The maintenance, protection, and regulation of open source software is being prepared for the entry into force of the European Union's Cyber ​​Resilience Act (CRA). This initiative provides practical, specialized training to developers, maintainers, contributors, project managers, product teams, security and compliance professionals, OSPO managers, and legal teams specializing in open source software.

While the CRA is a European law, its impact is global. Any organization that distributes or markets software products in the EU market, including open source software, must comply with its requirements. Open source software is now virtually universal, with over 96% of commercial codebases containing open source software (OpenLogic 2026 State of Open Source Report). As a result, the software industry worldwide needs clear and practical guidelines.

“The CRA changes how software is developed and delivered globally,” said Mike Milinkovich, executive director of the Eclipse Foundation. “Because open source software is part of almost all current applications and systems, CRA readiness must happen where the software is built. The ORC Learning Hub helps developers, maintainers, project managers, and software teams understand CRA requirements and put that knowledge into practice.”

Developed by the ORC Working Group and managed by the Eclipse Foundation, the ORC Learning Hub brings together knowledge from across the open source ecosystem, industry, and regulatory environments. It provides open source-focused training to help organizations understand how CRA applies in the real world and what actions they need to take.

The first phase of mandatory CRA compliance begins in September 2026, so organizations have little time to prepare. Guidelines available to date have been scarce and generally high-level, particularly regarding open source software. The ORC Learning Hub fills this gap by providing clear, practical, and specialized education that aligns with modern open source development practices.

The CRA adds mandatory cybersecurity requirements for products with digital elements sold in the EU, including those that integrate or depend on open source software. It establishes new responsibilities for manufacturers and distributors of such products in the European market. The CRA also introduces a new role, the open source officer, who must adopt secure development practices, ensure transparency, and manage vulnerabilities throughout the software supply chain.

The core of the ORC Learning Hub is a modular training program designed to guide organizations and prepare them step-by-step for the CRA's entry into force. This is the program structure:

Module 1: Introduction to CRA for Open Software
Module 2: Introduction to CRA for Manufacturers
Module 3: SBOM and Vulnerability Management with Open Software
Module 4: Due Diligence and Use of Open Software with CRA
Module 5: Vulnerability Management in Practice

The Learning Hub is launching Modules 1 and 2 today, which are intended for:

Open Software Developers, Maintainers, Contributors, and Project Managers
Product Teams, Security and Compliance Professionals, OSPO Managers, and Legal Teams

Modules on SBOM management, due diligence, and vulnerability will be announced soon.

The ORC Learning Hub is designed to:

Help developers, maintainers, project managers, and software teams understand the implications of the CRA for their work
; clarify the application of CRA requirements to open software, communities, and the development of open software-based products;
provide specific guidance for manufacturers, developers, maintainers, OSPO, security teams, and legal and compliance professionals;
help organizations prepare for the CRA across modern open software supply chains;
and offer global collaboration on best practices applied to emerging laws.

The ORC Learning Hub is free and available worldwide. We encourage organizations and the entire open software community to prepare before the CRA comes into effect in September 2026, and to stay tuned for the introduction of new modules and guidelines.

More information