Insight session image of Knowledge Forum A

Update on the Cyber Resilience Act—What needs to be done, and what are the rules for using Open Source?

The presentation provides an overview of the requirements for products with digital elements under the Cyber Resilience Act and focuses in particular on the use of open source.

Topic

Legislation, standards, regulations

When & Where

calendar_month

Wed, 10/28/2026 12:30 PM - 12:45 PM

location_on

Forum A, Booth 6-216

Download session as iCaldownload_for_offline

Details

  • Format:

    it-sa insights

  • Language:

    German

Session description

Speaker: Stephan Schmidt The Cyber Resilience Act (CRA, Regulation (EU) 2024/2847) imposes comprehensive new cybersecurity obligations on manufacturers, importers, and distributors of products with digital elements—and in doing so raises specific legal questions regarding the use and provision of open-source software. This presentation provides a practical overview of the key requirements and deadlines under the CRA and takes an in-depth look at the special provisions for open-source components and open-source software stewards under Articles 24–27 of the CRA.

Topics covered include:

- Scope of application and product classification (Standard, Important, and Critical Products, Annexes III/IV)
- Distinction between “Open-Source Software Stewards” and commercial manufactu ...