THE LINUX FOUNDATION PROJECTS

OpenChain Monthly Newsletter – July 2026

Welcome to the July 2026 edition of the OpenChain newsletter. Here’s what’s new across our community, our compliance programs, and our conformant organizations.


1. Join the OpenChain Business Operations Study Group

The OpenChain Business Operations Study Group is a community forum for exploring new ideas, identifying emerging requirements, and discussing potential projects that can help shape the direction of the OpenChain Project. The group is open to everyone — you’re welcome to join the discussion, share challenges and opportunities, and learn from others.

👉 Learn more and get involved: openchainproject.org/openchain-business-operations

2. CRA Requirement & Checklist Ready for Community Review

The OpenChain CRA Requirement & Checklist is now ready for review. This resource defines a compliance program for the EU Cyber Resilience Act (CRA), structured in alignment with the OpenChain Project’s adoption framework and ISO/IEC 18974 (Open Source Security Assurance). It serves as both a policy framework and a self-certification checklist.

A reminder on timing: the CRA’s main obligations apply from 11 December 2027, but reporting obligations already apply as of 11 September 2026 — so now is the time to get familiar with the checklist.

We warmly invite everyone in the community to review the document, share comments, and contribute via pull requests and issues on GitHub. If you’d like your name and company credited in the final published document, just note them in your comment.

👉 Review the checklist and CRA compliance page: openchainproject.org/cracompliance

3. Congratulations to 42dot — New ISO/IEC 5230 Conformance

We’re pleased to announce that 42dot has achieved conformance with ISO/IEC 5230, the international standard for open source license compliance developed through the OpenChain Project.

As part of this effort, 42dot strengthened its open source governance framework and improved collaboration across engineering, legal, and other key functions, resulting in a scalable compliance program that supports the responsible use of open source software throughout the organization. Open source plays a critical role in 42dot’s mobility solutions, including software-defined vehicles and connected mobility platforms.

42dot joins a growing global community of organizations that have adopted ISO/IEC 5230 as a benchmark for open source compliance and software supply chain management.

Congratulations to the 42dot team on this milestone! 🎉