In this episode of What's in the SOSS, host Sally Cooper sits down with returning champion Dave Russo, Policy and Standards Lead at Red Hat’s Open Source and AI Program Office, to unpack the European Union’s Cyber Resilience Act (CRA). Together, they explore the stark realities of the 2026 CRA Awareness and Readiness Report, exposing why three-quarters of North American tech companies remain completely unaware of the strictest cybersecurity mandate in history. Dave breaks down the hidden $250,000-per-release financial toll of maintaining private forks, the crucial legal distinction between software manufacturers and open source stewards, and Red Hat's framework for "champion stewardship." Whether you are facing the upcoming September 2026 vulnerability reporting platform launch or preparing for full December 2027 enforcement, this conversation delivers clear, actionable guidance to get your organization compliant, collaborative, and secure. 

Chapters:

  • 00:25 - Welcome & Introductions
  • 01:28 - Meet Dave Russo
  • 02:01 - The Global CRA Awareness Gap
  • 04:46 - The Hidden Cost of Private Forks
  • 07:32 - Manufacturer vs. Open Source Steward
  • 09:09 - Red Hat's Light vs. Champion Stewardship
  • 11:37 - Crucial CRA Deadlines Explained
  • 13:51 - Actionable Compliance Steps Today
  • 16:47 - Rapid Fire Fun

Episode links:

Podden och tillhörande omslagsbild på den här sidan tillhör OpenSSF. Innehållet i podden är skapat av OpenSSF och inte av, eller tillsammans med, Poddtoppen.