Skip to main content

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] [List Home]
[open-regulatory-compliance] Stewards cybersecurity policy, should it be a public document?

Hi everyone,

Following up on a recent chat discussion, we are bringing a topic to the broader list regarding how Open Source Software Stewards plan to handle their Cyber Resilience Act (CRA) cybersecurity policies.

Core question - Are most stewards planning to publish their CRA cybersecurity policies publicly, or keep them internal until requested by a Market Surveillance Authority?

Key Perspectives & Insights

  • Regulatory Baseline: The CRA does not strictly require the entire cybersecurity policy to be public, only documented in a verifiable manner and available to an MSA upon reasoned request. However, community-facing elements (e.g., vulnerability disclosure procedures and reporting channels) must naturally be public.

  • Manufacturer Due Diligence: Publishing policies publicly could significantly streamline due diligence and risk assessments for downstream vendors embedding OSS components into commercial products.

  • Hybrid Approach: A practical middle ground discussed is keeping formal administrative policy internal while publicly documenting its practical execution (e.g., secure development practices, security support structures, and reporting protocols).

Resources

Discussion questions for the mailing list and the next meeting on Tuesday

  1. What approach is your organisation or project planning to take?

  2. Do you see public availability as essential for vendor trust, or does public documentation of security procedures suffice?

Looking forward to hearing your thoughts and experiences.

Juan

--
Juan Rico
Senior Manager ORC, Oniro and Cloud Programs | Eclipse Foundation Europe GmbH | X | LinkedIn | YouTube | Instagram | Bluesky | Mastodon

Eclipse Foundation: The Community for Open Collaboration and Innovation



Berliner Allee 47, 64295 Darmstadt

Handelsregister: Darmstadt HRB 92821

Managing Directors: Gaël Blondelle, Mike Milinkovich, Michael Plagge


Back to the top