The CRA: A key to a more resilient FOSS ecosystem (mrmcd26)

The CRA: A key to a more resilient FOSS ecosystem (mrmcd26)

Author: CCC media team September 11, 2026 Duration: 45:24
With the Cyber Resilience Act FOSS projects are legally on the hook as part of software supply chain ecosystems. In order to address regulatory obligations and foster open collaboration within software supply chain ecosystems best practices, tooling and standards as well as established pathways for public benefit stewardship are needed. The talk will present current work in various Open Source Foundations, the IETF, as well the EU. Various supply chain regulations (EO 14028 [1], SSDF [2], SEC Cyber Rule [3], SLSA [4], NTIA [5]) and the currently developing Cyber Resilience Act (CRA) in the EU create obligations [6,7] for both software suppliers and dependents. For the first time, this includes Free and Open Source Software (FOSS) projects, with the CRA introducing the legal concept of the Open Source Software Steward in the EU framework. The talk will provide an overview of the work being done to ease the regulatory burden of these regulations on FOSS projects and their dependents (aka manufacturers). This includes: - Standards to enable compliance-critical communication within software supply chain ecosystems (e.g., the SCITT Working Group at the IETF [8]); - Machine-readable information about FOSS projects at the OpenSSF [9]; - The development of best practices for collaboration between FOSS projects and their dependents (aka manufacturers) under the CRA in the ORC Working Group [10]. Additionally, the talk will cover the current debate on recognizing public benefit status for the stewardship of Digital Commons (aka "Gemeinnützigkeit Open Source"), such as the recent policy paper by the German Association of Computer Scientists [11]. [1] https://www.nist.gov/itl/executive-order-14028-improving-nations-cybersecurity [2] https://csrc.nist.gov/projects/ssdf [3] https://www.sec.gov/rules-regulations/2023/07/s7-09-22 [4] https://slsa.dev/ [5] https://www.ntia.gov/page/information-quality-guidelines [6] https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng [7] https://digital-strategy.ec.europa.eu/en/factpages/cyber-resilience-act-implementation [8] https://datatracker.ietf.org/group/scitt/about/ [9] https://openssf.org/blog/2026/05/29/aligning-on-machine-readable-signals-as-the-foundation-for-due-diligence/ [10] https://orcwg.org/ [11] https://gi.de/fileadmin/GI/Allgemein/PDF/2026-06_GI_Policy_Brief_Anerkennung_und_Besserstellung_von_OSSS.pdf https://creativecommons.org/licenses/by-sa/4.0/ about this event: https://talks.mrmcd.net/2026/talk/9LHP77/

Tune into the Chaos Computer Club-recent events feed for a direct line to the forefront of digital culture and critical technology discourse. Curated by the CCC media team, this podcast channels the raw, insightful atmosphere of Europe's most influential hacker association, bringing you recordings from their major gatherings and community events. Each episode is a deep dive into talks and presentations from the last two years, covering topics from cryptography and privacy rights to hardware hacking, societal impacts of surveillance, and open-source philosophy. You'll hear from researchers, activists, and engineers who are actively shaping our digital future, offering perspectives rarely found in mainstream tech conversations. This isn't a produced show with hosts; it's an archival audio stream of genuine conference sessions, complete with audience questions and the spontaneous energy of the live event. For anyone interested in the technical details and ethical debates at the heart of modern technology, this feed serves as an essential, unfiltered resource. Subscribe to this podcast to keep your finger on the pulse of the Chaos Computer Club's ongoing dialogue, where complex ideas are broken down and the tools for a more empowered digital life are openly discussed.
Author: Episodes: 50

Chaos Computer Club - recent events feed
Podcast Episodes
Compiler Construction for Dummies (mrmcd26) [not-audio_url] [/not-audio_url]

Duration: 37:40
Wie funktionieren eigenlich Compiler und wie können wir einen eigenen bauen? In diesem Talk befindet sich die Antwort Dieser Talk beschäftigt sich mit dem theoretischen und praktischen Aufbau eines Compilers. Was sind Le…
Overcoming Agile (mrmcd26) [not-audio_url] [/not-audio_url]

Duration: 30:17
Sometimes frowned upon, yet often found in practice, with lots of variation from one company to another, the idea of _Agile_ has already gone beyond just software development. With this talk, I want to provide a positive…
DOOM in unbekannten Gefilden (mrmcd26) [not-audio_url] [/not-audio_url]

Duration: 15:06
Ein weiterer Fall von "Can it Run DOOM?" mit Hürden. Fehlendes SDK, mangelhaftes Datenblatt und Hardware die etwas mehr Rechenleistung hat als man für den Zweck erwarten würde Ein kleiner Projektbericht dazu wie DOOM auf…
Luftgrenzen überwinden: Messen, filtern, kühlen? (mrmcd26) [not-audio_url] [/not-audio_url]

Duration: 48:56
Was ist hier eigentlich in der Luft? Wie bekomme ich das wieder aus der Luft raus? Und wie bekomme ich meine Wohnung kühl? In diesem Talk schauen wir uns an, wie du mit ESP32, Lötkolben, Klebeband, 3D-Drucker und co. die…
Vacuum Deposition Systems And You (mrmcd26) [not-audio_url] [/not-audio_url]

Duration: 57:49
So, you wanna make some bathtub transistors at your hackerspace? Then you'll probably need to use a vacuum coating system! These are essential and ubiquitous in semiconductor manufacturing... But how do you get on cheap…
Shenzhen und die Elektronikmärkte (mrmcd26) [not-audio_url] [/not-audio_url]

Duration: 1:20:36
Eine Reise durch die Elektronikmärkte von Shenzhen, dem Ort von dem eure AliExpress Pakete mit den Bauteilen kommen. Mit vielen Fotos zeige ich wie die Märkte funktionieren und was man dort Spannendes entdecken kann. Ich…
Alles über die Eurobox (mrmcd26) [not-audio_url] [/not-audio_url]

Duration: 45:39
Wir überwinden den Stapelrand des Kleinladungsträgers und begeben uns auf die Suche nach der Euronorm der Euronormbox. Es geht auch um Geschichte, Erfinder und allerlei mehr oder weniger wissenswertes um das womöglich be…