Skip to content

Build1 publisher3 min readPublished

OpenSSF's CRA guide arrives with EU manufacturers already on a 24-hour reporting clock

OpenSSF published CRA readiness guidance for manufacturers that have owed 24-hour warnings on exploited vulnerabilities since September 11. Open-source stewards do not start reporting until December 2027, so for 15 months the duty sits with product teams alone.

The Engineer · Build desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying OpenSSF's CRA guide arrives with EU manufacturers already on a 24-hour reporting clock
Generated illustration

What happened

  • On October 6, OpenSSF announced four new General Members, JetBrains, Emphere, A-Team Systems and DACHS IT GmbH, in the same release as the CRA material.
  • The CRA Readiness User Journey sorts resources by role, from maintainers and stewards to manufacturers, and points to guides, training, working groups and technical projects.
  • By OpenSSF's account, Ericsson Software Technology eliminated its private forks and contributed more than 1,400 dependency updates and security fixes upstream.
  • After the 24-hour early warning, a manufacturer's full notification is due within 72 hours of becoming aware of the vulnerability or incident.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • constraint A warning due 24 hours after awareness forces manufacturers to keep a current map of which shipped versions contain which upstream code, and a role-sorted reading list does not supply that map.
  • decision Teams on private forks have to choose between backporting fixes themselves inside the 24-hour window and moving their changes upstream, the route Ericsson took by OpenSSF's account.
  • constraint Manufacturers building a reporting process on the journey now must judge whether it works from OpenSSF's own account of one case, with no outside measurement to check it against.

The manufacturer duty covers actively exploited vulnerabilities and severe incidents affecting the security of products with digital elements, according to the European Commission [3]. A plan keyed to the stewards' 2027 start is keyed to someone else's deadline [2]. Until then, when an exploited flaw sits in an open-source component, the company that shipped the product is the party with a CRA report to file [1][2].

The clock starts at awareness [4]. The early warning and the full notification are 48 hours apart [16]. In my view the 24-hour step is an inventory problem first. Inside a day, someone has to establish whether the exploited code is in what shipped, and in which version.

OpenSSF's role-based journey is an index of other material [7]. It shipped alongside a practitioner's guide at the foundation's Community Day Europe in Prague [6]. I'd use the journey as the reading list for a reporting runbook. The runbook itself, with an owner for each step and an hour budget against the 24-hour warning, is still the manufacturer's to write.

The Ericsson case holds the package's one quantified result. The order of events in it is the useful part: the private forks went first, and the upstream contributions followed [8]. The announcement does not provide an independent measure of the resources' adoption or of any effect on incident rates [9]. A team tracking upstream takes a fix by moving a version. A team on a private fork has to backport the fix, test it and ship it inside the same day. For the 1,400 figure to transfer, another codebase would need comparable forks to retire and upstream maintainers willing to accept the changes [8].

The membership additions came 25 days after the manufacturer clock started [17]. Of the four, Emphere is built around the problem the clock exposes. Its founders started it in 2025 to address the handoff between identifying vulnerabilities and getting fixes shipped [10]. CEO Ankit Kumar was the one filing vulnerability tickets during his six years on cloud infrastructure security at Uber. CTO Pallav Gupta built systems at CarGurus and Twitter, where engineers had to fix them [10]. "Emphere is glad to join OpenSSF to help the community outpatch attackers, human and AI alike," Kumar said [11]. Emphere raised $2.1 million in pre-seed funding in June from AI2 Incubator and Outsiders Fund, GeekWire reported [12].

OpenSSF is a Linux Foundation initiative [14]. Its general manager, Steve Fernandez, framed the work as coordination across the industry instead of isolated vulnerability fixes, according to the announcement [13]. In the material published so far, Ericsson's upstream count is the one place that coordination shows up as a number [8].

What to watch

  • Whether OpenSSF or the European Commission publishes figures on how many manufacturers use the readiness journey, or on any change in incident rates.
  • Whether other manufacturers publish fork-elimination results comparable to Ericsson's 1,400-plus upstream contributions.
  • How open-source stewards prepare for their own reporting obligations ahead of December 11, 2027.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories