OpenSSF Report Finds Low Awareness of EU Cyber Resilience Act Among Open Source Practitioners (infosecurity-magazine.com)
- 66% of open source practitioners globally unfamiliar with EU Cyber Resilience Act (72% in US/Canada)
- 41% of organizations have not determined CRA applicability; only 32% produce SBOMs for all products
- OpenSSF warns of 394% increase in reported CVEs, adding urgency to compliance efforts
"A survey by the Open Source Security Foundation (OpenSSF) reveals that 66% of global manufacturers, developers, and other open source practitioners are unfamiliar with the EU Cyber Resilience Act (CRA), which mandates minimum security standards for hardware and software sold in the EU by December 2027. Awareness is lowest in the US and Canada (72% unaware). Many organizations are unprepared, with 41% unsure if the regulation applies, 45% uncertain of deadlines, and 56% ignorant of penalties. Only 32% produce Software Bills of Materials (SBOMs) for all products. The report also notes a 394% year-on-year increase in published CVEs, adding urgency to compliance."
no comments yet.