Skip to main content

OCCTET

Open Source Compliance Toolkit

CRA Readiness for SMEs & OSS Projects

Our mission is to empower SMEs with accessible, efficient, and secure solutions for Open Source Software (OSS) integration, while strengthening the security posture of Open Source Communities.

The OCCTET project (Open-source Compliance: Comprehensive Techniques and Essential Tools) is an EU-funded initiative aimed at improving cybersecurity and compliance with the Cyber Resilience Act (CRA) for Small and Medium Enterprises (SMEs). The project focuses on creating an Open Source Toolkit to automate the compliance process for Free and Open Source Software (FOSS) used in digital products.

This toolkit is intended to provide a comprehensive suite of tools and resources tailored to the needs of SMEs:

  • Compliance Checklist
  • Conformity Assessment Specifications
  • Automated Evaluation Method and Tool
  • Federated Database platform for publishing the results of OSS component assessments allowing contributions from various stakeholders
  • Inventory of Automatic Dependency Analysis Tools
  • Reporting tool

Evaluate Your Cyber Resilience Readiness in Minutes

Strengthen your organization's cyber resilience with our quick, easy, and completely free self-assessment tool. The platform helps you instantly measure your compliance and preparedness in line with the EU Cyber Resilience Act (CRA).

Free self-assessment • Confidential processing • Instant next steps

Be part of the OCCTET journey!

Help us build a collaborative, open-source-driven solution that empowers both SMEs and open source communities. Register to our newsletter and stay updated on progress, opportunities, and community events.

Free to join • Early access to the toolkit • Shape the roadmap

News

Eclipse Foundation Releases Free Toolkit to Help SMEs Prepare for the EU Cyber Resilience Act

September, 10, 2026

📢 The Eclipse Foundation has announced the availability of a free, open-source toolkit developed through the EU-funded OCCTET project to help small and medium-sized enterprises (SMEs) and open-source projects prepare for the European Union's Cyber Resilience Act (CRA).

The toolkit translates complex regulatory requirements into practical steps that organisations can incorporate into their software development and security processes. It helps them assess their readiness, identify which open-source components are used in their products, manage vulnerabilities, and document how security risks are being addressed.

The release comes as the CRA's first obligations take effect. Beginning 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents affecting the security of products with digital elements made available in the European Union. The CRA's broader requirements will apply from 11 December 2027.

“For organisations with limited compliance resources, preparing for the CRA is a major undertaking. OCCTET makes that work more manageable by bringing together tools that help them understand their obligations, identify and address vulnerabilities, and maintain the records needed to support compliance.”
Mike Milinkovich, executive director of the Eclipse Foundation

📰 Read the full announcement

👉 Want to help test the OCCTET toolkit? Join the testing community

OCCTET Deliverables D3.3 and D3.4 – Toolkit Demo and Federated Database Final

July, 3, 2026

🛠️ How can SMEs turn open-source software analysis into practical CRA compliance evidence?

OCCTET has released two major Work Package 3 deliverables: D3.3 – Toolkit Demo and D3.4 – Federated Database Final.

Together, these deliverables demonstrate how OCCTET is building an open-source toolchain to help SMEs identify dependencies, detect vulnerabilities, generate SBOMs, curate findings, and reuse trusted software metadata across the open-source ecosystem.

D3.3 – Toolkit Demo

D3.3 presents the OCCTET Toolkit demonstrator, bringing together ORT Server, OCCTET Curator and supporting components to automate software composition analysis, vulnerability detection, SBOM generation, and CRA-oriented compliance evidence preparation.

