Public Policy
This is a list of materials (documents, services, and so on) released by the Open Source Security Foundation (OpenSSF) Global Cyber Policy Working Group (WG).
OpenSSF Policy Resources
European Union Cyber Resilience Act (CRA)
CRA Updates
- OpenSSF CRA Blog
- European Commission CRA Implementation Website
- European Commission CRA Guidance
- European Commission CRA FAQ
- CRA Experts Group
- OpenSSF Presentations
Stewards Guidance
Standards
- CRA Standards Map
- Standardization Special Interest Group Updates
- ESOs Overview
- OpenSSF Feedback on Draft Standards
For Maintainers
Checklists
- CRA Reporting obligations for Manufacturers - Resource Guide
- CRA Reporting obligations for Stewards - Resource Guide
- PSIRT Obligations Checklist
EU Authorities
- Market Surveillance Authorities (MSA)
- Administrative Cooperation Groups (AdCos)
- Conformity Assessment Bodies
- Market Surveillance (ICSMS)
- Notified Bodies
Additional Links
- ENISA Single Reporting Platform
- CSIRTs Network
- Implementing regulation (EU) 2025/2392: Technical description of the categories of important and critical products with digital elements
- Delegated act on terms and conditions for CSIRTs: Specifies the terms and conditions for applying the cybersecurity-related grounds in relation to delaying the dissemination of notifications
- ENISA Secure by Design and Default Playbook
- CRA Timeline
Contributing
We typically use the Simplest Possible Process (SPP) to publish our results on the web.
Please join the OpenSSF Global Cyber Policy Working Group if you’re interested in helping!
Please also see the main OpenSSF website to learn more about the OpenSSF.