7-9 October, 2026 Prague, Czechia View More Details & Registration Important Note:Timing of sessions and room locations are subject to change.
The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for Open Source Summit Europe 2026 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.
Sign up or log in to add sessions to your schedule and sync them to your phone or calendar.
The EU CRA is now law, yet confusion persists across the software ecosystem. Many developers still fear personal liability for upstream contributions, while organizations struggle to understand what compliance actually requires. This talk clarifies the four CRA compliance pathways: Self-Assessment, Standards, 3rd party Conformity Assessment, and the EUCC, and explains how they apply across the software supply chain.
We demystify the CRA’s approach to open source, focusing on OSS stewards such as foundations and legal entities, and their limited obligations compared to manufacturers. A key message: upstream contributors and individual maintainers have no direct CRA compliance responsibilities. We also examine supply chain security implications, including the need for stronger upstream-downstream collaboration, better dependency transparency, and clearer security ownership at integration points. Misinterpretation of CRA roles risks shifting compliance burden incorrectly upstream, undermining ecosystem resilience. Attendees will leave with a clear understanding of CRA responsibility boundaries, compliance routes, and the role of open source in a secure European software supply chain.