What it demonstrates:

  • Automated dependency discovery and vulnerability analysis with ORT Server
  • Continuous monitoring of software projects and evolving security advisories
  • SBOM generation in standard formats such as SPDX and CycloneDX
  • Human-in-the-loop curation with OCCTET Curator
  • Support for VEX-oriented vulnerability evidence and CRA reporting workflows
  • Validation on widely used open-source projects and SME use cases

D3.4 – Federated Database Final

D3.4 presents the final demonstrator of the OCCTET federated and shared software metadata platform. It extends the earlier FedDB beta into an operational approach for sharing package origin, license, vulnerability and SBOM metadata using Package URL (PURL) as the common software supply chain identifier.

What it brings:

  • Federated software package metadata keyed by PURL
  • Reusable origin, license, advisory and SBOM information
  • CycloneDX SBOM generation through PurlDB
  • Support for more than 20 million tracked packages in the public PurlDB demonstrator
  • An advisory-centric VulnerableCode model designed to support actionable vulnerability management
  • Decentralized publication of software metadata through API-accessible services and Git-based repositories

These two deliverables mark an important step toward OCCTET's goal by reducing the CRA compliance burden for SMEs.

CRA compliance requires more than knowing that a vulnerability exists. SMEs need to understand where components come from, whether they are affected, how findings should be prioritised, and how evidence can be produced and reused. D3.3 and D3.4 directly address this challenge.

📥 Read the full deliverables

👉 Want to help test the OCCTET toolkit? Join the testing community

OCCTET Deliverable D2.2 – SME CRA Self-Assessment Model & Survey

May, 12, 2026

Are your products Class I or Class II under the Cyber Resilience Act?

If you are not sure, you are not alone. And now there's a tool to help.

OCCTET's Deliverable D2.2 – SME CRA Self-Assessment Model & Survey is live. It's a streamlined, web-based tool built specifically to help SMEs in the software and hardware sectors understand their CRA obligations — without needing a legal team to decode every clause.

What it does:

  • Helps you self-evaluate your CRA compliance status
  • Clarifies whether your product falls under Class I or Class II requirements
  • Guides you through CRA obligations step by step
  • Designed for SMEs — straightforward, accessible, actionable

CRA compliance doesn't have to be a black box. This tool is designed to open it up!

📥 Read the full Deliverable

🔗 Try the self-assessment tool

👉 Want to be part of the OCCTET testing community? Sign up here

OCCTET Deliverable D2.1 – CRA SME Requirement Document Now Available

May, 2, 2026

🔍 What does CRA compliance actually mean for SMEs and open source?
We have done the research, so you don't have to start from scratch.

OCCTET's Deliverable D2.1 – CRA SME Requirement Document is now publicly available. This report maps out the real compliance landscape for SMEs and FOSS contributors under the Cyber Resilience Act, based on direct stakeholder engagement, expert consultations, and a thorough review of existing compliance literature.

Here's what's inside:

  • SME-specific CRA requirements, clearly explained
  • FOSS-specific obligations and what they mean in practice
  • Key challenges identified through direct engagement with SME owners and FOSS contributors
  • Best practices to support your compliance journey

Whether you're just starting to navigate CRA or looking to benchmark your current approach, this document is your starting point.

📥 Read the full Deliverable

👉 Are you an SME or open source contributor interested in testing our compliance tools? Join our community

Are you our next OCCTET tester?

February, 12, 2026

We are looking for a new testing round of the OCCTET.eu tooling, and we are looking for pioneering SMEs and Open Source Projects to join.

If you want early access, insights, and the chance to shape a new compliance solution, this is for you!

What you will get

Selected SMEs/Open Source Projects will benefit from an automated analysis of their product or software, including:

  • complete dependency analysis within supported technologies
  • inspection of dependency versions and management practices
  • identification of vulnerabilities across all dependencies
  • creation of product-specific, standardised SBOMs
  • generation of additional compliance and audit artefacts

All at no cost — we simply ask for your feedback throughout the process.

How it works

Your product source code repository will be analyzed by the OCCTET tooling, powered by the open source OSS Review Toolkit and ORT-server, further developed within the OCCTET project. Your data will be processed confidentially in our European ISO27001-certified hosting.

