THE LINUX FOUNDATION PROJECTS

This page defines the organization’s compliance program for the EU Cyber Resilience Act (CRA), structured in alignment with the OpenChain Project’s adoption framework and ISO/IEC 18974 (Open Source Security Assurance). It serves as both a policy framework and a self-certification checklist.

The CRA (Regulation (EU) 2024/2847) establishes mandatory cybersecurity requirements for products with digital elements placed on the EU market. Organizations that develop, maintain, or distribute software with digital elements must ensure their products meet essential cybersecurity requirements throughout the product lifecycle.

For details, see here. (UNDER CONSTRUCTION)