Skip to content

Beyond NIS2: Software Supply Chains and the Cyber Resilience Act (CRA)

This is a draft agenda: changes are still being made.

Speaker:
Barry O'Donovan, INEX
Date:
Time:
Room:
Side Room
Session:
Open Source
Duration:
25 min
Transcript:
Not Available
Meetecho chat:
Not Available
Type:
Talk
Slides:
—
Recording:
Not Available
Add to calendar

Abstract

As network operators, we are all familiar with NIS2 by now, with many of us being categorised as operators of essential or important entities. However, operational resilience is only half the equation - the EU’s Cyber Resilience Act (CRA) directly targets the software supply chain that powers our infrastructure.

With mandatory vulnerability reporting obligations taking effect from September 2026, where does this leave the open-source ecosystem that we rely on every day?

This presentation bridges the gap between NIS2 operator obligations and CRA software requirements. We explore how the CRA categorises open-source software, breaking down the critical distinction between Commercial OSS Manufacturers (subject to full product liability, CE marking, and fines) and Open-Source Software Stewards (non-profit foundations and industry associations operating under a light-touch regime).

Using familiar ecosystem tools as real-world examples, we explain what ISP and IXP operators can legally expect from their upstream maintainers regarding Software Bills of Materials (SBOMs), vulnerability disclosures, and patch timelines.

By the end of this talk, you should leave with a clear roadmap for auditing your open-source dependencies under NIS2, consuming standardised security feeds, and understanding your obligations if you publish tools for the community.

Recording

Video will be added soon.

Speaker

Barry O'Donovan

Barry O'Donovan

Rate this talk

Rating will open: Monday, 26 October 2026 09:00 (+0200).