What's in the SOSS? An OpenSSF Podcast
What's in the SOSS? features the sharpest minds in security as they dig into the challenges and opportunities that create a recipe for success in making software more secure.
Get a taste of all the ingredients that make up secure open source software (SOSS) and explore the latest trends at the intersection of AI and security, vulnerability management, and threat assessments.
Each episode of What's in the SOSS? is packed with valuable insight designed to foster collaboration and promote stronger security practices for the open source software community.
About Christopher Robinson (aka CRob), host
CRob is a 43rd level Dungeon Master and a 26th level Securityologist. He is a leader within several Open Source Security Foundation (OpenSSF) efforts and is a frequent speaker on cyber, application, and open source security. He enjoys hats, herding cats, and moonlit walks on the beach.
What's in the SOSS? An OpenSSF Podcast
CRA Readiness: Practical Strategies for Open Source Communities with Megan Knight
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
In this episode of What's in the SOSS, host Sally sits down with Megan Knight, Director of Software Communities at ARM, OpenSSF Board Member, and Chair of the Awareness SIG within the Global Cyber Policy Working Group. Together, they break down the upcoming European Union Cyber Resilience Act (CRA) and address the persistent gap in ecosystem awareness. Megan outlines concrete, practical strategies for maintainers and organizations, highlights the vital role of community collaboration across working groups like ORBIT and ORC, and shares key resources to help lower the barrier to compliance. Stick around for a fun rapid-fire round where favorite open source mascots steal the spotlight!
Chapters:
- 00:24 - Introduction and Welcome
- 01:44 - The current CRA landscape and key findings from recent LF Research reports.
- 04:23 - Actionable compliance steps for maintainers and organizations
- 07:16 - The mission of the OpenSSF Global Cyber Policy Working Group
- 10:28 - How to get involved
- 13:25 - Rapid-fire
- 15:12 - Key takeaways and resources for a deeper dive into CRA readiness
Episode links:
- Megan Knight’s LinkedIn page
- Cyber Resilience Act - Implementation
- Global Cyber Policy Working Group (policy.openssf.org)
- Linux Foundation 2025 CRA Awareness and Readiness Report
- Linux Foundation 2026 CRA Awareness and Readiness Report
- Open Regulatory Compliance Working Group
- Open Resources for Baselines, Interoperability and Tooling (ORBIT) Working Group
- Open Source Project Security (OSPS) Baseline
- OpenSSF’s Global Cyber Policy Working Group European Union Cyber Resilience Act (CRA) Information, Resources & Guides Page
- LF Training Course: Understanding the EU Cyber Resilience Act (CRA) (LFEL1001)
- Global Cyber Policy GitHub Repository
- Add any other applicable links related to the episode
- OpenSSF Community Calendar
- Get involved with the OpenSSF
- Subscribe to the OpenSSF newsletter
- Follow the OpenSSF on LinkedIn
Intro Music & Promotional Soundbyte Clip (00:00)
“I think right now ~ what we're focusing on and what we hear from community that they're focusing on is ~ really, we just can't wait for perfect standards or tooling. The defensible path is to build a practical evidence model now and ~ really update it as the guidance evolves. You need to be developing your strategy now and then fine-tuning as you get more clarity around the standards.” - Megan Knight
Sally (00:24)
Hello, hello, and welcome to What's in the SOSS, where we talk to amazing people that make up the open source ecosystem. These are engineers, developers, maintainers, researchers, and all manner of contributors that make open source so great.
I'm Sally, your co-host, and today I'm really excited to be joined by Megan Knight from ARM. Megan, thank you so much for being here. And just to get us started, yeah, tell our listeners a little bit about yourself.
Megan Knight (00:54)
Well hi Sally, thank you for having me. I am super delighted to be here. Thanks for the warm welcome and introduction. My name is Megan Knight and I am the Director of Software Communities at ARM and I also serve on the OpenSSF Board and participate in the Global Cyber Policy Working Group as the Chair of the Awareness SIG. So happy to finally make it here.
Sally (01:18)
Wow, this is really exciting to have you on the show. And yeah, we have a lot to dive into with the EU Cyber Resilience Act or CRA, because this is a really important topic lately. And I know you're involved in the Global Cyber Policy Working Group and the Awareness SIG. So let's just dive in. Like what is the current landscape looking like from your perspective when it comes to CRA?
Megan Knight (01:44)
Wow, that is a very large first question and I love it. I ~ think that the summer is feeling pretty busy this summer compared to previous summers with the upcoming reporting deadline starting on September 11th. So I think that we are all actively participating more now than ever, trying to come up with tooling, solutions, trying to understand each other's problem spaces, since there are so many gaps in the publicly available information in regards to some standards, the final draft, things that are really important to make a solid play at compliance, so it's a really great time to have community ~ to help share in the excitement and sometimes misery.
