Uploaded August 2026 | Updated September 2026, 4 hours ago
Cyber Resilience Act (CRA) and Stewardship
This is an auto-generated summary of the FRCL call on 2026-03-25:
The EU Cyber Resilience Act was presented, detailing its scope, compliance timeline, and implications for both commercial and non-profit open source entities.
CRA Scope and Obligations
The EU Cyber Resilience Act is an EU-wide regulation defining cybersecurity requirements for digital products, with compliance for vulnerability reporting starting in September 2026. This law distinguishes between “manufacturers” who monetize software and “open source software stewards” who provide sustained support.
Red Hat's Stewardship Approach
Red Hat, defined as a manufacturer for RHEL and a steward for projects like Fedora and CentOS, is developing a two-tiered stewardship model to meet CRA obligations. Steward obligations include implementing cybersecurity policies, encouraging vulnerability reporting, and cooperating with member state authorities to avoid unnecessary burden on FOSS projects.
Blurry Line to Manufacturer
A debate focused on the blurry line between steward and manufacturer, particularly concerning Red Hat’s sustained support activities for Fedora, like producing compliance documentation for OEMs. The primary point of concern for FESCO members was commercial adjacent activity involving non-Red Hat organizations, which could potentially trigger manufacturer obligations.
Jira Epic: redhat.atlassian.net/browse/FRCL-27
Gemini AI Summary: docs.google.com/document/d/1sAo49AKPkAIHiYhi2hsO6p9nsYjgMaQtQpzOaOzHOow/edit?usp=meet_tnfm_calendar
Cyber Resilience Act (CRA) and Stewardship
This is an auto-generated summary of the FRCL call on 2026-03-25:
The EU Cyber Resilience Act was presented, detailing its scope, compliance timeline, and implications for both commercial and non-profit open source entities.
CRA Scope and Obligations
The EU Cyber Resilience Act is an EU-wide regulation defining cybersecurity requirements for digital products, with compliance for vulnerability reporting starting in September 2026. This law distinguishes between “manufacturers” who monetize software and “open source software stewards” who provide sustained support.
Red Hat's Stewardship Approach
Red Hat, defined as a manufacturer for RHEL and a steward for projects like Fedora and CentOS, is developing a two-tiered stewardship model to meet CRA obligations. Steward obligations include implementing cybersecurity policies, encouraging vulnerability reporting, and cooperating with member state authorities to avoid unnecessary burden on FOSS projects.
Blurry Line to Manufacturer
A debate focused on the blurry line between steward and manufacturer, particularly concerning Red Hat’s sustained support activities for Fedora, like producing compliance documentation for OEMs. The primary point of concern for FESCO members was commercial adjacent activity involving non-Red Hat organizations, which could potentially trigger manufacturer obligations.
Jira Epic: redhat.atlassian.net/browse/FRCL-27
Gemini AI Summary: docs.google.com/document/d/1sAo49AKPkAIHiYhi2hsO6p9nsYjgMaQtQpzOaOzHOow/edit?usp=meet_tnfm_calendar










