Open Community Experience (OCX)

Trust but verify: How CRA could reduce compliance costs and improve sustainability of open source

43:51 · 21 Apr 2026 – 23 Apr 2026 · YouTube

About this talk

This panel discusses the impact of the Cyber Resilience Act (CRA) on the open source ecosystem and the role it plays in compliance and sustainability. The speakers, who include experts from various backgrounds, explore the concept of the 'trust tax' that arises from supply chain security concerns. They emphasize the need for manufacturers to engage with open source communities to improve compliance and support the development of software bills of materials (SBOMs). The discussion touches on the importance of educating both manufacturers and open source projects about the new obligations introduced by the CRA. Overall, the panel highlights the delicate balance manufacturers must maintain in their relationship with open source software while navigating these regulatory changes.

Full transcript

[music] So welcome back to the last block not session of the second day of open community for compliance. This is the first panel that we are going to have and we are going to address one of the key challenges that the CRA is bringing and how we can increase uh the sustainability of the open source ecosystem through the CRA. We titled the panel trust but verify how

the CRA could reduce compliance cost and improve sustainability of open source. And I have with uh me on the stage four experts that will share their views from different angles and yeah I will start with uh Alistister Woodman physicist by training who has spent the last decade uh plus as a foundational force in the force community development. uh yeah he brings an unique analytical lens to how

open communities grow and sustain themselves. [snorts] We have uh Aki Rose here an engineer and consultant with nearly 30 years of uh hobby and professional programming experience. uh she's an specialist in technical standards including yeah many of them of course Etsy special reporter and uh leading uh yeah the ch the charge of uh VPN cyber security standards for uh Mark Thomas 20 year veteran of the open

source world mark is uh one of the members of Apache software foundation um yeah he primarily works on Tom Cat if I'm not wrong yeah >> correct >> and he's also a former uh director of the Apaches software foundation and has served on their security team for over 15 years. And last on really close to me >> uh Teimmo Perala uh from Nokia joining us from the

telecom sector with over 30 years of experience and Teimmo is currently head of the uh opensource network and service automation. Right. Good. And co-chair of the open regulatory working group. So yeah, we have a really close relationship uh within the CLI foundation and bridge the gap between industry standards and open source governance. So four different profiles, one common issue and yeah the first thing is the trust

tax. The trust tax is a concept that is widely used to represent the pressure on the open source ecosystem due to the increasing number of supply chain attacks and yeah I wonder if it's possible to balance the requirements of uh that the CRA imposed on manufacturers and the role open source projects and community can play in this space. So I will start with you Timo. Um yeah

the CRA brings this new set of obligations. We have seen it in multiple talks during these two days and that increases the pressure on manufacturers of course and how this new situation impact the relationship with the open source uh elements you consume >> right yes so um [sighs] first maybe starting off that um because the CRA impacts manufacturers big time so we've started um some time ago

already kind of an internal program where we address all different angles of the CRA requirements be they legal. So there are contractual applications or contractual structures that we need to bring into in in place um going forward. of course production that's a that's a big thing and then then open source and uh I think we've been discussing many times during the journey of this CRA that uh

it has a potential to bring manufacturers more active towards the open source community and I think that's still something that I believe and I hope but It it it also in this context of attestation I think we probably come back to it and and due diligence during this discussion is that there are some potential changes in the in this manufacturer and opensource community relation that uh is

let's put it this way it's delicate and it has potential to bring some unwanted consequences and I think those are the things that we are wary of because I mean of course the positive things are al also always nice to be listed and and we we love to do that but I think the big big question mark at least in my mind is that how do we

how do we ensure that we don't cause trouble in in in this to this community due to the CRA. So I think that's that's not exactly an answer like what changes with us because it all depends. I think that's that's what where we are. Nobody really knows how this attestation looks like and how good it would be from the manufacturer point of view valuable. We don't know

how the atesta uh due diligence looks like and what's good enough to fulfill that requirement. So yes, we have some approximations something that we want to try for and uh we will change our direction when we learn more. Okay. So a key an important element to alleviate the pressure on manufacturers is the quality of the information associated with those components that they are consuming. So in your