But I think in general, conversations are happening. LF Research, though, did just recently put out this CRA awareness 2.0 report. ~ They had previously put out a version of the report about a year ago, where they reported back on how people were feeling about the CRA, how aware they were of the CRA, and how it would affect them.
~This year's report, which just came out in June, unfortunately reported that awareness is still relatively high. And it's still relatively high in many specific regions, like in US and Canadian-based enterprises. So we are currently trying to figure out how to best reach folks that
might not be aware, might be customers, might be consumers, might not understand that this is a thing that they do need to pay attention to and trying to lower the barrier to understanding what the heck this giant piece of legislation means for them.
Sally (03:49)
Yeah, thanks for bringing that up. And I really like your reframing and leaning into the community. That is so important so that we can all help each other, especially when so many people are unaware. I think it was 66% are still unaware in this recent 2026 survey. And by the way, for our listeners, we will link in the show notes both research from last year and this year.
So thanks really for bringing that up, Megan. And thinking about, you know, practical action. I know you spoke at Open Source Summit Europe on this. I was really impressed with your talk. What do those actionable steps actually look like for a maintainer or organization right now?
Megan Knight (04:30)
That's such a great question and thank you for the compliment. ~ I think even since last year, some of this has changed in ~ terms of what tooling is available, clarity on some of the guidance. So I'm glad we're getting a chance to talk through this again. I think right now what we're what we're focusing on and what we hear from community that they're focusing on is ~ really we just we can't wait for perfect standards or tooling, right? The the defensible path is to build a practical evidence model now and really update it as the guidance evolves. You know, in a perfect world, we'd have standards before the deadline. but this is the fastest this type of legislation has really ever come out of the commission. And so with that, there's going to be some hiccups and the pressure to get these standards out is super high. So really continuing to stay close to the standards development is going to help with maybe getting some direct knowledge on changes or potential things that might influence you. But I'd say trying to develop your strategy now. You need to be developing your strategy now and then fine-tuning as you get more clarity around the standards.
Some of the other things we're seeing are really preparing for those last minute solutions and requests from customers and partners that probably are in that unaware bucket. How can you within your own organization who might be aware create some sort of awareness campaign, encourage other departments to participate in this to be able to inform and have those conversations with your customers before they come to you, you know, at the reporting deadline asking for a bunch of compliance stuff that you might have not been prepared to to address.
So there are some practical things that can be done, even doing some role-playing through incidence response and what that's going to look like. There's that new single reporting portal that's going to exist, you know, coming up with a plan for how that's going to work and really simulating a dry run of what an incidence response would look like for your team with this new process in place. ~ Honing in on getting your categories right for your product families so that you can set kind of a framework for the compliance that you need in ~ that product family. So there's no shortage of things that you know you can be doing, but I would say reading it, making sure people at your company are aware of it, and collaborating in the community are probably great places to start.
Sally (7:18)
Yeah, the collaboration aspect naturally leads me to think about the OpenSSF Global Cyber Policy Working Group. So you're leading the Awareness SIG there. Why is this working group such a critical fit? I mean, not only for the OpenSSF right now, but for the communities that extend out from that. And what are you all working on these days? What's new over there?
Megan Knight (07:49)
The Global Cyber Policy Working Group is a great place for folks in the security and broader communities right now to come together on some of these more global cybersecurity related legislations. There have been legislations like this before, but not nearly in the volume we're experiencing right now. And the end goal is to raise the bar on security practices and software overall. And I think that really matches the mission of OpenSSF.
So, ~ I can't imagine a better place for it to be. And one of the strengths in OpenSSF is the relationship with Linux Foundation Europe. And then, you know, the relationship with many other foundations that are doing great work in the open right now, like the Eclipse Foundation and the ORC [Open Regulatory Compliance] Working Group, and then a lot of the standards expert working groups.
So we've got liaisons into many of the more expansive network of groups talking on the CRA and really coming together from a security perspective but from a policy perspective as well in this working group. And so right now we're developing a variety of assets and collaborating with the Orbit working group on this manufacturer tooling solution.
How can we help lower the bar for compliance? What existing tools can we use within the OpenSSF portfolio, like Baseline, for example, that may be able to map to CRA requirements. So really interesting discussions happening there. And developing tools and white papers to hopefully make things easier for our communities to understand, because it's not an average software developer's role to read a 300 page piece of legislation plus accompanying FAQs plus accompanying standards. ~ It's kind of an onslaught of very legal documents coming out right now. So anything we can do to help interpret those and support our community with questions, yeah, that's what we're there for.
