
Navigating the New Era: The EU Cyber Resilience Act Explained with Madalin Neag
Om avsnittet
In this episode of What’s in the SOSS, host Sally Cooper is joined by Madalin Neag, EU Policy Advisor at the OpenSSF, to demystify the European Union’s Cyber Resilience Act (CRA). As the tech industry shifts from treating open source as a free buffet to navigating a new era of regulatory liability, Madalin explains how the CRA establishes a horizontal cybersecurity baseline for digital products. The conversation explores the innovative concept of "open source software stewards," the importance of moving beyond passive consumption to active upstream contribution, and why compliance should be viewed as an outcome of good engineering rather than a separate checkbox exercise. Whether you are a manufacturer of smart devices or a volunteer maintainer, this episode provides essential insights into how the CRA will reshape the global software supply chain, encouraging a secure-by-design mindset that strengthens the entire digital ecosystem.
Chapters:
00:23 - Introductions and Madalin’s role at OpenSSF
03:42 - What is the Cyber Resilience Act (CRA)?
05:27 - The CRA in the global regulatory landscape
09:05 - Relevance to open source and the "Software Steward" concept
13:02 - Moving from passive consumption to upstream contribution
16:20 - Practical steps for organizational readiness
20:26 - Should open source maintainers be worried?
24:12 - Insights from the Linux Foundation CRA Readiness Report
31:32 - What to watch for in the coming year
34:07 - Rapid fire round and concluding thoughts
Episode links:
- Madalin Neag’s LinkedIn page
- Cyber Resilience Act - Implementation
- Global Cyber Policy Working Group
- Linux Foundation 2026 CRA Awareness and Readiness Report
- Case Study: Defending the Open Source Supply Chain in a New Regulatory Era
- OpenSSF’s Global Cyber Policy Working Group European Union Cyber Resilience Act (CRA) Information, Resources & Guides Page
- Open Source Project Security Baseline (OSPS)
- SLSA
- Gemara
- GUAC
- OpenSSF Projects
- Understanding the EU Cyber Resilience Act (CRA) (LFEL1001)
- Global Cyber Policy GitHub Repository
- Join us at Open Source Summit and OpenSSF Community Day in Prague
- Get involved with the OpenSSF
- Subscribe to the OpenSSF newsletter
- Follow the OpenSSF on LinkedIn
What's in the SOSS? An OpenSSF Podcast med OpenSSF finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.