Open Source Software in Public Policy

Governments globally recognize cybersecurity’s importance, establishing partnerships and strategies to secure digital infrastructure. However, this attention risks unintentional government policies inconsistent with open-source software (OSS) development and use, often due to a lack of understanding of OSS.

The OpenSSF is a “community of software developers, security engineers, and more who are working together to secure OSS for the greater public good.” This includes the secure development, distribution, deployment, and use of OSS. This short document gives a clear stance on OpenSSF policy work, whether regional or general, as a basis for policy summits, member discussions, and solidarity across our policy representatives.

We, the OpenSSF, take steps to constructively engage with stakeholders worldwide to help improve the security of OSS globally, including working to ensure that OSS will continue to be sustainably available to everyone. This includes responding to government requests for information (RFI), providing expert advice, engaging in processes to develop relevant standards, reporting vulnerabilities/incidents and working to improve related processes, providing fora for discussions and collaboration, and developing educational materials. Per the Linux Foundation bylaws section 8.8, we do not perform any political expenditure or lobbying that might impact our status as a tax-exempt organization.

The OpenSSF focuses on following (per the OpenSSF Public Policy Committee):

  1. Encourage governments to responsibly consume OSS in general and contribute upstream, particularly in areas concerning security
  2. Encourage public funding of OSS ecosystems, particularly targeting security enhancements and maintenance
  3. Encourage OSS consumers to be responsible for OSS security outcomes
  4. Encourage governments to engage with or join OSS communities
  5. Encourage governments to adopt secure-by-design, secure open source software, and software supply chain security best practices as three key pillars of cyber workforce and education strategies
  6. Encourage governments to collaborate, internationally, to secure open source software
  7. Encourage governments to include OSS consumption, contribution, appropriate regulation, engagement, education, and international collaboration as key prongs of their AI strategies, and use AI to accelerate each of these.

We advocate for flexible approaches that are efficient, agile, and enable innovation. We note that many OSS projects have small communities (often only one person) and don’t have a source of finances, so many OSS projects cannot develop extensive documentation or provide specialized responses to regulations without additional assistance. The OpenSSF develops tools, guidance, education, and other materials to make it easier for maintainers and communities to develop more secure OSS.

The OpenSSF has a global focus, with international policy and standards experts who advise and work with our communities. We recognize that cybersecurity concerns transcend political borders and want to address universal challenges that all creators and consumers of software face today.

For more information about the Economic and Security Imperative of Open Source Software, download our OpenSSF Policy Primer created by the OpenSSF Public Policy Committee.

Global Cyber Policy Working Group

Cybersecurity is a matter of global interest and concern. Stakeholders from across the ecosystem and the globe are impacted by the deluge of cybersecurity incidents and vulnerability exploits. The Global Cyber Policy Working Group seeks to assemble subject matter experts from many disciplines to collaboratively discuss legislation, regulation, and cybersecurity frameworks and standards that can help stakeholders of all background meet their compliance obligations.

Governing Board Public Policy Committee

The mission of the Governing Board Public Policy Committee is to provide an avenue for OpenSSF members to collaborate on policy matters related to or that impact open source software. Activities may include, for example, making recommendations on public statements regarding technical documents (including guidelines) published or authorized by public authorities, policy statements such as the U.S. EO, proposed regulations, and draft legislation or documents advancing the joint understanding on these issues in a manner consumable by policymakers.

European Union Cyber Resilience Act

The Cyber Resilience Act (CRA) law entered into force (EIF) on December 10, 2024, when it was published as Regulation (EU) 2024/2847 in the Official Journal of the European Union. The CRA will fully apply three years later, on December 11, 2027. The CRA will obligate all products with digital elements, including their remote data processing, put on the European market to follow this regulation. The CRA intends to address threats and vulnerabilities by establishing standardized frameworks for cybersecurity requirements as part of a wider set of European product legislation.

