Session
Transparency Upstream, Evidence Downstream: Manufacturers and Open Source under the CRA
The Cyber Resilience Act settled the legal side of the open source relationship: product responsibility stays with the manufacturer, stewards carry a light-touch regime, maintainers shielded from manufacturer-grade duties. The operational side is far less settled. Manufacturers must consume and interpret upstream security signals, but what that takes is rarely described from the manufacturer's seat.
This session walks that seat in concrete terms. From 11 September 2026, a manufacturer has 24 hours from awareness of active exploitation to file an early warning. Awareness at that speed is only dependable when machine-readable upstream signals (SBOMs, VEX, provenance, project health) are continuously correlated against what was actually shipped, per product, per configuration, with the record written as it happens, not assembled afterwards.
It also covers the return path: contributions rather than contracts, funding rather than warranties, and a defence of the transparency-versus-assurance boundary that keeps the voluntary model sustainable.
Presented three and a half weeks after the reporting duty goes live, it closes with first field observations from September.
William Janssen
CTO & Head of Engineering | EU Cyber Resilience Act author | Ex-Red Hat & Founder
The Hague, The Netherlands
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top