Open Regulatory Compliance's Avatar

Open Regulatory Compliance

@orcwg.org

Leading regulatory compliance for open source. Hosted by @eclipse.org

77
Followers
35
Following
136
Posts
06.02.2025
Joined
Posts Following

Latest posts by Open Regulatory Compliance @orcwg.org

Post image

The Open Regulatory Compliance Working Group will be at Embedded World 2026!

🌐 Visit the #EclipseFdn booth 4-554 in hall 4 to dive deeper into how #ORCWG is driving meaningful change in the world of open source compliance.

#embeddedworld #ew26 #CRA

11.02.2026 22:21 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
The European Union's Cyber Resilience Act | Open Regulatory Compliance Working Group Learn how the EU Cyber Resilience Act (CRA) impacts open source software development. Understand key compliance requirements and what the CRA means for your …

Did you know? According to ONEKEY:
πŸ™οΈ 37% of companies see the 24-hour reporting rule as their number 1 challenge.
🌐 29% say creating a Software Bill of Materials (SBOM) is the hardest requirement.

Get started with the #CyberResilienceAct today: orcwg.org/cra/

11.01.2026 09:51 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

🎊 Happy New Year from the Open Regulatory Compliance!

2025 was a year of learning, sharing, and steady progress for the Open Regulatory Compliance community.

πŸ‘ Thank you to everyone who participated, shared insights, and helped make these conversations clearer and more constructive.

01.01.2026 10:46 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
The CRA’s Global Impact: Why Manufacturers Hold the Key | Open Regulatory Compliance Working Group The open source community is collaborating to establish common specifications for secure software development based on open source best practices.

πŸ“£ β€œThe weight of compliance falls primarily on manufacturers, not on the open source community.”

Adrian O’Sullivan explains what this means in practice and how the ORC Working Group supports shared understanding across the ecosystem.

Read the article to learn more: orcwg.org/blog/manufac...

16.12.2025 12:23 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
The European Union's Cyber Resilience Act | Open Regulatory Compliance Working Group Learn how the EU Cyber Resilience Act (CRA) impacts open source software development. Understand key compliance requirements and what the CRA means for your …

9 months left to get ahead!

πŸ“‰ The #CyberResilience demands security by design across all digital products. But 27% of companies haven’t even started engaging with CRA requirements (ONEKEY).

πŸ”— Start today! orcwg.org/cra

11.12.2025 10:41 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

In this ORC article, Adrian O’Sullivan, Huawei, shares why the Cyber Resilience Act’s (CRA) impact is global for manufacturers and how early community engagement helped strengthen the regulation.

Learn more: orcwg.org/blog/manufac...

05.12.2025 11:17 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

πŸ“£ Registration is now open for Code & Compliance 2026!

Join us on 29 January in Brussels, ahead of FOSDEM, for the next edition of Code & Compliance.

Be part of the conversations advancing open source governance, policy, and practical security solutions.

Register now: hubs.la/Q03WGtF40

04.12.2025 11:09 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

πŸ“£ The FOSDEM 2026 Freedom, Sovereignty & Regulation Devroom is accepting proposals! Share your perspective on how regulation shapes digital freedom and open ecosystems.

CfP details ➜ softwarefreedom.net/fosdem-2026-...
⏰ Deadline: 1 December

#FOSDEM #FOSDEM2026

28.11.2025 12:15 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

πŸ” OC for Compliance at #OCX26 will bring together developers, maintainers, and legal experts to share approaches bridging the gap between legislation and implementation.

πŸ‘‰ If you want to stay ahead of evolving regulations, #OCX26 is the place for you.

πŸ“† Register! www.ocxconf.org/event/2026/r...

27.11.2025 08:18 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Help shape how the #CRA impacts open source. Not sure where to start? Begin with our Deliverables Plan. In a new blog and video, we explain what’s included, how to read the status indicators, and how to contribute.

πŸŽ₯ www.youtube.com/watch?v=QamK...
πŸ“ orcwg.org/blog/how-to-...

26.11.2025 10:11 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

⏰ Final call! Our ORC has received some amazing name suggestions, but there’s still time to share yours!

We’re collecting ideas until 28 November, so if you haven’t joined in yet, now’s your chance.

πŸ’š Help us give our ORC the perfect name to represent the Open Regulatory Compliance community.

25.11.2025 08:47 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

⏰ The call for proposals at Code & Compliance 2026 closes tomorrow!
Share your expertise and experiences with a highly engaged audience in Brussels.

πŸ”— Submit your talk now: www-eur.cvent.com/c/abstracts/...

#CodeCompliance #CFP #CRA #opensource

24.11.2025 11:38 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

πŸ‘‹ Join our speaker lineup for Code & Compliance 2026!

Following the success of our Code & Compliance Community Day, we’re building the next event to go even deeper into #CRA implementation and open source compliance.

πŸ“ Brussels
πŸ”— Submit your talk by 25 November: www-eur.cvent.com/c/abstracts/...

19.11.2025 21:37 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

πŸ” OC for Compliance at #OCX26 will bring together developers, maintainers, and legal experts to share practical approaches bridging the gap between legislation and implementation.

πŸ“† Lock in your #OCX26 ticket before prices go up! www.ocxconf.org/event/403bff...

18.11.2025 22:04 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

πŸ“’ Present at Code & Compliance 2026!

We’re looking for panels, presentations, roundtables, or workshops on topics such as tooling, attestations, stewardship, standardisation, or policy.