opinion, how they can rely on them uh to build evidence to facilitate their processes and demonstrate compliance. >> So I think this all goes back to sort of how we track our dependencies, right? Um the CRA requires that all manufacturers have, if I recall correctly, it's a top level ESBO is how it's worded. Um and a top level esbomb will help I suppose. But what open source

has the ability to do is um sort of become each project can become the a link in that chain in a way that makes it uh that makes makes transparency a really straightforward thing to accomplish. Like um you know all software is open source software, right? like all proprietary software has tons of open source software in it. And so if we kind of look at that as

the building blocks of software and software projects generally have a reasonable concept of what their dependencies are. Some languages are typically better than others at it. Um we can we can be generating sbombs from that information and sharing them. seems pretty obvious because of how open source works. And in in doing so, um being able to provide that chain, that information, and my hope is that we

can track that information enough and normalize it enough that the next time we have those big breaches or software supply chain problems, um that manufacturers can quickly respond because the the chain is already there. because we finally have gotten around to this thing that we've been talking about doing for 20 years. Um so the ESBOM um formats that exist right now are really easy to convert from

for example a package file or a gem file um the lock files, excuse me. So I I'm really hoping to see that sort of evolution happen of of it shouldn't be too much of a lift for open source projects to kind of shift to just to providing that um because the tools are already out there and I'm hoping that that can provide the sort of the the

building blocks for manufacturers to fulfill their part of that um making sure they have that information and then can act on it. So um Mark from an open source technology perspective uh are you willing to add extra effort to facilitate compliance I think that's one of the key questions that uh many times pop up and also how do you envision this new scenario based on the obligations

manufacturers need to comply with and the dynamics of open source project >> well I from a Tomcat perspective I'll start there uh it's a simple answer yes we want we want to provide that information We want to help. We've started looking at the CRA. What sort of information we think manufacturers might need? What do we need to do with our documentation to start putting that information together,

make it available? So, we're starting on that line. Although, as Teemo said, what we actually need is still undefined. Um, still being worked on. So, we're hopefully moving things in the right direction, but we don't actually know quite where we're heading yet. So, there's work to do there. at a foundation level then yes I think the ASF like all similar foundations where it can do things at

a foundation level to support the projects and to support the CRA will do that. I think where it gets really interesting is for the projects that aren't in the sort of position that Tomcat's in. We're fortunate that we've got a at least for an open source project a reasonably large reasonably diverse range of committers from a reasonably diverse range of companies. Um, we've got people who've got

the time and who are willing to do this. Um, other projects aren't so fortunate. Um, there's a couple of projects I can think of that are pretty much critical to their industrial sectors, but industry really isn't doing anything to support those projects. Now, what happens when the CRA comes along? Is that going to change? I really hope it does. Whether it will or not remains to be

seen. There's lots of unknowns. We sort of have got this idea of how we think it's all going to play out and how we hope it's all going to play out, but there's always unintended consequences and we can't really we don't know what they're going to be and we don't know what impact they're going to have. So there's quite a large unknown there. The other area is

or another category is projects that are very mature, very stable. They've got a community behind them, but they don't really need to spend that much time on them because not much is happening. It's the odd bug, the odd vulnerability report. How are those projects going to cope when the CRA comes along? And then there's all this extra stuff that suddenly needs to be be done again, what's

the relationship going to be between that project and those downstream users? Again, I hope it's a positive one. I hope it all works out very well. I hope that this idea that we can bring more of the downstream users into the projects and provide a little bit more support and really have open source working the way that we've always wanted it to work. I hope that happens.

