Tech Talk: CRA Readiness: A Practitioner’s Guide to Compliance

Tech Talk: CRA Readiness: A Practitioner’s Guide to Compliance

As upcoming reporting milestones draw near, how are industry leaders navigating the transition to EU Cyber Resilience Act (CRA) compliance?

The CRA has shifted from a future regulatory discussion to an immediate operational reality. Meeting key compliance milestones necessitates a pragmatic, clear path forward for software manufacturers, commercial entities, open source stewards, and foundations alike.

Join this OpenSSF Tech Talk to learn how organizations are operationalizing alignment and preparing for upcoming deadlines. In this session, we will explore key findings from the 2026 CRA Awareness and Readiness Report, introduce the newly launched Launchpad SIG under the Global Cyber Policy Working Group, and break down exactly who is impacted by upcoming regulatory milestones. Additionally, we’ll dive into Member Organization Case Studies featuring real-world examples of how OpenSSF member companies are operationalizing compliance, strengthening software supply chain transparency, and maintaining strategic open source engagement.

Speakers:

Roman Zhukov

Roman Zhukov
Principal Architect – Security Communities Lead, Red Hat

John Kjell

John Kjell
Principal Cloud-Native Consultant, ControlPlane

Nicole Bates

Nicole Bates
Principal Technical Program Manager, Microsoft

Moderator:

Megan Knight

Megan Knight
Director of Software Communities, Arm