CRA Guidance for Linux Foundation Projects

Effective September 11, 2026, the EU Cyber Resilience Act (CRA) requires Open Source Software (OSS) Stewards to report actively exploited vulnerabilities and severe security incidents impacting digital products sold in the EU market (to the extent they are involved in product development).

Why This Matters

Under the CRA, OSS Stewards (foundations and entities governing open source projects) must adhere to strict reporting timelines—including an early warning within 24 hours of becoming aware of an actively exploited vulnerability, followed by a formal notification within 72 hours.

The Linux Foundation is handling this for you. LF’s project-hosting legal entities will act as the CRA stewards for the projects they host. They will be registered on the ENISA’s single reporting platform, they know the deadlines, and they file the regulatory reports. Your project does not need to build its own EU CRA regulatory compliance function.

What do Academy Software Foundation hosted projects need to do

  1. Document whether your software is ultimately intended for commercial activities (most widely-used LF open source software projects are). If your project does not publish software, the CRA is not relevant to your project.
  2. Add a short CRA stewardship statement to your SECURITY.md or similar public-facing security process document. A template to use is below.

     CRA stewardship: This project is supported under the Linux Foundation CRA
     stewardship framework, as described at https://www.linuxfoundation.org/security.
     Security vulnerabilities should be reported through the mechanisms described
     below, which we will coordinate with our CRA steward. For actively exploited
     vulnerabilities and severe incidents that may require CRA escalation, please use
     the project’s emergency security reporting mechanisms as appropriate.
    
  3. Know the escalation rule: if you learn of an actively exploited vulnerability or a severe incident (for example, compromise of your release process), notify your LF steward’s CRA contact immediately ( steward@linuxfoundation.org ), while you fix the problem, never instead of fixing it.

Resources

Thank you for helping keep open source software secure and compliant.