Loading…
7-9 October, 2026
Prague, Czechia
View More Details & Registration
Important Note: Timing of sessions and room locations are subject to change.

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for Open Source Summit Europe 2026 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.



Friday October 9, 2026 16:30 - 17:10 CEST
The enforcement window for the EU Cyber Resilience Act (CRA) is arriving, triggering corporate compliance panic. While individual open-source developers and volunteer maintainers have zero obligations under the CRA, their downstream commercial adopters face mandatory due diligence requirements. How do Maintainers survive being bombarded with manual security questionnaires and subtle attempts to shift regulatory liability upstream?

The co-chair of the OpenSSF Global Cyber Policy Working Group and co-creator of the CRA Readiness Guide for Maintainers will walk you through converting the OpenSSF voluntary checklist into automated repository-level defenses. Attendees will see how to deploy the open-source OSPS Baseline Scanner GitHub Action to perform security gap analysis, expose standardized project postures via machine-readable security-insights.yaml files, and anchor liability disclaimers into repositories to push due-diligence burdens back downstream.
Speakers
avatar for Roman Zhukov

Roman Zhukov

Security Community Lead, Red Hat
Roman is a cybersecurity expert with 20+ years of experience securing complex systems and products. As Principal Architect at Red Hat, he drives open-source security strategy and cross-industry collaboration to build trusted software ecosystems. Formerly, he led Product Security... Read More →
Friday October 9, 2026 16:30 - 17:10 CEST
Conference Hall (Floor 4)

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link