Does accepting corporate donations or charging for documentation drag an open source project into full CRA commercial compliance? Under the Cyber Resilience Act, the line between an exempt open source project and a regulated commercial product hinges entirely on the phrase "intention to monetise." It is a complex legal area that requires precise delineation. According to the latest guidance from the European Commission: 🔹 Providing a software product for a fee or offering paid support directly tied to that specific product indicates an intention to monetise. 🔹 Charging for educational courses, general documentation, or accepting non-binding philanthropic donations generally does NOT trigger commercial status. 🔹 Sponsorship from commercial enterprises that directly control development paths may alter compliance requirements. 👉 Review community-curated guidance on monetisation: https://hubs.la/Q04lHKnz0 #LegalCompliance #OpenSourceMonetization #SaaS #TechPolicy #CRAHub
Open Regulatory Compliance
Software Development
Leading Regulatory Compliance for Open Source
About us
Through open collaboration, ORC brings together industry experts and open source leaders to develop best practices, tools, and guidance to support the continued use and advancement of open source throughout the software supply chain. 🔐 Our current priority is helping open source projects and organizations prepare for the European Union’s Cyber Resilience Act (CRA). We're focused on building community-driven resources that support compliance while safeguarding the unique nature of open source development. Follow us to stay up to date on new initiatives, working group updates, and key policy developments impacting open source.
- Website
-
https://orcwg.org/
External link for Open Regulatory Compliance
- Industry
- Software Development
- Company size
- 51-200 employees
- Founded
- 2024
- Specialties
- Open Source Compliance, Cybersecurity, Software Supply Chain Security, Cyber Resilience Act, Open Source Stewards, Community-driven best practices, Open source governance, Vulnerability reporting, Risk-based security, Regulatory alignment, Manufacturer compliance, and Open source maintainers
Updates
-
The Open Regulatory Compliance Working Group wants you! 🔥 GitHub: This is where the real action lives. Check the GitHub repository and contribute. 📬 Mailing list: Informal conversations to stay up to speed. 🧑🤝🧑 Become a member: Individuals and organisations are welcome. Review the Charter, then contact us. 🎙️ Bonus: working group calls, community calendar, and free webinars that discuss CRA implementation. Get involved: https://hubs.la/Q03_5Hwj0 #opensource #community #compliance #CRA #ORCWG
-
-
Open Regulatory Compliance reposted this
With the EU Cyber Resilience Act (#CRA) reporting requirements kicking off this September, moving from policy theory to operational reality is no longer optional but an urgent priority across the entire software and hardware supply chain. About this and other CRA aspects I'll be speaking with Laure Pourcin, Giovanni Corti, Rose-Viviane Jupiter Vannel and Roman Zhukov at the Global Digital Collaboration Conference #GDC26 in Geneva! 🗓 Date: September 2, 14:00 🎤 Session: Operationalising the Cyber Resilience Act: What manufacturers, Open Source stewards and security teams need now. 🎟️ If you are interested in attending, the Eclipse Foundation is a co-organiser of the event and you can get your ticket here --> https://luma.com/avxq2n1g ℹ More info about the event: https://lnkd.in/eS_DFVej/ Open Regulatory Compliance
-
-
Cyber Resilience Act (CRA) readiness isn't only about your software. If you're a manufacturer, engineering leader, security professional, maintainer, or Open Source Program Office (OSPO) leader, understanding your software supply chain is becoming increasingly important before additional CRA obligations take effect on 11 December 2027. Learn how Software Bills of Materials (SBOMs), vulnerability management, and due diligence support CRA readiness on the new ORC Learning Hub. Access the free training today: https://hubs.la/Q04n6VhY0 #SoftwareSupplyChain #SBOM #CyberResilienceAct
-
-
