
By Sally Cooper
Not sure how the EU Cyber Resilience Act (CRA) impacts your work? The OpenSSF’s new community garden user journey helps maintainers, open source software stewards, and manufacturers find their unique path to understanding the CRA. This resource provides a simple way to identify your specific role, navigate legal requirements, and access the tools, training, and community support necessary to maintain compliance and keep software secure.
Across the community, people are asking questions about the EU Cyber Resilience Act: Where do I fit? What do I need to do? Where can I find information that applies to my role?Â
That is why OpenSSF created Grow CRA Readiness: A Community Garden Journey with OpenSSF. It gives people a simple way to identify their role and move directly to the guidance, tools, and community support that can assist them.
What is the EU Cyber Resilience Act, and why does it matter now?
The EU Cyber Resilience Act introduces cybersecurity requirements for many hardware and software products made available on the EU market.
The first major deadline arrived on September 11, 2026, when reporting obligations for manufacturers began. The broader requirements apply beginning December 11, 2027. A good start in understanding is to know your role and where to find reliable guidance.
How can open source communities prepare for the CRA?
Many people are still unsure how the CRA applies to their work. The 2026 CRA Awareness and Readiness Report found that 66% of respondents were unfamiliar with the regulation.
That is why OpenSSF went all in on Policy and CRA alignment as a focus in its 2026 community roadmap. Working with the Global Cyber Policy Working Group and its Awareness SIG, the community helped to create this journey, podcasts, Tech Talks, guides, and other materials to help people find their role and take the next step.
How can I understand the different CRA roles? The community garden analogy
In our What’s in the SOSS? podcast conversation with Roman Zhukov, Roman used a community garden to explain the different roles in the open source ecosystem. Everyone contributes to the health of the garden, but not everyone has the same responsibilities.
That analogy became the foundation for the new journey.

Grow CRA Readiness: A Community Garden Journey with OpenSSF
What is my role under the CRA?
Are you an open source maintainer or contributor?
You are the hobby gardener, cultivating code and sharing it with the community. Most people contributing non-commercial open source software are not the ones carrying a manufacturer’s CRA responsibilities.
The journey points maintainers toward practical security guidance that can help projects stay healthy and make life easier for downstream users.
Are you an open source software steward?
You are the garden association, helping provide the support, governance, and resources that allow projects to thrive.
The CRA includes a specific role for open source software stewards. The journey connects stewards with guidance designed around their tailored responsibilities.
Are you a manufacturer of a product with digital elements?
You are the farm-to-table builder, taking ingredients from the shared garden and turning them into a product offered under your own name or trademark.
Manufacturers carry the broadest CRA responsibilities. The journey directs product, engineering, security, and compliance teams to the resources that can help them prepare.
Not sure which path is yours? Start with the Grow CRA Readiness journey. An organization may even follow more than one path across different projects and products.
When do CRA reporting requirements begin?
CRA reporting obligations took effect on September 11, 2026. The journey connects manufacturers and stewards with the current reporting guidance and the people who navigate these questions making it easy to find resources and information.
When do the full CRA requirements apply?
The broader CRA requirements begin to apply with the December 11, 2027 deadline. Organizations do not need to solve everything at once, but they should begin identifying their role and building a plan. The journey makes that first step much easier and links to the deeper guidance when needed.
How does the CRA journey complement OpenSSF’s Lazy River user journeys?
OpenSSF’s Lazy River user journeys help software developers, security engineers, OSPO leaders, marketing and community professionals, and executives find the OpenSSF projects and communities most relevant to their work. The CRA community garden journey adds a focused regulatory layer.
The Lazy River helps answer, “Where do I fit in OpenSSF?” The community garden helps answer, “What role do I play in CRA readiness?” Most readers will benefit from both. A security engineer working for a manufacturer, an OSPO leader helping define stewardship, or an executive building a compliance roadmap can follow a professional journey and the CRA role-based path at the same time.
What CRA readiness resources does OpenSSF offer?
The journey gathers the community’s resources into four easy stops:
- The visitor center offers the OpenSSF CRA resource hub, training, guides, and the Built to Last eBook.
- The learning greenhouse includes the CRA Readiness Tech Talk, the podcast series, and CRA readiness research.
- The tool shed points to OSPS Baseline, SLSA, Sigstore, GUAC, and Gemara.
- The community pavilion connects readers with the OpenSSF Global Cyber Policy Working Group and its public meetings, SIGs, Tech Talks, and community resources.
You do not need to visit every stop at once. Choose your path, find the resource you need today, and come back as your work develops.
Where should I start with CRA readiness?
Start with the journey.
Explore Grow CRA Readiness: A Community Garden Journey with OpenSSF
Find your role, follow your path, and use the OpenSSF community to help you take the next step. CRA readiness may be a serious challenge, but no one has to navigate it alone.
This article is for general informational purposes and is not legal advice. Consult current official guidance and your legal or compliance advisers for your specific circumstances.
About the Author
Sally Cooper is a Senior Communications & Marketing Manager and leads marketing and communications for the Open Source Security Foundation (OpenSSF). She helps the community share their stories and shines a light on the work that keeps open source secure for everyone.