The clock is ticking toward the European Union’s Cyber Resilience Act (CRA) deadlines, yet a staggering 66% of organizations remain completely unaware of what is coming. In this episode of What’s in the SOSS? host Sally sits down with Roman Zhukov, co-chair of the OpenSSF Global Cyber Policy Working Group and Security Communities Lead at Red Hat, to demystify this sweeping regulation. Using a brilliant "community garden" analogy, Roman breaks down the distinct roles of maintainers, stewards, and manufacturers under the law, illustrating why the traditional "consume and forget" model of open source is officially dead. They dive deep into the newly released 2026 CRA Awareness and Readiness Report, exposing the staggering $250,000+ engineering tax of maintaining private forks and detailing how active upstream collaboration is no longer just good citizenship—it’s a business and legal necessity. Tune in to discover actionable strategies, free educational resources, and how we can collectively bake "compliance as code" into the open source ecosystem. 

Chapters:

  • 00:01 – Introduction: The CRA Countdown is On
  • 02:04 – Tomatoes, Gardens, and Restaurants: Defining the CRA Personas
  • 06:40 – Reality Check: Shocking Findings from the 2026 Readiness Report
  • 10:12 – The Awareness Gap: Why Are We Ignoring the Warning Signs?
  • 15:01 – The End of "Consume and Forget"
  • 17:49 – The Private Fork Tax: A $250K Engineering Trap
  • 23:34 – Red Hat’s Blueprint & Free Community Security Tools
  • 28:44 – Taming the AI Vulnerability Tsunami
  • 31:27 – Build Your Program Now: Action Steps for Manufacturers
  • 36:12 – Supporting SMEs & Navigating Free Resources
  • 40:30 – Carrying the Torch as an OpenSSF Ambassador
  • 43:35 – Rapid Fire & How to Get Involved

Episode links:

Podden och tillhörande omslagsbild på den här sidan tillhör OpenSSF. Innehållet i podden är skapat av OpenSSF och inte av, eller tillsammans med, Poddtoppen.