Open Source

OpenSSF Adds Four Members, Releases CRA Compliance Resources at Prague Community Day

The Open Source Security Foundation announced new organizational members and published guidance on the EU's Cyber Resilience Act as regulatory pressure mounts on software vendors.

5 min read

At its Community Day Europe gathering in Prague on October 6, 2026, the Open Source Security Foundation—a Linux Foundation initiative dedicated to strengthening the security posture of open source software—unveiled expanded membership alongside fresh resources addressing compliance with emerging regulations. A-Team Systems, Emphere, DACHS IT GMBH, and JetBrains have joined as General Members, bringing their expertise to the Foundation's working groups and technical initiatives.

The Foundation simultaneously released materials to help the industry navigate the EU's Cyber Resilience Act (CRA), which entered a critical enforcement phase last month with mandatory vulnerability and incident reporting requirements now legally binding. As artificial intelligence accelerates the pace of vulnerability discovery and shrinks reporting timelines, OpenSSF has positioned itself as a neutral resource for guidance, collaboration, and security education across jurisdictions.

Steve Fernandez, General Manager of OpenSSF, characterized the moment as a turning point for the field: "Securing the open source ecosystem is no longer just about patching isolated vulnerabilities. It requires proactive, systemic collaboration across the entire industry. Initiatives like the Open Secure AI Alliance and pioneering projects such as Akrites reflect this critical shift. We are moving beyond fragmented defenses and building a unified front, equipping the global developer community with the comprehensive frameworks needed to secure the next generation of software. OpenSSF and our members are a key element in this shift."

New Members and Their Commitment

The four new General Members bring complementary perspectives to the Foundation's mission. Adam Strohl, President of A-Team Systems, emphasized the organization's long operational history: "Open source software has been central to our work supporting Linux and FreeBSD systems in critical production environments for more than two decades. We depend on the security work happening throughout the open source ecosystem. OpenSSF provides part of the foundation that makes secure, reliable production operations possible. Joining OpenSSF reflects our commitment to materially supporting the people who make open source what it is today. We look forward to contributing an infrastructure operations perspective and supporting the important work OpenSSF is doing across the open source community."

Alexander Schaber, Founder and CEO of DACHS IT GMBH, framed membership as a response to shared dependency: "Virtually every critical enterprise builds on an open source foundation. When everyone relies on the digital common ground, maintaining its safety is a shared responsibility. Securing the supply chain helps ensure that open-source software remains safe, trusted, and open for everyone. Through our continuous work in the Linux Foundation and CNCF, we've helped build cloud-native ecosystems. Now, through OpenSSF, we're expanding our work to help protect and nurture the security foundation they rely on."

Emphere's statement was concise: "Open source is shared code, and so is the responsibility to secure it. Emphere is glad to join OpenSSF to help the community outpatch attackers, human and AI alike."

Katherine Druckman, Head of Community and Partnership Engagement at JetBrains, connected the company's developer-focused mission to the Foundation's work: "Software development is at an inflection point. AI is changing how software is built and creating new security challenges, making it more important than ever that developers can understand, verify and trust the software they produce. JetBrains has supported professional software development for more than two decades, and we believe staying ahead of these challenges is best done collaboratively and in the open. OpenSSF brings together some of the strongest expertise in the industry, and we are glad to join the community and help shape the future of secure software development."

Third-Quarter Milestones

Beyond membership expansion, OpenSSF marked several significant achievements during the third quarter of 2026:

  • The Foundation published a CRA Readiness practitioner's guide translating regulatory requirements into concrete compliance steps for maintainers and vendors, alongside a User Journey document to support organizations at any stage of preparedness.
  • Ericsson Software Technology contributed a case study demonstrating enterprise-scale upstream security work: the company eliminated internal code forks and contributed over 1,400 dependency updates and security fixes upstream to meet CRA obligations, validating the principle of fixing vulnerabilities at their source rather than in isolated branches.
  • OpenSSF introduced role-based User Journeys tailored for developers, security engineers, OSPO leaders, marketers, and executives, directing each audience to relevant guidance and resources.
  • OpenBao, the open source secrets management tool, reached version 2.6 with per-namespace sealing and a new workflow engine enabling cross-plugin communication.
  • BOMHort, a Kubernetes-native tool for SBOM visualization and governance, entered the OpenSSF Sandbox as SBOMs transition from best practice to regulatory mandate under the CRA, NIST SSDF, and Executive Order 14028.

Upcoming Events and Engagement

OpenSSF members are convening this week in Prague for Community Day Europe, with a dedicated workshop on operationalizing the Cyber Resilience Act scheduled for Friday, October 9. The Foundation will continue its presence at AGNTCon + MCPCon North America in San Jose, California on October 22–23, and at Open Source SecurityCon North America in Salt Lake City, Utah on November 9.

Organizations and individuals interested in participating can view the complete membership roster, contribute to active working groups and projects, or subscribe to the OpenSSF newsletter for updates on events, resources, and community developments.

About the Organizations

The Open Source Security Foundation is a cross-industry organization within the Linux Foundation that consolidates the industry's most significant open source security initiatives and the people and companies supporting them. The Foundation prioritizes upstream collaboration and engagement with established communities to advance open source security globally. More information is available at openssf.org.

The Linux Foundation serves as the world's primary hub for collaboration on open source software, hardware, standards, and data. Its projects—including Linux, Kubernetes, Model Context Protocol (MCP), OpenChain, OpenSearch, OpenSSF, OpenStack, PyTorch, Ray, RISC-V, SPDX, and Zephyr—underpin global infrastructure. The organization emphasizes sustainable collaboration models that serve contributors, users, and solution providers. Details are available at linuxfoundation.org.

Source: OpenSSF · Reporting supplemented by The Silicon Ledger staff.