It remains to be seen what actually But um Alistister uh from the land ecosystem foundation you have spoken about the role of attestations many time but how do you plan to accommodate your activities to the new reality that the the CRA establishes? >> Uh so the foundation has been very engaged in this space for at least the last three years. Um I think uh I know a

few people who were engaged in three year over three years ago with the CRA but there aren't that many. And we I think were fortunate in the sense that we realized that we needed to do something about this and get our house in order. So we've been very actively engaged with what's going on in the European Union. not just because of the European Union but because I

think it's generally useful hygiene. Um so the um was has been quite happy to be engaged in these things and we got uh engaged in the open chain uh project a lot of our code comes from Ericson um and they were were a prominent driver behind the behind the open chain effort but it was also just a sensible thing to be doing for the industry. So when

the CRA took the present shape that it's in, it just became very obvious to me and the folks in the community that the right thing to do was to apply central resources to this and make sure that most of the uh projects in our area didn't actually have to do anything. So if you centralize the efforts for these types of things and just make it uh part

of your build process and make sure that these things just occur, then it's relatively easy to get compliance from engineering teams. If you've done all the work, they're just quite happy to, you know, let some other script run and do some other type of thing. if you don't and you actually try and get engineers to do something that they they will just you know dig their heels

in and not want to do anything. So I think the only sensible way to get this stuff done is by some form of divide and conquer at whatever the idea of stewards were. Um, and we haven't formally declared that we will be a steward, but I think it's entirely obvious that we will. And um, we're doing everything that I think a sensible steward should be doing to

put the tooling in place to make it easy for anybody is in our community to get the job done. And hopefully they won't even notice that that uh we went through some milestone barrier because we're automatically providing them with the uh tooling that they need to get the job >> Good. Um yes some of the one key aspect that all of you have uh pointed out is

that uh the diversity of the entities that impacted by the CRA not only in terms of uh yeah manufacturers towards but also the type of manufacturers the different type of open source projects basically this diversity is huge and in all directions and there are multiple elements that uh can be the pain point depending on where you are and what are the sector that you are targeting. So

my question to all of you and yeah any feel free to jump here and I want to encourage you to discuss and and share your views on this is what is the element or the asset that you think will be transformed the most and what are the drivers for that transformation. I think um I think it's going to be quite interesting when we start to see manufacturers

who in the past have not participated in open source um starting to show up at open source projects and of course there's going to inevitably be the please fill out this form so that we can continue using your module that's going to happen and it's going to be on all of us to laugh them out of the room and then welcome them back when they send engineers.

um with open arms. So it's going to happen. It's going to it's going to start with that trickle that's already sort of started happening as manufacturers saying like prove your conformance and open source projects saying no. Um I actually I support that behavior. However, um once we have manufacturers realizing that there is um that there is software that they depend on for their core business that is

causing this gaping hole in their conformance, they're going to start figuring out how to do something about it. And the path of least resistance is probably going to be commit an engineer to work with the project to make sure that their security house is in order. Either um you know actively saying hey would you would you be willing to sit down with us and and we'll put

in the work um but we we need to know where you're at or whether it's um uh uh forking and upstreaming. There's kind of a lot of different ways that can be pulled off. But I think that it's going to be a huge transformation when the for the medium-sized open source projects that won't have any sort of um steward when the manufacturers start coming around and saying

uh please prove that you you that you are um ready for this they're going to be they're going to be goatated into actually giving back which I'm going to find really exciting and interesting. >> Yeah. I think in my my mind it it kind of revolves around maybe it's because of the theme of the panel but this this kind of due diligence and and testation because I

think from the manufacturer point of view that we we would this is something that we need to it's a new thing that we need to be able to demonstrate that we've been doing stuff to to to to do the right things and be able to present that to to some somebody who comes and scrutinizes. So I think that's that's one one aspect that is for sure um

sort of changing if not the landscape then at least the kind of the practices that we need to carry out. I mean obviously we've had we creating sbombs for our products and the things that software that we put into the products we do have the open source selection criteria which is uh diligently followed but I think this this new thing kind of brings a new flavor to

to all that and uh and the shameless block here is that we're working in the OC working group on the manufacturer opensource studio diligence. So you're interested on the topic. So please come to the next uh call put some PRs into the repo so we get it right because that contributes to what Aki was just saying that if the manufacturers come to the pro projects and say

