Loading…
Type: Regulatory Compliance clear filter
Tuesday, October 6
 

10:30 CEST

Who Pays When Debug Breaks? Supply-Chain Liability Under the CRA and the Product Liability Directive - Annika Kristin Niemann, iRights.Law Rechtsanwälte
Tuesday October 6, 2026 10:30 - 10:50 CEST
On 8 Sept 2025, one phishing email hijacked a maintainer's npm account and pushed malicious versions of chalk, debug and 16 other packages totalling 2.6B weekly downloads. When such a package breaks something that hurts someone, who pays?
Two EU laws finalised in 2024 shape the answer, the Product Liability Directive and the Cyber Resilience Act, and their duties phase in across 2026 and 2027. So we go hands-on: we take this real compromise and walk it, step by step, down the liability chain. The maintainer, it turns out, is the one the law works hardest to shield as non-commercial open source sits largely outside both regimes. The bill lands downstream, on the commercial manufacturer who ships debug inside a product. Under the PLD, a missing security update can itself be a defect, under strict liability. The CRA adds a second layer since it lays a duty on to manage exactly this kind of vulnerability - detect it, report it, patch it - backed by fines, while the "open-source steward" carries a lighter, fine-free load.
Speakers
avatar for Annika Kristin Niemann

Annika Kristin Niemann

Lawyer, iRights.Law
Annika Niemann is a solicitor specialising in IT law, with a focus on open source compliance, supporting companies in the legally compliant use of open source software across the supply chain. She advises on CRA and product liability questions, including how the EU's Cyber Resilience... Read More →
Tuesday October 6, 2026 10:30 - 10:50 CEST
South Hall 3B-3C

13:55 CEST

Operationalizing the CRA and Shaping OpenSSF’s Community Roadmap - Roman Zhukov, Red Hat; Daniel Appelquist, Samsung Electronics; Madalin Neag, OpenSSF; Megan Knight, Arm
Tuesday October 6, 2026 13:55 - 15:10 CEST
As of Sept 11, 2026, the EU CRA mandates short-window reporting for actively exploited vulnerabilities to ENISA. Yet, Linux Foundation research shows 66% of the ecosystem remains unprepared, risking expensive "private forking" traps.

Hosted by the OpenSSF Global Cyber Policy WG, this 75-minute interactive workshop shifts the conversation from abstract legal theory to operational realities a lot of us are facing right now. Following a short briefing, the core 1-hour session unites enterprise engineers, security officers, stewards, open source developers and layers in collaborative 3 breakouts to stress-test real-world CRA challenges. Topics include: governance, open source particularities and CRA personas across varying PDE classifications, as well as secure-by-design mandates, risk assessments, due diligence, SBOMs, vulnerability management and reporting obligations. We conclude with a 15-minute synthesis of mapping live insights directly to OpenSSF roadmap and our work for the upcoming quarters.

Whether you are an enterprise architect trying to keep your product compliant, a steward, or an upstream developer, this workshop offers to tackle your specific use cases.
Speakers
avatar for Dan Appelquist

Dan Appelquist

Open Source Strategist, Samsung Electronics
Dan Appelquist is Open Source Strategist at Samsung Open Source Group. He is a web & mobile industry veteran and long-time participant and leader in open source and open standards. He is co-chair of the OpenSSF Global Cyber Policy working group and also has been a member of the OpenSSF's... Read More →
avatar for Roman Zhukov

Roman Zhukov

Security Communities Lead, Red Hat
Roman is a cybersecurity expert and leader with 20+ years of experience securing complex systems and products. As Principal Architect at Red Hat, he drives open-source security strategy and cross-industry collaboration to build trusted software ecosystems. Formerly, he led Product... Read More →
avatar for Madalin Neag

Madalin Neag

EU Policy Advisor, OpenSSF
Madalin serves as EU Policy Advisor at OpenSSF, working at the intersection of cybersecurity, open source software, and European technology policy. He helps connect open source technical communities and policymakers, supporting the development of practical regulatory frameworks, aligning... Read More →
avatar for Megan Knight

Megan Knight

Director of Software Communities, Arm
Megan Knight is the Director of Software Communities at Arm where she leads upstream engagements with open source communities. She holds many leadership positions with various communities including Advocacy Chair for the Yocto Project, OSPO Special Interest Group lead for UXL Foundation... Read More →
Tuesday October 6, 2026 13:55 - 15:10 CEST
South Hall 3B-3C
 
  • Filter By Venue
  • Filter By Type
  • Timezone

Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.