🏛 Code & Compliance 2026 brings together manufacturers, industry associations, OSPOs, policymakers and legal teams to explore practical strategies for developing compliant products, navigating evolving EU regulatory frameworks like the Cyber Resilience Act and the AI Act, and fostering cross-sector collaboration. Join us on 27 October in Brussels: https://hubs.la/Q04qkw7L0 More information: https://hubs.la/Q04qknFf0 #CodeCompliance #opensource #CyberResilienceAct #AIAct
-
-
Not all software faces the same compliance pathway under the CRA. Do you know if your product falls into a "Critical" category? The Cyber Resilience Act applies a risk-based approach to product regulation. While the vast majority of standard software falls under the Default compliance tier (requiring self-assessment), high-risk items face strict, independent validation pathways. The classification breaks down as follows: 📦 Default Products: Require internal control-based self-assessments to confirm compliance. 🔐 Important Products (Class A & B): Cover critical infrastructure, operating systems, routers, and password managers, requiring specific standard alignments. ⚡ Critical Products: Involve highly sensitive security infrastructure that may require third-party conformity audits. Knowing your exact product category dictates your testing budget and engineering roadmap. 👉 Map your software to the correct risk tier using our guide: https://hubs.la/Q04tYNcF0 #ProductManagement #SoftwareArchitecture #RiskAssessment #CRA #SecurityAudits
-
-
📆 It’s hard to believe we’re more than halfway through 2026. In “ORC’s impact in the first half of 2026,” Juan Rico looks back on everything the Open Regulatory Compliance Working Group has accomplished this calendar year. Highlights include: - Operationalising due diligence (including the development of resources to support manufacturers) - Expanding visibility through numerous in-person events - Launching the ORC Learning Hub (available now on our website) Resources: 📰 Full blog post – https://hubs.la/Q04tZbpx0 💻 Free courses on CRA compliance – https://hubs.la/Q04tZ7x30 #CyberResilienceAct #OpenSource #DigitalSovereignty #Cybersecurity #TechRegulations
-
-
⏳ There's still time to learn about the CRA and win ORC swag. With the first Cyber Resilience Act (CRA) reporting requirements taking effect on 11 September 2026, there's never been a better time to explore the ORC Learning Hub. To enter: ✅ Repost this post ✅ Tell us in the comments why CRA readiness matters to you. Entries close soon. We'll announce winners on 31 August 2026. Explore the ORC Learning Hub: https://hubs.la/Q04s0-rp0 #CyberResilienceAct #OpenSource #SoftwareSecurity #ORCLearningHub
-
-
Failure to comply with the CRA risks fines up to €15 million or 2.5% of global annual turnover, plus immediate removal from retail and digital shelves. Regulatory enforcement under the Cyber Resilience Act is structured to match the severity of modern cyber threats. Non-compliance is treated with the same financial weight as GDPR violations. In addition to severe monetary penalties, market surveillance authorities have the power to: 🔸 Order the immediate recall or withdrawal of non-compliant software from the entire European market. 🔸 Prohibit or restrict the placement of specific digital products on digital platforms and physical marketplaces. 🔸 Issue public compliance alerts that can cause massive brand and reputational damage. Mitigating this risk requires early architectural planning and transparent governance across your development pipelines. 📜 Understand the legal mechanics of non-compliance and protect your firm: https://hubs.la/Q04lJ5v00 #CorporateRisk #ComplianceOfficer #EnterpriseSecurity #CRA #LegalStrategy
-
-
What responsibilities do Open Source Software Stewards have under the CRA? The final implementation guidance by the European Commission clarifies that obligations depend on the steward's role. Organisations focused on governance, infrastructure, or engineering support are not all treated the same under the CRA. As presented in our white paper, providing clarity around the role of Open Source Software Stewards has been an important focus for the ORC community, and our blog breaks down what these distinctions mean in practice. Read the full blog: 🔗 https://hubs.la/Q04rNTPm0 #CyberResilienceAct #OpenSourceCompliance #OpenSourceSecurity #CRAReadiness
-