By Madalin Neag, Sally Cooper, and Steve Winslow
If you are a maintainer, steward, or manufacturer, you might have heard about the EU Cyber Resilience Act (CRA) and wondered how it impacts your day-to-day work. The CRA requirements for Stewards do not take effect until December 11, 2027, but the requirements for Manufacturers take effect today, on September 11, 2026.
The CRA introduces new cybersecurity requirements for products with digital elements, with responsibilities that differ across the software ecosystem. Most of the open source software community will qualify under the CRA’s Steward framework, but knowing how the CRA will impact your downstream commercial ecosystem, who will be classified as Manufacturers, will be important. For the open source community, understanding how manufacturers will interact with open source projects is an important part of preparing for the next phase of CRA implementation.
An important milestone for this shared security model is fast approaching. On September 11, 2026, the CRA’s mandatory reporting requirements apply for manufacturers. This article explains what that means for manufacturers and, importantly, how open source projects and stewards can be ready to support and collaborate with manufacturers when reported vulnerabilities involve open source components.














