This toolkit transforms complex regulatory requirements into a series of practical steps that organizations can incorporate into their software development and security processes. It helps them assess their readiness, identify open-source software components used in their products, manage vulnerabilities, and document how security risks are addressed.
This announcement comes as the first obligations set by the CRA are being implemented. From September 11, 2026, manufacturers must actively report exploited vulnerabilities and serious security incidents affecting products that incorporate digital elements and are marketed in the European Union. These CRA requirements will be extended on December 11, 2027.
The initial rollout of the OCCTET self-assessment platform has identified a widespread problem: many SMEs implement security measures but lack the visibility, documentation, and consistent processes needed to demonstrate how they are managing software risks.
“Organizations with limited resources for compliance face significant challenges in preparing for the implementation of the CRA,” said Mike Milinkovich, executive director of the Eclipse Foundation. “OCCTET simplifies the process by providing tools that help them understand their obligations, identify and address vulnerabilities, and maintain the necessary records for compliance.”
A practical solution from assessment to action:
The OCCTET toolkit brings together several services that equip organizations from initial assessment through vulnerability management and documentation.
SMEs and open-source software projects can now access and test the following services:
Assess readiness: The CRA Assessment Portal helps SMEs understand how the CRA applies to them, evaluate their current readiness, and identify areas for improvement. The free, guided assessment translates CRA clauses into structured questions, scores, and practical recommendations.
Identify software components: Eclipse Apoapsis (an OCCTET instance) identifies open-source software components, dependencies, and licenses based on the OSS Review Toolkit and known vulnerabilities. It can also generate a range of CRA-ready compliance reports and artifacts, such as Software Bills of Materials (SBOMs), which provide a standardized inventory of the software components embedded in a product.
Review findings and take action: Bitsea Curator (an OCCTET instance) combines automated analysis and human review to help users verify software information, assess whether vulnerabilities affect their products, prioritize issues, and document their decisions. It also allows the creation of Vulnerability Exploitability Exchange (VEX) reports, which record whether a product is affected by a known vulnerability.
Reuse shared software information: The Federated OSS Assessment Database, vulnerablecode.io, provides information on open-source software packages, including their origins, licenses, security warnings, vulnerabilities, and reference SBOMs. Its PurlDB demo version allows you to generate reference SBOMs for over 20 million packages, while its integration with VulnerableCode connects vulnerability information to the corresponding software packages.
The toolkit's validity has been tested in real-world, complex software dependency scenarios across ten different technology ecosystems. Testing was conducted on widely used open-source software projects and through a large-scale analysis of the entire Eclipse Foundation project portfolio, as well as for a growing number of real-world SMB use cases. This comprehensive testing demonstrates the toolkit's ability to work with diverse technologies, project sizes, and software supply chains.
Testing has shown that it can analyze complex dependency structures, identify vulnerabilities, support human reviews, and monitor security over time.
Access to OCCTET:
The OCCTET (Open Source Compliance: Comprehensive Techniques and Essential Tools) project brings together industry leaders, cybersecurity experts, representatives from SMEs, and open-source organizations to make software security and CRA readiness more accessible, transparent, and cost-effective.
SMEs and open-source projects can test the toolkit and resources available at occtet.eu. Organizations interested in testing the services using real-world development products and workflows, and providing feedback for further improvements, can visit this OCCTET webpage.
OCCTET complements the extensive work of the Eclipse Foundation to help open-source organizations and communities prepare for CRA. Participants are developing, through the ORC (Open Regulatory Compliance) Working Group, community-driven specifications, along with guidelines, training, and other resources that facilitate CRA implementation across the open-source ecosystem.
Among these resources is the free ORC Learning Hub, which offers practical, role-specific training to help open-source developers, maintainers, project managers, product teams, and security and compliance professionals understand how the CRA applies to their work and how to meet these requirements in practice.
The community also comes together at Code & Compliance, ORC’s flagship event for open-source developers, project managers, legal and compliance professionals, public officials, and industry leaders. The next event, taking place on October 27, 2026, in Brussels, will provide a forum to exchange experiences, share best practices, and explore how the CRA and other emerging digital regulations affect the open-source ecosystem. Register now.
