The EU Cyber Resilience Act (CRA) is no longer a future regulatory discussion; it is an immediate operational reality. With the September 2026 reporting deadline rapidly approaching and full compliance required by December 2027, software manufacturers, commercial entities, open source stewards, and foundations must establish a clear, pragmatic path forward.
If your organization builds, distributes, or commercializes software with digital elements, now is the time to shift from policy interpretation to operational execution.
To help you navigate this transition, OpenSSF is hosting an upcoming Tech Talk: CRA Readiness: A Practitioner’s Guide to Compliance. Join industry leaders and security architects as they share real-world implementation strategies, empirical research, and actionable guidance for software supply chain transparency.
Event Details
- Date & Time: Thursday, August 20 at 1:00 PM ET
- Location: Virtual via Zoom
- Registration Link: Register for the Tech Talk
What will you learn?
This interactive session moves beyond theoretical compliance to address how organizations are actively operationalizing CRA alignment on the ground. Key highlights include:
- 2026 CRA Research Insights: A deep dive into empirical findings from the 2026 CRA Awareness and Readiness Report, highlighting ecosystem trends, persistent readiness gaps, and major compliance friction points.
- Member Case Studies & Milestone Guidance: Real-world examples of how OpenSSF member companies are preparing for upcoming reporting deadlines while strengthening software supply chain transparency and upstream open source engagement.
- OpenSSF Community Collaboration: An inside look at the newly launched Launchpad SIG under the Global Cyber Policy Working Group, exploring how open source communities collaborate to share actionable resources, tools, and best practices.
What’s in this Tech Talk?
- Introduction: Opening remarks by session moderator Megan Knight.
- Understanding the CRA: What It Requires and Why It Matters: Roman Zhukov breaks down core CRA obligations, defining “products with digital elements,” mapping critical timelines, and analyzing data from the 2026 CRA Awareness and Readiness Report.
- Insights from Implementing Organizations: John Kjell and Nicole Bates present case studies on how their respective organizations are operationalizing supply chain frameworks, hardening SBOM/provenance practices, and utilizing the Launchpad SIG.
- Panel Discussion and Live Q&A: The panel addresses top questions submitted by attendees. We will also address common questions regarding upstream engagement strategies, implementation hurdles, and open source tooling.
Who are the speakers?
- Megan Knight (Moderator) – Director of Software Communities, Arm
- Roman Zhukov – Principal Architect – Security Communities Lead, Red Hat
- John Kjell – Principal Cloud-Native Consultant, ControlPlane
- Nicole Bates – Principal Technical Program Manager, Microsoft
Secure Your Spot Today
Whether you are auditing your software supply chain, implementing SBOM practices, or determining how CRA impacts your open source contributions, this session will provide concrete, peer-tested strategies to guide your roadmap.
Click here to register for the Tech Talk now








