Functional criticality
Does the component handle vital functions like authentication, cryptography, update mechanisms, or network exposure?
CRA Adoption Best Practices
Practical, risk-based guidance for SMEs and open source communities to adopt and integrate Free and Open Source Software (FOSS) in line with the EU Cyber Resilience Act (CRA).
These pages translate the CRA’s risk-based mandate into actionable best practices for the open source community, and offer SMEs a clear path to secure and compliant FOSS integration. They focus on integrating security across the lifecycle, ensuring governance and transparency, and building supply chain resilience.
Lightweight tools from the SME Practical Implementation Toolkit, ready to tick online, print or download into your own tracker.
Under the CRA, cybersecurity obligations are not uniform or prescriptive. Manufacturers must implement “appropriate and proportionate” security measures based on identified risks, rather than striving for absolute security. Obligations are scaled based on:
For FOSS components, this means that the same open source library might pose a low risk in one scenario and a high risk in another, entirely dependent on how and where it is deployed. A risk-based approach looks beyond the fact that a component is open source and assesses:
Does the component handle vital functions like authentication, cryptography, update mechanisms, or network exposure?
Is the component exposed to untrusted inputs or external interfaces?
How many indirect dependencies are introduced, and how well are they understood?
Is the project actively maintained? Are security issues promptly acknowledged and addressed?
How is the component configured, hardened, and isolated within the final product?
These factors, and not the development model itself, are what determine the required level of due diligence and security controls.
The guidance is informed by anonymised, aggregated results from voluntary assessments on the OCCTET CRA Self-Assessment Platform. No company-level or personal data is included.
The challenge is not introducing complexity, but introducing clarity.
How mature is your organisation?
Measure your own preparedness in minutes with the free and confidential CRA self-assessment.