How to show interest

Please fill out the OCCTET Interest Form below stating your interest and a short description of the product you develop. We will get back to you to let you know if you were selected.

     👉Please fill out the OCCTET Interest Form

OCCTET Community Surpasses 150 SME Members!

December, 4, 2025

We are proud to announce that the OCCTET Community has passed 150 European SMEs who have already joined our network! 🙌✨

The community is a space where SMEs can:

  • Test and validate tools and solutions related to the Cyber Resilience Act
  • Connect with a network of companies, experts and stakeholders shaping Europe's cybersecurity landscape
  • Contribute real feedback to make solutions SME-friendly and future-proof

In a fast-moving digital environment, it's not enough to react, you need to take part in building Europe's secure and resilient future!

Are you our next cybersecurity changemaker? Join us and become part of the community!

     👉 Join the OCCTET Community.

Check Your Cybersecurity Compliance in Minutes

September, 18, 2025

OCCTET is proud to introduce its first self-assessment web-app, created to help SMEs take the first step toward stronger cybersecurity and easier compliance with European regulations such as the Cyber Resilience Act.

This free, easy-to-use tool gives SMEs an instant picture of their current cybersecurity and compliance status, highlights gaps and priorities, and points them toward practical resources from the OCCTET toolkit, including a compliance checklist, automated evaluation tools, a federated OSS assessment database, and reporting features.

By trying the web-app, organisations do not just gain a clearer view of their own readiness; they also join a growing OCCTET Community of early testers and contributors who are shaping the toolkit to reflect real SME needs. Together we are building an open, practical and community-driven approach to cybersecurity compliance, and this web-app marks the first step in that journey.

The Eclipse Foundation Launches OCCTET Project to Speed CRA Compliance

August, 14, 2025

The Eclipse Foundation, one of the world’s largest open source software foundations, today announced the launch of the OCCTET project, a European Commission-funded initiative aimed at helping small and medium-sized enterprises (SMEs) and open source developers navigate compliance with the Cyber Resilience Act (CRA).

The Open Source Compliance: Comprehensive Techniques and Essential Tools (OCCTET) project brings together a consortium of industry leaders, cybersecurity experts, and open source advocates to build free, open source tools that make regulatory compliance more accessible, transparent, and cost-effective.

...

     👉 Read the full announcement to learn more about the project’s goals.

Webinar Replay: Introducing OCCTET – Open Source Compliance & Security in Action

July, 1, 2025

This recorded webinar is a follow-up to the OpenChain & Friends conference held in Stuttgart (April 2025), where the OCCTET project was introduced for the first time.

The session featured presentations by Andreas Kotulla (Bitsea) and Martin von Willebrand (DoubleOpen), and included engaging discussion with participants on best practices for OSS compliance automation.

Watch the full webinar replay online to discover how OCCTET is shaping the future of open source security and compliance.

Watch Webinar - Project OCCTET.eu - The Why, What and How

Webinar - From regulation to solution: How the Cyber Resilience Act is reshaping the cybersecurity landscape

June, 16, 2025 | 2:00pm - 3:00pm CET

Digital regulations like the Cyber Resilience Act (CRA) are reshaping how companies approach cybersecurity. While the goal is to improve the security of digital products and services, small and medium-sized enterprises (SMEs) often struggle with putting these rules into practice.

This is where the OCCTET project comes in. The project is building a practical, open-source toolkit designed to help SMEs meet CRA requirements more easily, without creating unnecessary costs or complexity. The toolkit is being shaped directly by feedback from SMEs and experts to ensure it reflects the real challenges faced by small businesses.

During this online workshop, participants will gain insights into the project’s progress, get an exclusive first look at the forthcoming toolkit, and learn how their feedback can contribute to shaping the final version. Attendees will also have the opportunity to register as early users to test the toolkit and become part of a growing community helping to refine and implement its features.

