Security

Secure by Design? Discussion on Voluntary Security Attestations

Session Abstract

With this discussion following the Chatham House Rule format, we wish to invite FOSS Backstage attendees to come together to explore how communities could issue risk-based attestations sufficient to reduce downstream compliance burdens in ways that support (rather than burden) open source communities.

Session Description

The Cyber Resilience Act creates a transformative opportunity to strengthen both cybersecurity and the sustainability of open source through Article 25’s voluntary security attestation framework.

We will examine practical implementation questions:
– How do we balance proportional requirements with project maturity?
– What governance models work for stewardship, as defined by the CRA?
– How can attestations create sustainable funding flows to upstream communities without capture by commercial interests?

Your perspective will help determine whether this framework becomes a tool for sustainability or part of a regulatory barrier to open collaboration.

This session is an interactive session taking place under Chatham House Rules and therefore not recorded.

Wintergarten
16.Mar 2026
16:40pm - 17:10pm
Workshop
Æva Black
Æva Black

Null Point Studio

Gregor “Little Detritus” Bransky
Gregor “Little Detritus” Bransky

Innovationsverbund Öffentliche Gesundheit e.V.