Close Menu
UK Daily: Tech, Science, Business & Lifestyle News UpdatesUK Daily: Tech, Science, Business & Lifestyle News Updates
    What's Hot

    How to avoid bad hires in early-stage startups

    February 26, 2026

    Italian Pear Cookies – The Petite Cook™

    February 26, 2026

    Instagram now alerts parents if their teen searches for suicide or self-harm content

    February 26, 2026
    Facebook X (Twitter) Instagram
    Trending
    • How to avoid bad hires in early-stage startups
    • Italian Pear Cookies – The Petite Cook™
    • Instagram now alerts parents if their teen searches for suicide or self-harm content
    • Brits push down house prices to dodge mansion tax
    • Man’s body found in Irvine as death treated as unexplained
    • Inquest date set for man who ‘died a hero’ in River Lagan incident
    • Water outages in Lamberhurst and Horsmonden due to ‘technical issue’ at South East Water treatment works
    • Kalshi fined a MrBeast editor for insider trading on markets related to the YouTube star
    • London
    • Kent
    • Glasgow
    • Cardiff
    • Belfast
    Facebook X (Twitter) Instagram YouTube
    UK Daily: Tech, Science, Business & Lifestyle News UpdatesUK Daily: Tech, Science, Business & Lifestyle News Updates
    Subscribe
    Thursday, February 26
    • Home
    • News
      1. Kent
      2. London
      3. Belfast
      4. Birmingham
      5. Cardiff
      6. Edinburgh
      7. Glasgow
      8. Liverpool
      9. Manchester
      10. Newcastle
      11. Nottingham
      12. Sheffield
      13. West Yorkshire
      Featured

      ‘Miniature’ mountain creature with ‘squeaker’-like call discovered as new species

      Science November 9, 2023
      Recent

      How to avoid bad hires in early-stage startups

      February 26, 2026

      Instagram now alerts parents if their teen searches for suicide or self-harm content

      February 26, 2026

      Brits push down house prices to dodge mansion tax

      February 26, 2026
    • Lifestyle
      1. Celebrity
      2. Fashion
      3. Food
      4. Leisure
      5. Social Good
      6. Trending
      7. Wellness
      8. Event
      Featured

      Italian Pear Cookies – The Petite Cook™

      Food February 26, 2026
      Recent

      Italian Pear Cookies – The Petite Cook™

      February 26, 2026

      BLUES BABY

      February 26, 2026

      How Much Money the Actor & Comedian Has – Hollywood Life

      February 26, 2026
    • Science
    • Business
    • Sports

      Gillingham boss Gareth Ainsworth has said he will make changes to his squad for the League Two trip to Barrow but who comes in?

      February 26, 2026

      Barry Goodwin’s best images from the 2026 Dartford Half-Marathon

      February 26, 2026

      Joe Dunne returns to Colchester United as under-18 lead coach after quitting his role as Gillingham youth manager

      February 24, 2026

      Gillingham boss Gareth Ainsworth with work to do this week to restore confidence ahead of trip to Barrow

      February 24, 2026

      Gillingham striker Marcus Wyllie moves to National South side Ebbsfleet United on loan

      February 23, 2026
    • Politics
    • Tech
    • Property
    • Press Release
    UK Daily: Tech, Science, Business & Lifestyle News UpdatesUK Daily: Tech, Science, Business & Lifestyle News Updates
    Home » Open source foundations unite on common standards for EU’s Cyber Resilience Act

    Open source foundations unite on common standards for EU’s Cyber Resilience Act

    bibhutiBy bibhutiApril 3, 2024 Tech No Comments4 Mins Read
    Facebook Twitter LinkedIn WhatsApp Telegram
    Share
    Facebook Twitter LinkedIn Telegram WhatsApp


    Seven open source foundations are coming together to create common specifications and standards for Europe’s Cyber Resilience Act (CRA), regulation adopted by the European Parliament last month.

    The Apache Software Foundation, Blender Foundation, Eclipse Foundation, OpenSSL Software Foundation, PHP Foundation, Python Software Foundation, and Rust Foundation revealed their intentions to pool their collective resources and connect the dots between existing security best practices in open source software development — and ensure that the much-maligned software supply chain is up to the task when the new legislation comes into force in three years.

    Componentry

    It’s estimated that between 70% and 90% of software today is made up of open source components, many of which are developed for free by programmers in their own time and on their own dime.

    The Cyber Resilience Act was first unveiled in draft form nearly two years ago, with a view toward codifying best cybersecurity practices for both hardware and software products sold across the European Union. It’s designed to force all manufacturers of any internet-connected product to stay up-to-date with all the latest patches and security updates, with penalties in place for shortcomings.

    These noncompliance penalties include fines of up to €15 million, or 2.5% of global turnover.

