Skip to main content

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] [List Home]
[open-regulatory-compliance] Minutes from the Cyber Resilience SIG meeting on 2026-08-17

Dear all,

please find here the minutes of the meeting held today. If you have any comments, you can add them to the PR.

I wanted to share a summary of the key updates and discussion points for those who couldn’t attend:
  • CRA Guidance v1.0: The finalised guidance is now available. It provides essential clarity on compliance and governance, though we continue to have concerns regarding the lack of mandatory timelines for manufacturers to upstream fixes.
  • ENISA Reporting Platform: This platform goes live on September 11. Please note it currently supports manual reporting only, has account limitations (2 per organisation), and lacks a user guide. We will be actively collecting community feedback on this to share with ENISA.
  • CRA Expert Group: A new work stream focusing on SBOM reference architecture has been initiated, with the next meeting set for October 8th.
  • BSI Technical Guidance: We recommend this as key reading for members working on due diligence, noting that while it offers good risk assessment references, it lacks specific definitions for due diligence.
  • Code and Compliance Update: Registration for the October 27th edition in Brussels is open. ORC members can use code ORCMEMBER50 for a 50% discount.
  • Community Progress: Our training initiative continues to be successful, with over 225 completions for modules 1 and 2. We are currently planning a session to test module 3 on SBOMs.
Cheers,
Juan

--
Juan Rico
Senior Manager ORC, Oniro and Cloud Programs | Eclipse Foundation Europe GmbH | X | LinkedIn | YouTube | Instagram | Bluesky | Mastodon

Eclipse Foundation: The Community for Open Collaboration and Innovation



Berliner Allee 47, 64295 Darmstadt

Handelsregister: Darmstadt HRB 92821

Managing Directors: Gaël Blondelle, Mike Milinkovich, Michael Plagge


Back to the top