Public Policy News and Updates

Sep 29, 2026 | OpenSSF

CRA Tech Talk, 09/07/2026

This CRA Tech Talk was hosted by the OpenSSF Global Cyber Policy Working group on Monday, 7 September at 4:00 PM CEST. High-level Agenda: Introduction to the CRA reporting obligations SUSE’s journey towards readiness for the CRA reporting obligations Nokia’s journey towards readiness for the CRA reporting obligations Linux Foundation:… Read more.

Sep 15, 2026 | OpenSSF

Grow CRA Readiness: Find Your Path Through the European Union Cyber Resilience Act

Discover how the EU Cyber Resilience Act (CRA) impacts your open source work. OpenSSF’s new community garden user journey helps maintainers, software stewards, and manufacturers navigate legal requirements and find essential tools for CRA readiness. Read more.

Sep 11, 2026 | OpenSSF

A Community Guide to the EU CRA September 11 Deadline for Manufacturers

The EU Cyber Resilience Act (CRA) introduces new cybersecurity requirements for products with digital elements. Discover what the September 11, 2026 reporting deadline for manufacturers means for the open source community, maintainers, and stewards, and how you can prepare to support downstream ecosystems. Read more.

Sep 10, 2026 | OpenSSF

Open by Default After AI: The GDS Guidance and the Enforcement Question

September 2026 By Sal Kimmich and Simon John Executive Summary In early May 2026, NHS England issued a reported internal guidance note, SDLC-8, mandating the removal of public access to several hundred GitHub repositories. The stated reason was AI-accelerated vulnerability discovery. The actual effect was to contradict years of established… Read more.

Sep 1, 2026 | OpenSSF

What’s in the SOSS? Podcast #71 – S3E23 Navigating the New Era: The EU Cyber Resilience Act Explained with Madalin Neag

In this episode of What’s in the SOSS, host Sally Cooper and OpenSSF EU Policy Advisor Madalin Neag demystify the EU Cyber Resilience Act (CRA). Learn how the CRA establishes a new cybersecurity baseline and what it means for open source maintainers, contributors, and the global software supply chain. Read more.

Aug 26, 2026 | OpenSSF

Case Study: Conquering the EU Cyber Resilience Act (CRA) with 1,400 Upstream Security Fixes

Ericsson Software Technology successfully met the stringent obligations of the EU Cyber Resilience Act (CRA) by fundamentally shifting to upstream collaboration. Guided by OpenSSF principles, they eliminated private forks and contributed over 1,400 dependency updates and security fixes directly to open source communities. Read more.

Aug 25, 2026 | OpenSSF

What’s in the SOSS? Podcast #70 – S3E22 Private Forks, CRA Deadlines, and the True Cost of Open Source Compliance with Dave Russo

In this episode of What's in the SOSS, host Sally Cooper and Red Hat's Dave Russo unpack the European Union’s Cyber Resilience Act (CRA). Discover the hidden financial toll of private forks, the crucial legal distinction between manufacturers and open source stewards, and actionable steps your organization can take to… Read more.

Aug 18, 2026 | OpenSSF

What’s in the SOSS? Podcast #69 – S3E21 Watering the Community Garden: Navigating the EU CRA for Open Source with Roman Zhukov

The clock is ticking toward the European Union’s Cyber Resilience Act (CRA) deadlines, yet a staggering 66% of organizations remain completely unaware of what is coming. In this episode of What’s in the SOSS? host Sally sits down with Roman Zhukov, co-chair of the OpenSSF Global Cyber Policy Working Group… Read more.

Aug 14, 2026 | Jeff Diecks

CRA Monthly Tech Talk: ORBIT Launchpad SIG Updates

https://youtu.be/gAv60r9ZRVs?si=c329jpaEfHQE7TQ0 Read more.
Tech Talk: CRA Readiness: A Practitioner’s Guide to Compliance

Aug 11, 2026 | aliu

CRA Readiness: A Practitioner’s Guide to Compliance

The EU Cyber Resilience Act (CRA) is no longer a future regulatory discussion; it is an immediate operational reality. With the September 2026 reporting deadline rapidly approaching and full compliance required by December 2027, software manufacturers, commercial entities, open source stewards, and foundations must establish a clear, pragmatic path forward.… Read more.