Summer is normally quiet in Brussels, but this year might just be the exception: over the last month, the EU has passed two milestones in implementing its Cyber Resilience (CRA) and AI acts. The OSI has been engaged with European policymakers over the past two years to ensure those laws don’t inadvertently harm Open Source.

For Open Source developers, maintainers, and organizations, these developments raise important questions about how new regulatory frameworks apply across the software ecosystem. Clear, practical information is essential to help the community understand new requirements, distinguish applicable obligations, and continue building and sharing open technologies.

The first milestone comes in the form of Commission guidance on the Cyber Resilience Act. The law establishes cybersecurity requirements for products with digital elements, including vulnerability handling, security updates, and lifecycle responsibilities. The European Commission’s guidance provides answers to many of the burning questions about the CRA. The guidance contains sections both on Open Source software and Open Source software stewards, which both offer important clarifications on how the CRA will impact Open Source in practice.