Open source software faces significant regulatory shifts, making "secure by design" development practices increasingly important. The Cyber Resilience Act (CRA) takes effect on December 11, 2027, and as of September 11, 2026, the first CRA vulnerability and incident reporting obligations were live. These new cybersecurity regulations impact all companies that sell software or hardware to the European market and will have a huge impact on open source as a whole. Despite the looming deadline, the software industry remains unprepared.
According to The Linux Foundation’s 2026 CRA Awareness and Readiness Report , 66% of companies remain unfamiliar with the CRA and only 41% expect to be fully compliant by December 2027. The CRA regulates products with digital elements placed on the EU market, and open source software underpins most modern software products including cloud infrastructure, operating systems, and AI frameworks. According to the 2026 Open Source Security and Risk Analysis Report , it’s estimated that over 97% of the code in most codebases comes from open source.
As a result, it's important that organizations understand how they are dependent on open source software. Organizations who are impacted by the CRA must first understand the software being used in their products. They need to identify known vulnerabilities, assess potential risk, respond to incidents, and communicate information across their software supply chain. Under the CRA, manufacturers must collaborate with open source communities, with specific mandates to disclose vulnerabilities and share fixes developed upstream.
While the CRA doesn't prohibit private forks of software, there is now a cost of carrying divergence, as the related security risks of doing so are inherently higher. Additionally, organizations that choose to maintain private forks of software will face increased labor costs, upward of $258,000 based on The Linux Foundation’s 2026 CRA Awareness and Readiness Report . Participating in upstream community development will not only become the more secure path toward CRA compliance, but also the more economical one.