πŸ‘‰ Submit your talk before 25 November: www-eur.cvent.com/c/abstracts/...

14.11.2025 11:35 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

New project!

πŸ” The objective of the Cyber Resilience Attestations project is to propose a means to support the due diligence responsibilities of manufacturers who rely on F/OSS components.

Learn more: projects.eclipse.org/projects/tec...

13.11.2025 08:34 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

The countdown is on!

Manufacturers have less than a year to comply with the #CyberResilienceAct’s vulnerability reporting requirements.

πŸ“˜ Explore our resources to help your team prepare: orcwg.org/cra/
#CRA #CyberResilience #ORCWG

11.11.2025 09:45 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

What is an #opensource software steward?

🌐 Open source software steward is a term defined in Article 3(14) of the CRA. However, the discussion on this topic is ongoing.

Check our ongoing #CRAFAQ discussion on GitHub and share your thoughts and contributions!
github.com/orcwg/cra-hu...

10.11.2025 09:01 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

πŸ’» Open source AI in automotive: legal & compliance implications
Join us on 6 November 2025 at 3 PM CET for a practical briefing with Dr. Lina BΓΆcker.

πŸ‘‰ Register now: www.crowdcast.io/c/ocx-day4-c...

30.10.2025 09:12 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

πŸ€” Can a solo maintainer be considered to be an #opensource software steward? What do you think?

Share your feedback on our CRA FAQ document: github.com/orcwg/cra-hu...

29.10.2025 10:12 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

βœ… Compliance isn’t about ticking boxes; it’s about building trust in open source.

At #OCX26, the Open Community for Compliance invites proposals on regulatory requirements, the CRA, certification, and standardisation.

Send your proposal before 13 November! www.ocxconf.org/event/403bff...

28.10.2025 11:34 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
cra-hub/faq/maintainers/transparency.md at main Β· orcwg/cra-hub Everything you ever wanted to know about the CRA and its implementation - orcwg/cra-hub

I am NOT subject to the CRA, and want to make this clear to downstream users. What should I say?

Help answer this question in our CRA FAQ document.

Contribute to the discussion πŸ‘‡
github.com/orcwg/cra-hu...

23.10.2025 09:02 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Francisco Carneiro will introduce the @eclipse.org Open Regulatory Compliance WG at #SFSCON in Bolzano.

Join his session on 7 November to explore how the working group brings together key stakeholders to co-develop reusable tools.

Don’t miss it πŸ‘‰ pretix.eu/noi-digital/...

21.10.2025 10:04 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
cra-hub/faq.md at main Β· orcwg/cra-hub Everything you ever wanted to know about the CRA and its implementation - orcwg/cra-hub

πŸ“’ Contribute to the FAQ on the Cyber Resilience Act (#CRA) and have an impact!

Some questions around open source projects, maintainers, stewards, or CRA standards are still being discussed. We need your input.

πŸ‘‰ Check out the CRA FAQ and share your feedback with us! github.com/orcwg/cra-hu...

17.10.2025 09:14 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
How to Contribute to ORC Deliverables
How to Contribute to ORC Deliverables Want to shape how the Cyber Resilience Act (CRA) impacts the open source ecosystem? This video walks you through the ORC’s Cyber Resilience SIG deliverables plan and explains how you can see which…

Discover the ORC’s Cyber Resilience SIG deliverables plan:

βœ… Navigate the deliverables plan and see CRA-related projects
βœ… Understand the scope of each deliverable
βœ… Find ways to get involved and contribute

πŸŽ₯ Watch video: www.youtube.com/watch?v=QamK...
πŸ“ Read the blog: orcwg.org/blog/how-to-...

16.10.2025 08:41 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

🎀 It’s #CRA time at The Things Conference!

@j-rico.bsky.social, Senior Program Manager @orcwg.org at @eclipse.org is on stage in Amsterdam delivering the keynote β€œWill the CRA Break Open Source in #IoT, or Make It Stronger?”

#EclipseFdn #opensource #CyberResilienceAct

24.09.2025 10:35 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Why attend the Code & Compliance Community Day?

1️⃣ Deepen your understanding of the #CRA
2️⃣ Be part of the discussions shaping CRA compliance
3️⃣ Attend the OpenForum Europe's roundtable β€œSolving the Standardisation Dilemma”
orcwg.org/blog/code-co...

www.eclipse-foundation.events/event/Code-a...

08.09.2025 07:21 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

πŸ” Are you interested in the #CRA? September is packed with events!

1️⃣ Comply.Land – Malta, 11-12 September
2️⃣ Bitkom Open Source Forum – Erfurt, 18 September
3️⃣ The Things Conference – Amsterdam, 23–24 September

πŸ‘‹ Connect with Juan Rico, from the ORC, at Bitkom & The Things Conference.

05.09.2025 08:01 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

With more than 600 videos relevant to the #Java community, #JakartaEE's YouTube channel has something for everyone.

Check it out and be sure to subscribe.
www.youtube.com/channel/UC4M...

04.09.2025 09:34 πŸ‘ 2 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0
Post image

πŸ” Why attend Comply.Land 2025? Because regulatory frameworks are shaping the future of technology, and this is your chance to be part of the conversation.

The #ORC community will be there, sharing our work on aligning open source practices with evolving compliance requirements.

πŸ‘‰ hubs.la/Q03FqKSK0

01.09.2025 14:38 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0