Skip to content
You can now search across every topic, entity and event.What's new
Open Source Security Foundation
AI-generated illustration
Organisation

Open Source Security Foundation

Linux Foundation initiative coordinating open-source software supply-chain security across member companies.

The Open Source Security Foundation, a Linux Foundation initiative formed in August 2020, has been preparing open-source communities for the EU Cyber Resilience Act's first enforcement date, 11 September 2026.

Last refreshed: 22 September 2026 · Appears in 1 active topic

Timeline for Open Source Security Foundation

#16 11 Sept

Prepared open-source communities for the CRA reporting deadline

European Tech Sovereignty: Cyber Resilience Act starts its clock
View full timeline →

Background

The Open Source Security Foundation (OpenSSF) is a cross-industry initiative formed by the Linux Foundation in August 2020 to improve software supply-chain security. Founding governing board members included GitHub, Google, IBM, JPMorgan Chase, Microsoft and Red Hat, and membership has since grown to well over 100 organisations.

OpenSSF is hosted by the Linux Foundation, a US-based body, not a European one, which matters in a European tech sovereignty context: an organisation coordinating supply-chain security for European regulation sits, structurally, outside Europe. It works alongside Linux Foundation Europe on compliance-facing work such as CRA preparation, drawing on the wider Linux Foundation's cross-industry membership rather than a Europe-only base.

Key Issues
Cyber Resilience Act

It readies open source for the CRA

The EU's Cyber Resilience Act began enforcing on 11 September 2026, giving manufacturers a 24-hour duty to report actively exploited vulnerabilities or risk fines of up to €15 million. The Open Source Security Foundation and Linux Foundation Europe spent months preparing open-source communities for that Deadline.

The duty lands on the commercial vendor selling a product, not on the open-source code inside it, so what the CRA requires of open-source maintainers themselves remains unsettled; full application of the Act follows in December 2027.

Common Questions
What is the Open Source Security Foundation?
The Open Source Security Foundation (OpenSSF) is a Linux Foundation initiative, formed in 2020, that coordinates open-source software supply-chain security work across member companies.
How is OpenSSF connected to the Cyber Resilience Act?
OpenSSF and Linux Foundation Europe have been preparing open-source communities for the EU Cyber Resilience Act's 11 September 2026 enforcement date, which requires reporting actively exploited vulnerabilities within 24 hours.
Source Material