Abstract
As network operators, we are all familiar with NIS2 by now, with many of us being categorised as operators of essential or important entities. However, operational resilience is only half the equation - the EU’s Cyber Resilience Act (CRA) directly targets the software supply chain that powers our infrastructure.
With mandatory vulnerability reporting obligations taking effect from September 2026, where does this leave the open-source ecosystem that we rely on every day?
This presentation bridges the gap between NIS2 operator obligations and CRA software requirements. We explore how the CRA categorises open-source software, breaking down the critical distinction between Commercial OSS Manufacturers (subject to full product liability, CE marking, and fines) and Open-Source Software Stewards (non-profit foundations and industry associations operating under a light-touch regime).
Using familiar ecosystem tools as real-world examples, we explain what ISP and IXP operators can legally expect from their upstream maintainers regarding Software Bills of Materials (SBOMs), vulnerability disclosures, and patch timelines.
By the end of this talk, you should leave with a clear roadmap for auditing your open-source dependencies under NIS2, consuming standardised security feeds, and understanding your obligations if you publish tools for the community.
Recording
Video will be added soon.
Speaker
Barry O'Donovan
Rate this talk
Rating will open: Monday, 26 October 2026 09:00 (+0200).