    The legislation in its initial guise prompted fierce criticism from numerous third-party bodies, including more than a dozen open source industry bodies that last year wrote an open letter saying that the Act could have a “chilling effect” on software development. The crux of the complaints centered on how “upstream” open source developers might be held liable for security defects in downstream products, thus deterring volunteer project maintainers from working on critical components for fear of legal retribution (this is similar to concerns that abounded around the EU AI Act, which was greenlighted last month).

    The wording within the CRA regulation did offer some protections for the open source realm, insofar as developers not concerned with commercializing their work were technically exempt. However, the language was open to interpretation in terms of what exactly fell under the “commercial activity” banner — would sponsorships, grants, and other forms of financial assistance count, for example?

    Some changes to the text were eventually made, and the revised legislation substantively addressed the concerns through clarifying open source project exclusions.

    Although the new regulation has already been rubber stamped, it won’t come into force until 2027, giving all parties time to meet the requirements and iron out some of the finer details of what’s expected of them. And this is what the seven open source foundations are coming together for now.

    Documentation

    The manner in which many open source projects evolve has meant that they often have patchy documentation (if any at all), which makes it difficult to support audits and makes it difficult for downstream manufacturers and developers to develop their own CRA processes.

    Many of the better-resourced open source initiatives already have decent best practice standards in place, relating to things like coordinated vulnerability disclosures and peer review, but each entity might use different methodologies and terminologies. By coming together as one, this should go some way toward treating open source software development as a single “thing” bound by the same standards and processes.

    Throw into the mix other proposed regulation, including the Securing Open Source Software Act in the U.S., and it’s clear that the various foundations and “open source stewards” will come under greater scrutiny for their role in the software supply chain.

    “While open source communities and foundations generally adhere to and have historically established industry best practices around security, their approaches often lack alignment and comprehensive documentation,” the Eclipse Foundation wrote in a blog post today. “The open source community and the broader software industry now share a common challenge: legislation has introduced an urgent need for cybersecurity process standards.”

    The new collaboration, while consisting of seven foundations initially, will be spearheaded in Brussels by the Eclipse Foundation, which is home to hundreds of individual open source projects spanning developer tools, frameworks, specifications, and more. Members of the foundation include Huawei, IBM, Microsoft, Red Hat and Oracle.



    Source link

    Featured Just In Top News
    Share. Facebook Twitter LinkedIn Email
    Previous Article4th annual Sustainability Week US: Uniting businesses to shape climate solutions
    Next Article Stablecoin Issuer Tether Completes SOC 2 Type 1 Audit
    bibhuti
    • Website

    Keep Reading

    How to avoid bad hires in early-stage startups

    Italian Pear Cookies – The Petite Cook™

    Instagram now alerts parents if their teen searches for suicide or self-harm content

    Brits push down house prices to dodge mansion tax

    Man’s body found in Irvine as death treated as unexplained

    Inquest date set for man who ‘died a hero’ in River Lagan incident

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    89th Utkala Dibasa Celebration Brings Odisha’s Vibrant Culture to London

    April 8, 2024

    US and EU pledge to foster connections to enhance research on AI safety and risk.

    April 5, 2024

    Holi Celebrations Across Various Locations in Kent Attract a Diverse Range of Community Participation

    March 25, 2024

    Plans for new Bromley tower blocks up to 14-storeys tall refused

    December 4, 2023
    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement

    Recent Posts

    • How to avoid bad hires in early-stage startups
    • Italian Pear Cookies – The Petite Cook™
    • Instagram now alerts parents if their teen searches for suicide or self-harm content
    • Brits push down house prices to dodge mansion tax
    • Man’s body found in Irvine as death treated as unexplained

    Recent Comments

    1. Register on Anycubic users say their 3D printers were hacked to warn of a security flaw
    2. Pembuatan Akun Binance on Braiins Becomes First Mining Pool To Introduce Lightning Payouts
    3. tadalafil tablets sale on The market is forcing cloud vendors to relax data egress fees
    4. cerebrozen reviews on Kent director of cricket Simon Cook adapting to his new role during the close season
    5. Glycogen Review on The little-known town just 5 miles from Kent border with stunning beaches and only 600 residents
    The News Times Logo
    Facebook X (Twitter) Pinterest Vimeo WhatsApp TikTok Instagram

    News

    • UK News
    • US Politics
    • EU Politics
    • Business
    • Opinions
    • Connections
    • Science

    Company

    • Information
    • Advertising
    • Classified Ads
    • Contact Info
    • Do Not Sell Data
    • GDPR Policy
    • Media Kits

    Services

    • Subscriptions
    • Customer Support
    • Bulk Packages
    • Newsletters
    • Sponsored News
    • Work With Us

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    © 2026 The News Times. Designed by The News Times.
    • Privacy Policy
    • Terms
    • Accessibility

    Type above and press Enter to search. Press Esc to cancel.

    Manage Cookie Consent
    To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}