Shanda,
I did a presentation to help US Companies prepare for the EU CRA; happy to help. Here is the video presentation and a link to the slide deck used; Vicky Risk, an ORCWG colleague, was also a valuable contributor to this presentation:
https://www.youtube.com/watch?v=IGnE7I7dyDY
https://github.com/rjb4standards/CISASAGReader/raw/refs/heads/main/2025-0417-OWASP-AMHERST-EUCRA-OVERVIEW.pptx
Some “speculative examples of artifacts for EU CRA conformance” are also provided (very speculative based on EU CRA requirements specified in Annex I)
https://github.com/rjb4standards/CISASAGReader/blob/main/README.md
Could this group of artifacts provided with the CISASAGReader open-source product (see table below) also serve as a model for what Open Source Stewards should provide to satisfy EU-CRA expectations for transparency and Secure by Design/Default?
https://github.com/rjb4standards/CISASAGReader/blob/main/README.md#how-long-did-it-take-to-produce-the-cisasagreader-sbom-vdr-vrf-and-cisa-software-acquistion-guide-spreadsheet-attestation-artifacts
Thanks,
Dick Brooks

Active Member of the CISA Critical Manufacturing Sector,
Sector Coordinating Council – A Public-Private Partnership
Never trust software, always verify and report! ™
Risk always exists, but trust must be earned and awarded.™
https://businesscyberguardian.com/
Email: dick@xxxxxxxxxxxxxxxxxxxxxxxxx
Tel: +1 978-696-1788
From: open-regulatory-compliance <open-regulatory-compliance-bounces@xxxxxxxxxxx> On Behalf Of Shanda Giacomoni via open-regulatory-compliance
Sent: Wednesday, April 23, 2025 12:01 PM
To: open-regulatory-compliance@xxxxxxxxxxx
Cc: Shanda Giacomoni <shanda.giacomoni@xxxxxxxxxxxxxxxxxxxxxx>
Subject: [open-regulatory-compliance] Join our first Outreach & Engagement Community Call on 30 April
We’re excited to invite you to the first Outreach & Engagement Community Call taking place on 30 April. This new series is an opportunity for the community to connect, exchange ideas, and collaborate on initiatives that help grow awareness and participation across the ecosystem.
📅 Date: 30 April 2025
🕒 Time: 4 PM CET / 10 AM ET
📍 Meeting Link
During this first call, we’ll review the 2025 marketing plan and introduce the initial content initiatives that community members can get involved in. Whether you’re interested in contributing ideas, helping with content, or supporting broader engagement goals, your participation is welcome and appreciated.
We look forward to working together to strengthen ORC’s outreach and impact.