that provide us with this then you can give them this due diligence guidance paper that says that what actually the manufacturer should be doing not asking these things but doing something by themselves to guarantee that that they get get appropriate level of appropriately secured open source and I so I'm the I'm the bad guy here I'm the but at the same time I'm not I'm I'm part

of the open source community so that's kind of an interesting dynamics there as well so it's like it's not like we are looking over the fence to that other side and kind of asking and and demanding things we are part of that thing. So who would in their right minds kind of look at the other side to themselves and ask stuff from themselves? So it's like there

is a lot of different kinds of dynamics here. Um I think and um and and I think we should be capitalizing on that part that manufacturers are part of the community. So let's just encourage them to be even more active than what they have been so far. Yeah, I I definitely agree with that and I very much hope that one of the end results is that manufacturers

are much more involved in the open source, but I do wonder whether particularly for those projects that are currently outside of the foundation and that aren't that interested in the CRA and those manufacturers that aren't that interested in contributing back whether there isn't sort of a gap in the middle where some other entity of some form may emerge to sort of help bridge the gap between the

two. But what that might look like very hard to tell at this stage, but I can certainly see that there's a potentially something there that could emerge in some form. But with so many unknowns everywhere, it's hard to see what exactly what that might look like, but I think there's certainly a potential for something there. Yeah, >> just a note maybe there that what strike struck me

odd in the CRA text is that it kind of talks about open source and then it talks about the stewards and well somebody has said that 90% of the open source is developed by somebody who doesn't have anything like a steward in the picture at the moment. So it's like um so did you really deliberately kind of overlook like 90% of of of the open source when

in writing that text and this is exactly the thing that when there are these uh sort of individual projects that they what's the motivation and what's the resources they have to to step up and there the community comes into picture and then there are the manufacturers who are part of the community. So maybe that kind of cycle, [sighs] virtue cycle might happen hopefully. >> Well, I I've

been on public record multiple times and pointed out that there's a very long tale of stuff out there which is open source which is just abandonware and it should be very clearly labeled as abandonware or certainly not for um you know formal use in for for manufacturing purposes. Um, so if I had my brothers, u I would just suggest to GitHub that everything was flagged as not

to be used and then you'd see who turned the bit over and changed it into it's okay to use this for commercial process. So I'm not sure that my wish will will happen, but um I think we'll end up with a a slightly less confrontational way of of going about this. But uh I would expect that most of the active projects will then put some flag up

saying okay we are CRA compliant or we're working for we're anticipating that we're used in commercial projects and come talk to us. Um I'm more concerned about the long tale of the >> who so we have this manufacturer on stage. I get to talk to him at least once a week on conference calls. Um there's a couple of other manufacturers that show up and uh behaving in

good civil uh society models and engaging in the process, but there's so many other manufacturers at the moment who are overworked, busy, or it they have so many other things that they're worried about at this moment that they still think of it as not actually something that they need to be worrying about. And even though part of the CRA comes into into force this year, they're still

going, well, I don't really have to worry about anything till 2027. So, uh, they're not that engaged in the process. And when they do start to get engaged, we will see the flurry of please fill out this, you know, Excel spreadsheet and fax it back to me type of thing because that's to a certain extent still the level of some of the stuff that's going on out

there. and they need to get into the modern tool chain stuff, but they also need to think about what they're doing. And that would all be quite complicated. And then suddenly AI is coming out of left field and making them possibly become more of an issue that they need to be paying more of attention to this stuff anyway. So, it's going to be an interesting couple of

years is my take on this. So, we'll see what happens. >> Good. You pointed out a lot of different things. Of course, due diligence and Teemo, don't worry, you could be the bad guy in the panel, but we have a lot of manufacturers in the audience, so it's a fair battle. Um, >> plenty of my friends are manufacturers today. [laughter] >> Yeah. C, can we have a

quick show of hands? Actually, who are manufacturers in the audience? >> Oh, look at that. >> Good. Excellent. Well done. Thank you. >> So pleased to see you all. >> Yeah, but yeah, you point out um due diligence. We have article 25 with attestations. [snorts] Uh Alistister pointed out that people is still not aware of what are the obligations that need to they need to fulfill and

