Loading…
7-9 October, 2026
Prague, Czechia
View More Details & Registration
Important Note: Timing of sessions and room locations are subject to change.

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for Open Source Summit Europe 2026 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.



Friday October 9, 2026 12:45 - 14:00 CEST
As of Sept 11, 2026, the EU CRA mandates short-window reporting for actively exploited vulnerabilities to ENISA. Yet, Linux Foundation research shows 66% of the ecosystem remains unprepared. Hosted by the OpenSSF Global Cyber Policy WG, this 75-minute interactive workshop shifts the conversation from abstract legal theory to operational realities many of us are currently facing.

Following a 10-minute briefing, small groups will stress-test real-world CRA challenges in a community-feedback-inspired session that unites enterprise engineers, security officers, stewards, open source developers. Topics include: governance, open source particularities and CRA personas across varying PDE classifications, secure-by-design mandates, risk assessments, due diligence, SBOMs, vulnerability management and reporting obligations. We conclude with a synthesis of mapping live insights directly to the OpenSSF roadmap and our work group activities for the upcoming quarters.

Come to CRA it and lunch together! Whether you are an enterprise architect trying to keep your product compliant, a steward, or an upstream developer, this workshop offers to tackle your specific use cases.
Speakers
avatar for Dan Appelquist

Dan Appelquist

Open Source Strategist, Samsung
Dan Appelquist is Open Source Strategist at Samsung Open Source Group. He is a web & mobile industry veteran and long-time participant and leader in open source and open standards. He is co-chair of the OpenSSF Global Cyber Policy working group and also has been a member of the OpenSSF's... Read More →
avatar for Megan Knight

Megan Knight

Director Software Communities, Arm
Megan Knight is the Director of Software Communities at Arm where she leads upstream engagements with open source communities. She holds many leadership positions with various communities including Advocacy Chair for the Yocto Project, OSPO Special Interest Group lead for UXL Foundation... Read More →
RZ

Roman Zhukov

Principal Architect - Security Communities Lead, Red Hat
avatar for Madalin Neag

Madalin Neag

EU Policy Advisor, The Linux Foundation

Friday October 9, 2026 12:45 - 14:00 CEST
Chamber Hall (Floor 3)

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link