Starting September 11, 2026, the EU Cyber Resilience Act (CRA) requires open source software stewards to report actively exploited vulnerabilities and severe security incidents to ENISA. Timelines are tight: 24-hour early warning, 72-hour formal notification, final report within 14 days (vulnerabilities) or one month (incidents).
The Linux Foundation has established a stewardship framework where LF legal entities can act as CRA stewards for hosted projects, handling registration, deadlines, and regulatory filings. Projects don't necessarily have to build their own compliance function.
Because OpenJS is independently incorporated, we are checking if we can use an LF legal entity as steward. I am hoping to have an answer by Monday. I think the answer is yes but.. I am not a lawyer, so we want to confirm :)
Decision: Who Is the Steward
The LF framework offers two paths applicable to OpenJS:
- Delegate to LF legal parent (assuming this is an option): A LF legal entity acts as steward.
- Project acts as its own steward: Project handles all CRA management directly.
We need to confirm which model fits OpenJS. Given that we operate as a CNA and have an established security release process, we should discuss whether this creates any additional obligations or favors a different model.
What Needs To Happen Across our Projects
For each project that publishes software intended for commercial use in the EU (all OpenJS projects likely fit this definition):
- Add a CRA stewardship statement to SECURITY.md identifying the LF steward (Placeholders populated based on steward decision):
CRA stewardship: This project is supported under the Linux Foundation CRA stewardship framework. Our project CRA steward is [Steward legal entity] and its policy is available at https://www.linuxfoundation.org/security. Security vulnerabilities should be reported through [project security reporting mechanism] which we will coordinate with our CRA steward. For actively exploited vulnerabilities or other security matters that may require CRA escalation, please use the project's security [emergency reporting mechanism] as appropriate.
-
Document whether the software is intended for commercial activities in the EU. (I am looking into exactly what this means)
-
Know the escalation rule: If a project learns of an actively exploited vulnerability or a severe incident (e.g., compromise of the release process), notify the LF steward's CRA contact immediately while fixing the problem. Don't wait for complete information, the steward's clock starts at awareness. See screenshot below.
Timeline
September 11, 2026 — Reporting obligations take effect (~2 weeks)
December 11, 2027 — Full product conformity requirements apply
Additional Information
Tagging in @tobie as I know they have been very involved in all things CRA.
Starting September 11, 2026, the EU Cyber Resilience Act (CRA) requires open source software stewards to report actively exploited vulnerabilities and severe security incidents to ENISA. Timelines are tight: 24-hour early warning, 72-hour formal notification, final report within 14 days (vulnerabilities) or one month (incidents).
The Linux Foundation has established a stewardship framework where LF legal entities can act as CRA stewards for hosted projects, handling registration, deadlines, and regulatory filings. Projects don't necessarily have to build their own compliance function.
Because OpenJS is independently incorporated, we are checking if we can use an LF legal entity as steward. I am hoping to have an answer by Monday. I think the answer is yes but.. I am not a lawyer, so we want to confirm :)
Decision: Who Is the Steward
The LF framework offers two paths applicable to OpenJS:
We need to confirm which model fits OpenJS. Given that we operate as a CNA and have an established security release process, we should discuss whether this creates any additional obligations or favors a different model.
What Needs To Happen Across our Projects
For each project that publishes software intended for commercial use in the EU (all OpenJS projects likely fit this definition):
CRA stewardship: This project is supported under the Linux Foundation CRA stewardship framework. Our project CRA steward is [Steward legal entity] and its policy is available at https://www.linuxfoundation.org/security. Security vulnerabilities should be reported through [project security reporting mechanism] which we will coordinate with our CRA steward. For actively exploited vulnerabilities or other security matters that may require CRA escalation, please use the project's security [emergency reporting mechanism] as appropriate.
Document whether the software is intended for commercial activities in the EU. (I am looking into exactly what this means)
Know the escalation rule: If a project learns of an actively exploited vulnerability or a severe incident (e.g., compromise of the release process), notify the LF steward's CRA contact immediately while fixing the problem. Don't wait for complete information, the steward's clock starts at awareness. See screenshot below.
Timeline
September 11, 2026 — Reporting obligations take effect (~2 weeks)
December 11, 2027 — Full product conformity requirements apply
Additional Information
Tagging in @tobie as I know they have been very involved in all things CRA.