in terms of really create an impact. What are the things that should be prioritized to to basically change things and make the CR implementation a success? What what are your views on this? It's there is a single thing that need to be prioritized or it's something basically that uh yeah alto together we we need to work out >> like everything it's logistics it's convincing executives to invest

in logistics um for example I recently had some dinner with a handful of um engineering and compliance executives and when they found out that I worked on CRA stuff they start peppering me with questions and oh I heard absurd thing and oh I heard that we're going have to do this and said no and kind of and yeah um and having a conversation with them where I

heard what their concerns were and kind of tried to the to the best of my ability to to explain to them what the what the act actually meant. Um I could see the gears turning in their head of of oh we're going to have to do an inventory and then figure out what we're going to do next. So it starts with logistics right like convincing the manufacturers

that they need to get started. I I think that that alone and this might be might be a failure of imagination on my part or naive but I think that alone if you can convince the executives that they need to start [snorts] it it really seems like it's at this point um orc has done such great work there's there's so much out there for them to to

read and and follow that from there it's it's it's more of a step by step now as opposed to a massive question mark. >> Yeah. I think I was kind of thinking that u with the with this attestation and due diligence that would be that would take us already a long way. But then I started to think as you talk that when we started OC I think

the first thing we had in mind was that we need to kind of spread the news and and and educate people that this is this is actually this is not just another regulation. it actually does have a significant impact on on ways of of producing and putting stuff on market and and kind of what that all that entails. So you can't wait until end of 27 and

then then do some crash action that doesn't cut it. So so that was more more than a year ago. So then working on with this one like on on a weekly basis if not on daily basis, one starts to think that okay now people have heard about it, people know about it, they understand it and then I step outside into the sun and and talk to people

and I realize that nothing changed. 12 months and still there are tons of people who should know about it. they don't should put some thought on it and they haven't. So I think that still so that's why I put that one as our first priority. We >> don't sell your resources short. Once we can get people pointed at them, they're really fantastic. >> Good. Yeah, I'd agree

that it's outreach outreach. Outreach. Um on the open source side of things, I think that's gone pretty well. Most people in the open source community are aware of what this is and most of the FUD has been dis disposed of and open source generally is in a reasonably good position. It's the manufacturers particularly the long tale. >> The long tail it's the long tail. >> It's it's

how do we re how do we reach out to them? And yeah, there should be hundreds of people in this room. They should be streaming out of the door listening to stuff about the CRA trying to find out more and they're not here. Um, and they're not getting that information anywhere else either as far as I can tell. And I've had the same experiences. You I talk

to people, friends who work in in software and see our what and oh that's going to be painful. So it it it's just more and more outreach definitely. >> Yeah. Yeah. And it's like I mean like like who I'm told I come from the telecom industry side where we have been like tens tens of years used to uh following standards. There are requirements there are mandatory requirements

and we've fulfilled them and all good. Now we have these standards around CRA which kind of have requirements or recommendations and when when you write recommendation the engineer looks like okay but that's such a requirement we don't need to care about it and all of a sudden you're in a situation even in in in our company some corners still that people think that they can negotiate their

ways through this so there's a recommendation maybe if I do something little here maybe it's okay it's like well half a billion one mistake half a billion that's kind of a stakes we are talking about here so it's it's it is an interesting situation so yes like you said three biggest problems awareness awareness awareness >> and and so having positively mentioned my experience with the open chain

folks there are a bunch of manufacturers who turn up to those events but they're all in regulated industries. >> They're the telco guys that have to deal with everything from spectrum to, you know, all those other types of things. So, they are used to turning up for those types of things. It's the automotive guys who turn up because they're in a regulated business, but there's this huge

hole in the middle, which is essentially what the purpose of the CRA was anyway, which was to fill to cover everything that wasn't there before. And because in the past they've had entire except on the CE marks were only for the product itself. So does it have lead paint on it? Is it going to electrocute somebody? They have compliance in their organization to worry about those things.