Sally (9:53)
Love that, Megan. What a nice resource for the community. And we'll definitely add a link to the information. And then also looking forward to some of the upcoming white papers and other resources for the community. That's just great. If the goal is to help secure open source software and ease compliance, how can people listening to this podcast get involved in the working group?
Megan Knight (10:22)
Oh, well, just come on down. We would love to have you. The working group is a totally open working group. We have a variety of meetings that you can attend on the global cyber policy side. As mentioned before, we've got an awareness SIG where we cover a variety of topics and is a great place if you want to write about it, talk about it, do a LinkedIn post about it. Great place to collaborate on those sorts of things.
We also have the Standards SIG call under the Global Cyber Policy Awareness, where the fabulous Madelin Neag from LF Europe talks through the latest updates on the standards development process. And right now it is pretty focused on the CRA, as is the awareness SIG. and then there's also the biweekly all up calls where we cover everything that's been discussed in the Awareness SIG and the Standards SIG, in addition to some new topics.
So, if you can't attend the individual SIG calls, attending that big all-up call is a really great way to get caught up on everything that's been happening. And then we also host these monthly CRA Tech Talks where we bring in folks from the community. Most recently we did a panel we heard from several different maintainers on how the CRA is affecting them. So we
We try and bring in some folks that have different backgrounds and experience and perspectives to share as it relates to the CRA. And then I also would want to shout out the Orbit Working Group. The Orbit Working Group is the one I mentioned through the Launchpad SIG, working on the tooling for manufacturers. And they have a weekly, a bi-weekly cadence, I believe, as well. So I would encourage everyone to go check out the OpenSSF community calendar.
All of the talks that I mentioned and the ~ calls that I mentioned ~ are listed there. ~ You can you can subscribe from there. and then I would also suggest that folks go check out policy.openssf.org. A lot of the materials that I mentioned kind of at a high level but didn't get into details on, they live there.
So the stewardship guidance that we've got, there's a stewardship one pager and a larger stewards playbook. we've also got a big section on standards. So understanding there's a standards map and a lot of the ~ feedback that OpenSSF has given on draft standards to the various standards bodies. And then we've also got some maintainer resources. There's a readiness guide for maintainers and developers there.
So yeah, and we're adding new things every day. So I would really encourage you all to go check that page out and always accepting contributions. So if ~ you'd like to add or make changes to any of those documents, They're available to do so on on GitHub.
Sally (13:19)
All right, Megan, before we wrap, it's time for the rapid, rapid fire round. These are questions I'm gonna ask you. And you can answer without overthinking, no explanations, just your first instinct answers for fun. Are you ready for rapid, rapid fire?
Megan Knight (13:35)
Oh goodness, let's do it.
Sally (13:37)
Okay, Star Wars or Star Trek.
Megan Knight (13:40)
Star Wars
Sally (13:41)
Solid. Favorite baked good to sample.
Megan Knight (13:46)
Oh, it's gonna be a croissant.
Sally (13:49)
Croissants, yes. Excellent. Okay, last one. Favorite open source mascot.
Megan Knight (14:06)
Oh my goodness. That's ~ a horribly hard question. How could you possibly choose? I really I mean, I do have to shout out the CRAWfish, the CRA-fish, that's the mascot for the OpenSSF's Global Cyber Policy Working Group. It is…it is an amazing mascot, and shout out to Stacey, the community manager, for getting plushy keychains made of them. Absolutely adorable.
But then definitely a fair tie is the Pocky Beaver for Yocto Project. He's a little hardworking beaver with a construction hat and a tool belt and he's ready to go create you a ~ custom distribution. So yeah, I think it's gotta be a tie between those two. But please, all of them are amazing. Keep them coming.
Sally (14:52)
All right. Yeah, those are two great ones. Perfect. No notes. As we wrap things up, what's your call to action for our audience? If someone's listening and wants to learn more about the CRA or get involved, where do they start?
Megan Knight (15:06)
That's a great question. I would say to start at the Linux Foundation training course, there's a one-on-one CRA course that is a fairly comprehensive overview of the different articles and areas that might impact you. I would start there and get your feet wet with the content, understand the language. A lot of these terms are being used for the first time ever in legislation.
So if you're thinking, man, I haven't heard of a steward ever. And now I'm just hearing that word constantly. Well, this is why. so start there. And then I would encourage you to just come to a global policy, global cyber policy call and start listening to the types of conversations. Check out the resources I mentioned on policy.opensf.org and reach out to the Global Cyber Policy Working Group channel on Slack if you've got any specific questions or concerns or areas that you've been working on that you want to share. We are always open on the Slack channel for for communication. So please please reach out.
Sally (16:12)
Megan, thank you so much for joining us today and for all the work you're doing to build awareness and help secure how open source software is delivered in this new landscape. And to everyone, happy listening, happy open sourcing, and that's a wrap.