October 5, 2026

Please note that the information provided in this document is for informational purposes only and does not constitute legal advice.

Earlier this year, the Foundation launched its Cyber Resilience Act (CRA) Readiness project. The launch blog post outlines the reasons for the project and what it seeks to achieve. 

A lot of progress has been made in the project since February which we would like to share with you. First, a reminder that the project is being documented on a GitHub repository, with monthly updates and meeting notes available for you to read. 

What is the CRA? – A quick refresher

Note: this is a very brief overview. There is a lot of detail in the regulation which is not given here.

  • The EU Cyber Resilience Act is a new EU regulation. 
  • It affects anyone selling Products with Digital Elements (PDEs) in the EU. 
  • It mandates that PDEs are managed through a secure software lifecycle and that actively exploited vulnerabilities must be reported to the European authorities.
  • Its goal is to improve the security of software (and hardware with software installed) for users residing within the EU, whether individuals or organizations. 
  • The regulation is enforced through various mechanisms, including non-compliance fines for manufacturers of up to €15M or 2.5% of global revenue. 
  • The regulation is already in place, with a phased rollout. Manufacturers are already obliged to report actively exploited vulnerabilities within 24h of discovery, and after Dec 11, 2027 all PDEs on the market must meet “Secure by Design” obligations and have an CE mark affixed.

How does the CRA affect FreeBSD? 

FreeBSD vendors serving the EU market have a responsibility to ensure that the implementation of FreeBSD they include in their products meets the CRA’s requirements for “Secure by Design” and “Secure by Default”. They are also responsible for reporting any actively exploited vulnerabilities in their entire codebase which naturally includes FreeBSD code.

The FreeBSD Project itself, along with its contributors, is not directly regulated by the CRA but may expect to see a change in focus for manufacturers who are seeking to meet their CRA obligations. There is a little over a year remaining for manufacturers to get their SBOMs in order, and make any other changes needed so that their PDEs have a secure software lifecycle. Their reporting obligations are already in force, so a critical incident (with the chance of large fines) could occur at any time. 

As the upstream project, FreeBSD may start to experience some behavioral changes in downstream manufacturers, for example:

  • Pressure to engage with manufacturers who are up against tight vulnerability report and remediation deadlines, or who are looking for patches in a hurry.
  • Manufacturers looking for information on FreeBSD secure development practices, or who are looking for a FreeBSD SBOM.
  • Manufacturers looking for ways to reduce risk in FreeBSD or its dependencies or who are looking for alternatives to FreeBSD.
  • Manufacturers coming with questions about how FreeBSD works or is developed, or who want changes to how FreeBSD works or is developed.

What is the Foundation’s role in this?

The FreeBSD Foundation exists to support the FreeBSD Project. Its longstanding and extensive role in supporting the Project means it is classified as an “open source software steward” under the CRA. There are a few lightweight obligations under the CRA for stewards, but there are no fines. Where stewards are involved in development work or managing infrastructure, they have some reporting responsibilities but these do not come into force until Dec 11, 2027. They are also required to provide a cybersecurity policy to Market Surveillance Authorities (MSAs) on demand. 

Getting ready to meet these responsibilities has been part of the Foundation’s Cyber Resilience Act (CRA) Readiness project, but the project has been scoped to go much further and ensure that the FreeBSD Project and its community are ready to support and engage with manufacturers as they seek to meet their CRA obligations.

Project progress to date

Reminder: the project is being documented on a GitHub repository, with monthly updates and meeting notes available for you to read. 

Foundation readiness

Manufacturer outreach program

The Foundation has been contacting manufacturers to understand what they are doing to prepare for the CRA and to seek their support for FreeBSD. The engagement levels have been mixed, with European vendors being most advanced in their understanding and interest.

Steward obligations

The Foundation has created its Cybersecurity Policy, an internal document that captures existing relationships and processes in the FreeBSD Project and can be provided to the MSA as neededWe have also created an internal live cybersecurity incident protocol for Foundation staff to follow in case of an incident which needs to be reported under the CRA.

The Foundation has been preparing to use the European Union Agency for Cybersecurity (ENISA) reporting platform. This is the platform that manufacturers are already using to report actively exploited vulnerabilities, and it will be opened up to stewards on Dec 11, 2027.

Open Source solidarity

We have been engaging with the Eclipse Foundation’s Open Regulatory Compliance (ORC) working group to keep up with the latest news from the European Commission (EC), share perspectives, and support other projects.

FreeBSD Project readiness

Security Team Resilience

The Foundation has invested in increasing the resilience, capacity, and CRA expertise of the Security Team by sponsoring Pierre Pronchery to join as a new member. His dual role on the team and as a Security Engineer for the Foundation has been pivotal in facilitating the flow of information in both directions. He is currently working on a CRA live incident information pack for the Security Team to reference in case of a live incident.

Core Team engagement

The Foundation has been keeping the new Core Team (which was formed in June) up to date with the work in flight, and sharing CRA information so that the Core Team can begin to include CRA considerations in their work.

SBOM tooling for FreeBSD

A large part of the readiness project has been dedicated to developing the tooling for creating an SBOM at build time for FreeBSD. SBOMs (Software Bills of Materials) are required by manufacturers under the CRA and form the backbone of license compliance and vulnerability management. This has proven to be a complex and challenging project which has many unknown unknowns. The progress has not been linear but the solution is becoming very robust and comprehensive, and will prove to be an excellent asset to FreeBSD over the coming years. Work is ongoing and will be available in FreeBSD 16, and also in point releases of FreeBSD 14 and 15 when ready.

FreeBSD community readiness

Information sharing

The Foundation has been working hard to understand the CRA and share FreeBSD-specific information about it. Key outputs include:

Legislative engagement

We have been sharing known open consultations on legislation with the community via mailing lists, and on a GitHub reference page. We have had some really supportive community members who have collaborated on providing feedback to the EC on their draft public guidance.

What’s next and how can you help?

The Foundation’s project has achieved the majority of its immediate goals, but the CRA is here to stay and FreeBSD will feel its influence over the coming months and years. The Foundation remains committed to supporting FreeBSD through this phase of its development.

Our main focus going forward will be to work with the Core Team, Security Team, and manufacturers to make improvements to FreeBSD’s security posture that will in turn make CRA compliance easier. Keep an eye on the monthly updates to track progress.

The number one thing you can do to help is to learn about the CRA – so thank you for reading this post. If you have any questions feel free to ask, by emailing cra@freebsdfoundation.org. Your questions help us to improve our work.

If you are a manufacturer affected by the CRA, we would love to hear from you and understand how you are preparing and what you need from FreeBSD. Where concrete changes are needed, we would be happy to coordinate a joint effort supported by like-minded manufacturers.

Donations in support of the CRA readiness work are always appreciated and will help us to continue supporting this important work