But they don't have a software compliance person that needs to worry about filling the hole in the CRA yet. And so they if you're an naive view of the world, you can see an executive. They say, "Oh, software now needs is covered by the CE mark on the outside of my product." But that's okay. I've got these compliance guys over here that look after the CE mark.

Unfortunately, they're all just hardware people, right? So they don't bringing any of their skill sets to bear in this particular area related to software compliance. So they understand that they need to get, you know, stainless steel screws so that the thing doesn't rust, but they don't understand how to engage with the software community. And I think that is going to be is a latent problem at the

moment for for how that middle, call it the long tail or it's the folks who don't worry about, you know, compliance centric businesses, but they're all going to have to turn up and do stuff. on at the moment. Depending on their size and scale, they may be just still building stuff on somebody's old Solaris workstation in their basement and that's it, right? And they're going, "We took

something from an FTP server a while ago and everything's good, isn't it?" And and we're dealing with folks that may still have systems that look like that. And it's going to be an interesting time shift that they need to get with the program. So >> yeah, that's a very interesting point because indeed my background I came from a home appliance manufacturer. We have probably 100 people working

on physical products, bill of materials. I checked a couple of weeks ago with them how many people is working on software bill of materials and none of them. We have only the IT [laughter] which is in charge of setting up routters and this kind of stuff trying to lend a hand on on the topic and in your view any of you of course how we can help

to to bridge this gap because it looks like this is something completely new that most of the companies that are affected by the CRA don't have resources that can support them but this is actually the main point of the CRA. Do you have any idea recommendation that uh yeah we can help with? >> Start with the firmware engineers, you know, bridge that gap between software and hardware.

We find the firmware engineers, get them on board. I don't have an answer beyond that. >> Maybe. >> Oh yeah, scratch that. Maybe that that's a role for sort of um industry bodies, the man the man manufacturing groups, their representatives that hopefully the manufacturers are in contact with maybe through them is is a way to reach out to them and get the message across. >> I I'll

be honest actually I have spoken to the industry group for VPN. So I work on the VPN vertical um standard for implementing the the CRA and I have um talked to the the industry group the VPN trust initiative and um got less engagement than I had hoped but but but not none >> okay >> not none. So it was a good start. Um I I I haven't

figured out what the rest of that list is yet. You know >> it's it's a long list and that's that's I think part of the problem. >> Yeah. Yeah. Yeah, I think I was kind of thinking I mean I I know that for example one and and and the other iss and I guess all of us as well we go to various events where we try to

evangelize this >> happy thing and make raise the awareness but uh that's seems to be a scaling problem there and of course like everything now you putting my old standardization hat on everything you want to get through you need to take three such first time nobody listens second time they actually remember that somebody raised that point third time if you're lucky they actually think that they they

came up with the idea and then then it's sold so unless you're able to do that much then it's it's an uphill struggle and I mean times of essence it's one and a half years to So, so we could be all more than occupied by by doing that and still we wouldn't be able to cover enough. So, I I don't know. It's it I'm not really encouraged

by by the um longtail thing and feel happy about >> No, I I think it's going to be an interesting that there is going to be some pain in that area. So >> yeah because it is like you said it's like uh some industries know about it and when we discuss in in telco circles for example there is nobody who hasn't heard about it. So it's like

a awareness is there and and then agent industry is the same thing but uh but yeah how do you go with those with whom you don't have any connection it's like shouting to the wind. Good. So, we are getting closer. Maybe one question and then closing a statement because yeah, I have Gregor. Maybe you both can share uh ask your questions and then the panel to decide

uh [laughter] what to say to respond if they want. >> Hey. Um so when it comes to talking to what you call the longtail, I think there are two points where I would love to hear your opinions about. Uh first of all, what do you do? what do you say the small and medium enterprise that is basically faced with the fact that they don't have engineers that

would be qualified to work on open source projects but still want to use software and also would any of you be willing to go to those events and actually talk to those people because uh at least in the ecosystem I'm working in which is um mechanical engineering in Germany uh there are quite a few people talking about the cyber resilience act but I never see them at

those uh cyber resilience act foss events and they pretend to be speaking for the false community. Um, so perhaps bridge building takes two to tango >> and uh if anyone wants to walk across that bridge that might be interesting. >> I think I would like to hear the answer first. [laughter] >> Wise move. Well, I I mean now putting my RSC co-chair hat on. So, I think

that might be something that we want to take take up um kind of at least to try try and figure out an answer. I mean, I would be happy to pick your brains and get it get those connections and then we'll see who has the cycles to to reach out and uh and and kind of engage with with those communities. Uh I mean that's the only way

