Hi everyone,
Following up on a recent chat discussion, we are bringing a topic to the broader list regarding how Open Source Software Stewards plan to handle their Cyber Resilience Act (CRA) cybersecurity policies.
Core question - Are most stewards planning to publish their CRA cybersecurity policies publicly, or keep them internal until requested by a Market Surveillance Authority?
Key Perspectives & Insights
Regulatory Baseline: The CRA does not strictly require the entire cybersecurity policy to be public, only documented in a verifiable manner and available to an MSA upon reasoned request. However, community-facing elements (e.g., vulnerability disclosure procedures and reporting channels) must naturally be public.
Manufacturer Due Diligence: Publishing policies publicly could significantly streamline due diligence and risk assessments for downstream vendors embedding OSS components into commercial products.
Hybrid Approach: A practical middle ground discussed is keeping formal administrative policy internal while publicly documenting its practical execution (e.g., secure development practices, security support structures, and reporting protocols).
Resources
Discussion questions for the mailing list and the next meeting on Tuesday
What approach is your organisation or project planning to take?
Do you see public availability as essential for vendor trust, or does public documentation of security procedures suffice?
Looking forward to hearing your thoughts and experiences.
Juan