Trust but verify: How CRA could reduce compliance costs and improve sustainability of open source
About this talk
This talk, presented by Aki Rose Brown, Alistair Woodman, Mark Thomas, and Timo Perälä, explores the implications of the Cyber Resilience Act (CRA) on open source ecosystems and the compliance obligations of manufacturers. It discusses how the CRA introduces new requirements for due diligence, attestations, and visibility within the software supply chain, highlighting the concept of a "trust tax" that shifts the responsibility of software integrity proof onto manufacturers utilizing open source components. The panel emphasizes the importance of software bills of materials (SBOM) for traceability, encouraging open source projects to generate and share dependency data for compliance evidence and better vulnerability management. Structural changes in manufacturer engagement with open source are also covered, advocating for increased direct participation rather than merely requesting compliance artifacts. The discussion addresses the challenges faced by smaller manufacturers, including awareness gaps and the need for integrated compliance processes across diverse ecosystems.