I see I don't see any other way. There is no automation yet in place for that. There's no AI agent yet running around delivering the message. So it would be us people who would need to do that. So some leg work needed. >> I I have looked at you know um a bunch of sort of more generic tech conferences or industry specific tech conferences that have nothing

to do with open source or compliance or the CRA but just software or products with digital elements. um they don't seem that interested in talking about it at their events yet. So, I'm going to keep trying and maybe polish my pitch a little. Uh they don't need to accept me, but I would like them to accept someone. [laughter] I haven't given up though. >> Yeah. My question

is more around uh the small open-source communities especially like you know you were mentioning that there are still a number of projects who are not supported by the industry the way they should be and you are worried about them and then there are also a lot of small communities you know we we like to jot about it but it's true somebody in Nebraska or I come from

India I know many developers in India are building critical open-source projects that are going to be part of critical infrastructures in companies and they right now are struggling with the bandwidth to remediate vulnerabilities and AI slooping and now we have mythos as well which is exposing every single vulnerability that existed 50 years ago. So how they should be you know working towards CRA and handling compliance and

working towards compliance as well. Yeah, there's certainly a lot of pain for a lot of projects from AI and AI vulnerability reports at the moment. It remains to be seen whether it's a hump that will get over or whether it's a slope that's just going to get steeper and steeper and steeper. Um, if I had to bet a proportion of my salary on that, I'd bet a

small proportion on it being a hump, but only a small proportion. In terms of what we can do to help or what what can be done to help those projects, I it it's back to help those projects and help the manu the manufacturers depend on them. The projects need the help. there's clearly a mutually beneficial solution in there somewhere. Um whether that whether they can work it

out on themselves, whether we can provide some frameworks to help them work it out, whether it needs some sort of intermediary, whether more projects end up moving towards some form of that there are solutions in there. I don't think there's a one-sizefits-all. Um but there's certainly there are options there that we should be able to help or those projects should be able to get some help along

the way. >> I think it's in the nature of open source developers to want their project to be good. And so given an infinite re resources, those open source developers would absolutely be doing all of the security processes that they could possibly do because it's in the nature of especially a project that has a community built around it. They want it to be good. So if we

can make sure that we provide the tooling to make it uh as easy as possible for a project to go from um we've never really thought about this to we feel like we can help manufacturers integrate this project um to so to to to be able to provide tooling instructions and then also to provide guidance to manufacturers um figuring out how to integrate all of these different

projects into their um documentation. for example. I I I think that can make a really big difference because cuz kind of everybody wants the same thing. It's just that everyone maybe has different ideas of who should do it and how. >> Good. So, uh demo you want to say something? >> You have one minute. >> It's it's like I think I I was thinking that I I

was being naive because but I then I I was thinking along the same lines it. So it's ultimately a project is like a single project doesn't really have too too many requirements on them from from the CRA. So from that point of view all good. It's all on manufacturers. If the manufacturer needs this project deliverable, it's in their best interest to become active and support that project.

So it to me it sounds so that's the naivity part. It sounds simple solution. >> How it happens in reality there has to be a lot of pain points encountered first and through that pain the industry will learn. Maybe that was my final comment. >> All right. So I have no time for more questions but I have a solution which is we have meetings Monday, Tuesdays and

Thursdays in the OC community. We will be discussing attestations and due diligence and if the topic is not covered in those groups you can always come to the sik meetings which is open to all the different topics but uh yeah we run out of time I want to thank Timo Aki Mark and Alistister for uh their time and their contributions and we continue with the next session

in five minutes. Thank you very much. >> Thank you. >> Thank you. [applause]