THE LINUX FOUNDATION PROJECTS

The Cyber Resilience Act’s main obligations apply from 11 December 2027, with reporting obligations already applying as of 11 September 2026.

This page defines the organization’s compliance program for the EU Cyber Resilience Act (CRA), structured in alignment with the OpenChain Project’s adoption framework and ISO/IEC 18974 (Open Source Security Assurance). It serves as both a policy framework and a self-certification checklist.

The CRA (Regulation (EU) 2024/2847) establishes mandatory cybersecurity requirements for products with digital elements placed on the EU market. Organizations that develop, maintain, or distribute software with digital elements must ensure their products meet essential cybersecurity requirements throughout the product lifecycle.

We’re excited to announce that the OpenChain CRA Requirement & Checklist is ready for review!

We warmly invite everyone in the community to review the document, provide comments, and contribute. Your input is crucial to ensuring this checklist is comprehensive and high-quality and release on time.

Contributions and feedback are welcome via pull requests and issues in GitHub. If you would like your name and company to be included in the final published document, please note your name and company in your comment. Your contributions are truly appreciated, and we look forward to recognizing them if you choose to share!