Dear Committers,
Today, 11 September 2026, marks the first major milestone of the EU Cyber Resilience Act (CRA): the first obligations under the regulation now apply.
What applies today
The obligations entering into force today are the Reporting Obligations, and they apply to manufacturers only. From today, manufacturers of products with digital elements must report security-related events of the following nature:
All official submissions must be routed through the designated European platform, ENISA's Single Reporting Platform (SRP) https://portal.cra-srp.enisa.europa.eu/ (not yet available at the time this email is sent).
1. What it means for you as a committer
In short: nothing changes for you today. As an open source committer contributing to an Eclipse Foundation project, you have no new obligations under the CRA, neither today nor at a later stage. The CRA deliberately does not impose obligations on individual open source contributors, and you should continue to handle security issues in your project exactly as you do now.
Where it may touch you indirectly is through your employer. If your company integrates Eclipse Foundation projects (or any other software) into products it places on the EU market, then your company is a manufacturer under the CRA and its reporting obligations started today, for the whole product, including the open source components it ships. You may therefore see increased interest from your company's product security or compliance teams in the security practices of the projects you contribute to. That is expected, and the resources below can help you answer their questions.
2. What it means for the Eclipse Foundation
The CRA introduced a new role that most of you will not have come across before: the open source software steward. A steward is a legal entity, other than a manufacturer, that provides sustained support for the development of open source software intended for commercial use, typically a foundation like ours. The Eclipse Foundation is the open source software steward of every Eclipse Foundation Projects under the CRA.
Stewards have a lighter set of obligations than manufacturers, centred on having a cybersecurity policy for the projects they host and on reporting the same two types of security events described above. Importantly, the European Commission clarified in its CRA FAQ update of 4 September that the reporting obligations applying today concern manufacturers only:
https://digital-strategy.ec.europa.eu/en/library/cyber-resilience-act-implementation-frequently-asked-questions
For open source software stewards, and therefore for the Eclipse Foundation, the reporting obligations will only apply as of 11 December 2027.
The Eclipse Foundation was ready to start fulfilling these obligations today. In light of the Commission's clarification, we will not begin formal reporting for now, and we will use the additional time to further refine our processes ahead of the December 2027 deadline. Nothing changes for committers today with respect to how you handle security vulnerabilities in your projects.
Want to know more?
Questions?
For questions about the CRA and what it means for your project, open a help desk ticket – this way answers benefit the whole community.
For questions about how the Eclipse Foundation is preparing for its steward obligations, or anything you would prefer not to raise publicly, write to emo@xxxxxxxxxxxxxxxxxxxxxx.
For any security vulnerability in an Eclipse Foundation project, continue to follow the existing process and report it to the Eclipse Foundation Security Team by opening a confidential issue.
Kind regards,