europe’s EU Sovereign Tech Fund proposal
Favorite As the European Union (EU) prepares its budget for the coming years, the Open Source Initiative (OSI) has endorsed a proposal by Open Source think tank “Open Forum Europe” to create an EU Sovereign Tech Fund. The fund, modeled on the German Sovereign Tech fund, would support maintenance and development of key Open Source…
OSI at the Open Source Founders Summit: supporting entrepreneurs to build a business with Open Source
Favorite Open Source Founders Summit (#05F525), held May 19–20 in Paris, brought together a vibrant community of Open Source entrepreneurs, builders, and advocates for two days of deep, engaging conversations about what it takes to create sustainable, successful Open Source companies. As part of the action, the Open Source Initiative (OSI) was proud to sponsor…
Standards and the presumption of conformity
Favorite If you have been following the progress of the Cyber Resilience Act (CRA), you may have been intrigued to hear that the next step following publication of the Act as law in the Official Journal is the issue of a European Standards Request (ESR) to the three official European Standards Bodies (ESBs). What is…
Improving Open Source security with the new GitHub Secure Open Source Fund
Favorite The Open Source community underpins much of today’s software innovation, but with this power comes responsibility. Security vulnerabilities, unclear licensing, and a lack of transparency in software components pose significant risks to software supply chains. Recognizing this challenge, GitHub recently announced the GitHub Secure Open Source Fund—a transformative initiative aimed at bolstering the security…
CRA standards request draft published
Favorite The European Commission recently published a public draft of the standards request associated with the Cyber Resilience Act (CRA). Anyone who wants to comment on it has until May 16, after which comments will be considered and a final request to the European Standards Organizations (ESOs) will be issued. This process is all governed…
Openly Shared
Favorite The definition of “open source” in the most recent version (article 2(48)) of the Cyber Resilience Act (CRA) goes beyond the Open Source Definition (OSD) managed by OSI. It says: “Free and open-source software is understood as software the source code of which is openly shared and the license of which provides for all…
