<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>CRA Adoption Best Practices on OCCTET Project</title><link>https://occtet.eu/best-practices/</link><description>Recent content in CRA Adoption Best Practices on OCCTET Project</description><generator>Hugo -- gohugo.io</generator><language>en</language><lastBuildDate>Tue, 06 Oct 2026 08:00:00 -0400</lastBuildDate><atom:link href="https://occtet.eu/best-practices/index.xml" rel="self" type="application/rss+xml"/><item><title>Secure FOSS Component Development</title><link>https://occtet.eu/best-practices/secure-foss-development/</link><pubDate>Tue, 06 Oct 2026 08:00:00 -0400</pubDate><guid>https://occtet.eu/best-practices/secure-foss-development/</guid><description>CRA Adoption Best Practices
Secure FOSS Component Development How open source projects can embed security across the lifecycle, govern transparently and handle vulnerabilities in proportion to risk, so that downstream integrators can manage their own CRA obligations.
Overview Secure FOSS development Open source stewards SME guidelines Checklists &amp;amp; templates On this page Enabling downstream risk management Risk-based orientation Security across the lifecycle Governance and transparency as risk controls Relevance to supply chain security Voluntary security attestations (Article 25) Cybersecurity activities for full lifecycle support Vulnerability handling Core elements of vulnerability handling Proportional maturity levels What this means for SMEs integrating FOSS Enabling downstream risk management For developers and maintainers of FOSS components, the CRA&amp;rsquo;s risk-based approach translates into enabling downstream risk management, rather than assuming direct regulatory responsibility.</description></item><item><title>Open Source Stewards</title><link>https://occtet.eu/best-practices/open-source-stewards/</link><pubDate>Tue, 06 Oct 2026 08:00:00 -0400</pubDate><guid>https://occtet.eu/best-practices/open-source-stewards/</guid><description>CRA Adoption Best Practices
Open Source Stewards The new actor introduced by the CRA: what open source stewards are, what the regulation expects from them, and how they help SMEs meet their own obligations.
Overview Secure FOSS development Open source stewards SME guidelines Checklists &amp;amp; templates On this page A new actor in the CRA Role and responsibilities Stewards as compliance enablers Cybersecurity attestations A new actor in the CRA The CRA takes the particularities of open source into account and introduces open source stewards as a new actor.</description></item><item><title>SME CRA Compliance Guidelines</title><link>https://occtet.eu/best-practices/sme-guidelines/</link><pubDate>Tue, 06 Oct 2026 08:00:00 -0400</pubDate><guid>https://occtet.eu/best-practices/sme-guidelines/</guid><description>CRA Adoption Best Practices
SME CRA Compliance Guidelines A practical, proportionate path for SMEs integrating FOSS components: who should focus on what, how to assess risk, which level of due diligence to apply and how to keep it up over time.
Overview Secure FOSS development Open source stewards SME guidelines Checklists &amp;amp; templates On this page SME personas: what to focus on From ad-hoc consumption to structured governance Due diligence for open source components Risk-based assessment of FOSS components Proportional due diligence levels Ongoing monitoring and lifecycle responsibility Consuming security attestations Common pitfalls and red flags The SME path to CRA-aligned FOSS adoption Decision matrix for FOSS component due diligence SME personas: what to focus on SMEs approach CRA adoption from different roles and levels of technical maturity.</description></item><item><title>Checklists &amp; Templates</title><link>https://occtet.eu/best-practices/checklists-and-templates/</link><pubDate>Tue, 06 Oct 2026 08:00:00 -0400</pubDate><guid>https://occtet.eu/best-practices/checklists-and-templates/</guid><description>CRA Adoption Best Practices
Checklists &amp;amp; Templates The SME Practical Implementation Toolkit: lightweight checklists and templates to tick online, print, or download into the tools you already use.
Overview Secure FOSS development Open source stewards SME guidelines Checklists &amp;amp; templates On this page SME practical implementation toolkit Minimum Viable Compliance (MVC) checklist Quick due diligence checklist FOSS component register Open source component record Vulnerability handling mini-playbook Dependency update policy SBOM checklist for SMEs SME practical implementation toolkit Reusable templates and practical guidance to help SMEs implement a proportionate and lifecycle-oriented approach to integrating FOSS components under the CRA.</description></item></channel></rss>