Deliverable: CRA SME/FOSS Requirements and Self-Assessment

Thursday, April 22, 2025

This OCCTET publication explores the concrete needs and obstacles that SMEs and FOSS contributors face when it comes to complying with the Cyber Resilience Act. The Report is based on input from SMEs and FOSS stakeholders through interviews, surveys, and focus groups. It also draws expert consultations and a broad review of compliance literature and case studies.

Workshop Needs Analysis Report

Thursday, April 03, 2025

The findings of the Needs Analysis Workshop are now available in our report, which outlines the key takeaways and recommendations based on SME input. Just click this news or access the report directly in the Resources/Workshop section of our website.

Participate in OCCTET Survey on CRA and Open Source Compliance

Monday, March 19, 2025

Help us to shape and contribute to an Open-Source driven solution. We greatly appreciate your insights and expertise. The survey should take no more than 10 minutes.

OCCTET Needs Analysis Workshop

Monday, March 17, 2025

The Cyber Resilience Act (CRA) introduces new cybersecurity requirements for digital products, impacting SMEs, open-source developers, and software vendors across Europe. As compliance deadlines approach, many SMEs face uncertainty about how to meet these obligations, what tools to use, and what steps to take.

As part of its mission to simplify CRA compliance, OCCTET is hosting a Needs Analysis Workshop to gather insights from SMEs and key stakeholders. The goal is to identify compliance challenges, assess cybersecurity preparedness, and ensure that the OCCTET open-source toolkit is built to address real SME needs.

Agenda

  • Introduction to the OCCTET Project & Toolkit - Mikael Barbero (Eclipse Foundation)
  • Needs Analysis Miro Board Session - Davide Iaccarino (European DIGITAL SME Alliance)
  • Conclusion and Q&A

What to Expect from the Workshop

  • Introduction to OCCTET: Learn about the project’s mission, its objectives, and how it will help SMEs comply with the CRA.
  • Overview of the OCCTET Toolkit: Discover how the open-source compliance toolkit will support SMEs in managing cybersecurity risks and regulatory requirements.
  • Interactive MIRO Board Session: Engage in a collaborative discussion to map SME challenges and define the key features that the toolkit should include.
  • Q&A & Discussion: Share your thoughts, ask questions, and contribute directly to the project’s development.

This workshop is a key opportunity for SMEs to voice their challenges and influence the development of practical tools that will help them meet CRA requirements. By participating, you will be helping shape an accessible, open-source compliance solution tailored to SME needs.

Webinar - The Cyber Resilience Act and the Open-Source Community: Understanding the Impact and Managing Compliance

Monday, January 27, 2025

On 27 January 2025, OCCTET hosted a webinar diving into the Cyber Resilience Act (CRA) and its impact on SMEs, open-source community, and the broader digital landscape. With expert insights from our partners at the Eclipse Foundation, as well as contributions from the European Cyber Security Organisation (ECSO), the session explored the challenges and opportunities the CRA presents for open-source security and compliance.

The discussion covered key aspects of the CRA, including its new requirements for digital products, what it means for open-source developers, and how SMEs can navigate compliance more effectively. As part of OCCTET’s mission to support businesses in adapting to these changes, we also introduced how our open-source compliance toolkit will help SMEs meet CRA obligations with practical, accessible solutions.

Upcoming Events

📅 Friday, Sept. 11, 2026

CRA reporting obligations take effect

European Union

⚖️ First Cyber Resilience Act obligations applying.


Partners

  • AboutCode-logo
  • Bitsea-logo
  • DoubleOpen-logo
  • DSME-logo
  • Eclipse Foundation-logo
  • ExpertWare-logo
  • RedAlert-logo

Get Engaged

Help us build a collaborative, open-source–driven solution that empowers both SMEs and open-source communities.

Be part of the OCCTET journey!

Register to our newsletter and stay updated on progress, opportunities, and community events. (if you can’t see registration form please contact us directly)

Engages with Us Directly

Back to the top