Skip to main content

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] [List Home]
[open-regulatory-compliance] Minutes from the Cyber Resilience SIG meeting on 2026-08-31

Dear all,

find here the link to the PR with the minutes of our meeting today. I think I have included pointers to all the different topics addressed, but if you feel something is missing, please add them or ping me to do it.

To everyone, the main topics covered today were:
Here is a summary of the meeting:
  • Due Diligence Progress: The group has moved from a blank page to active contributions and pull requests, with ongoing debates concerning the scope of guidance, non-technical factors, and contractual due diligence.
  • Reporting Platform Coordination: With reporting obligations starting September 11, the group will gather feedback on the Single Reporting Platform (SRTP) and coordinate responses to ENISA.
  • OpenChain Collaboration: The group is evaluating potential cooperation with the OpenChain initiative regarding their CRA compliance checklist, aiming to align requirements and best practices.
  • Code and Compliance Event: The upcoming fall edition of the Code and Compliance event will focus on engaging industries new to open source, featuring thematic blocks on institutional, CRA, AI, and industry topics.
  • Upcoming Conferences: Key upcoming events include the Nordic Software Security Summit in Stockholm (November 4–6, 2026) and FOSDEM in Brussels (January 30–31, 2027), which will include a community-focused Code & Compliance edition on January 28.
Cheers,
Juan
--
Juan Rico
Senior Manager ORC, Oniro and Cloud Programs | Eclipse Foundation Europe GmbH | X | LinkedIn | YouTube | Instagram | Bluesky | Mastodon

Eclipse Foundation: The Community for Open Collaboration and Innovation



Berliner Allee 47, 64295 Darmstadt

Handelsregister: Darmstadt HRB 92821

Managing Directors: Gaël Blondelle, Mike Milinkovich, Michael Plagge


Back to the top