Why "secure by design" is the new standard for open source
What happened
The Cyber Resilience Act (CRA) takes effect on December 11, 2027, and as of September 11, 2026, the first CRA vulnerability and incident reporting obligations were live. According to the 2026 Open Source Security and Risk Analysis Report , it’s estimated that over 97% of the code in most codebases comes from open source.
Open source software faces significant regulatory shifts, making "secure by design" development practices increasingly important. These new cybersecurity regulations impact all companies that sell software or hardware to the European market and will have a huge impact on open source as a whole.The readiness gap and the cost of inactionDespite the looming deadline, the software industry remains unprepared.
These new cybersecurity regulations impact all companies that sell software or hardware to the European market and will have a huge impact on open source as a whole. The readiness gap and the cost of inaction Despite the looming deadline, the software industry remains unprepared.
According to The Linux Foundation’s 2026 CRA Awareness and Readiness Report , 66% of companies remain unfamiliar with the CRA and only 41% expect to be fully compliant by December 2027. The CRA regulates products with digital elements placed on the EU market, and open source software underpins most modern software products including cloud infrastructure, operating systems, and AI frameworks.
Sources & evidence
- Red Hat Blog Primary / official
Why "secure by design" is the new standard for open source ↗
https://www.redhat.com/en/blog/why-secure-design-new-standard-open-source