Skip to main content

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] [List Home]
Re: [open-regulatory-compliance] Stewards cybersecurity policy, should it be a public document?

For your 2. question, I am mostly wondering what attaches to the choice once a steward is deciding per requester who gets the (full) policy. Selective disclosure to a party invited to rely on the document looks less like publication and more like a representation to a counterparty. That applies even with no money changing hands; monetization of CRA attestation is only the sharper case. So I wonder whether discrimination there opens a liability door that publishing from the start simply does not and one the CRA's steward protections may not reach, being a contract rather than CRA liability.

On Thu, Sep 3, 2026 at 4:00 PM Juan Rico via open-regulatory-compliance <open-regulatory-compliance@xxxxxxxxxxx> wrote:

Hi everyone,

Following up on a recent chat discussion, we are bringing a topic to the broader list regarding how Open Source Software Stewards plan to handle their Cyber Resilience Act (CRA) cybersecurity policies.

Core question - Are most stewards planning to publish their CRA cybersecurity policies publicly, or keep them internal until requested by a Market Surveillance Authority?

Key Perspectives & Insights

  • Regulatory Baseline: The CRA does not strictly require the entire cybersecurity policy to be public, only documented in a verifiable manner and available to an MSA upon reasoned request. However, community-facing elements (e.g., vulnerability disclosure procedures and reporting channels) must naturally be public.

  • Manufacturer Due Diligence: Publishing policies publicly could significantly streamline due diligence and risk assessments for downstream vendors embedding OSS components into commercial products.

  • Hybrid Approach: A practical middle ground discussed is keeping formal administrative policy internal while publicly documenting its practical execution (e.g., secure development practices, security support structures, and reporting protocols).

Resources

Discussion questions for the mailing list and the next meeting on Tuesday

  1. What approach is your organisation or project planning to take?

  2. Do you see public availability as essential for vendor trust, or does public documentation of security procedures suffice?

Looking forward to hearing your thoughts and experiences.

Juan

--
Juan Rico
Senior Manager ORC, Oniro and Cloud Programs | Eclipse Foundation Europe GmbH | X | LinkedIn | YouTube | Instagram | Bluesky | Mastodon

Eclipse Foundation: The Community for Open Collaboration and Innovation



Berliner Allee 47, 64295 Darmstadt

Handelsregister: Darmstadt HRB 92821

Managing Directors: Gaël Blondelle, Mike Milinkovich, Michael Plagge

_______________________________________________
open-regulatory-compliance mailing list
open-regulatory-compliance@xxxxxxxxxxx
To unsubscribe from this list, visit https://accounts.eclipse.org


--
regards,
Lukas

Back to the top