
Open Source Security Foundation
Linux Foundation initiative coordinating open-source software supply-chain security across member companies.
The Open Source Security Foundation, a Linux Foundation initiative formed in August 2020, has been preparing open-source communities for the EU Cyber Resilience Act's first enforcement date, 11 September 2026.
Last refreshed: 22 September 2026 · Appears in 1 active topic
Timeline for Open Source Security Foundation
Prepared open-source communities for the CRA reporting deadline
European Tech Sovereignty: Cyber Resilience Act starts its clockBackground
The Open Source Security Foundation (OpenSSF) is a cross-industry initiative formed by the Linux Foundation in August 2020 to improve software supply-chain security. Founding governing board members included GitHub, Google, IBM, JPMorgan Chase, Microsoft and Red Hat, and membership has since grown to well over 100 organisations.
OpenSSF is hosted by the Linux Foundation, a US-based body, not a European one, which matters in a European tech sovereignty context: an organisation coordinating supply-chain security for European regulation sits, structurally, outside Europe. It works alongside Linux Foundation Europe on compliance-facing work such as CRA preparation, drawing on the wider Linux Foundation's cross-industry membership rather than a Europe-only base.
It readies open source for the CRA
The EU's Cyber Resilience Act began enforcing on 11 September 2026, giving manufacturers a 24-hour duty to report actively exploited vulnerabilities or risk fines of up to €15 million. The Open Source Security Foundation and Linux Foundation Europe spent months preparing open-source communities for that Deadline.
The duty lands on the commercial vendor selling a product, not on the open-source code inside it, so what the CRA requires of open-source maintainers themselves remains unsettled; full application of the Act follows in December 2027.