Secure by Design? Discussion on Voluntary Security Attestations
Session Abstract
With this discussion following the Chatham House Rule format, we wish to invite FOSS Backstage attendees to come together to explore how communities could issue risk-based attestations sufficient to reduce downstream compliance burdens in ways that support (rather than burden) open source communities.
Session Description
The Cyber Resilience Act creates a transformative opportunity to strengthen both cybersecurity and the sustainability of open source through Article 25’s voluntary security attestation framework.
We will examine practical implementation questions:
– How do we balance proportional requirements with project maturity?
– What governance models work for stewardship, as defined by the CRA?
– How can attestations create sustainable funding flows to upstream communities without capture by commercial interests?
Your perspective will help determine whether this framework becomes a tool for sustainability or part of a regulatory barrier to open collaboration.
This session is an interactive session taking place under Chatham House Rules and therefore not recorded.
Workshop
Æva Black
Null Point Studio
Gregor “Little Detritus” Bransky
Innovationsverbund Öffentliche Gesundheit e.V.