No UK support scheme for open source maintainers facing EU Cyber Resilience Act obligations

openclaimed ·shipped ·
What is missing

The EU Cyber Resilience Act creates obligations for manufacturers and a novel open-source-software-steward category, phasing in through 2026-27. UK-based foundations, SMEs and maintainers whose software reaches the EU market must comply regardless of Brexit. The UK's own Cyber Security and Resilience Bill, at report stage in June 2026, focuses on NIS-regulated sectors and makes no equivalent provision for open source stewardship, and DSIT's Software Security Code of Practice from 2025 is voluntary and generic. EU communities get guidance through the Linux Foundation Europe and Eclipse CRA workstreams. No UK-facing help exists, and small UK maintainers are the people least equipped to interpret extraterritorial product law.

Why it matters

The UK hosts Europe's largest open source contributor base. If CRA compliance is left to individuals, projects will geofence the EU, relocate governance, or abandon maintenance, and each of those erodes the sovereign capability other gaps on this map aim to build.

What would fill it

A DSIT and NCSC CRA-readiness programme: plain-English guidance for UK maintainers and stewards, small tooling grants for compliance artefacts like SBOMs and security attestations, and a UK steward concept in future secondary legislation to keep UK-EU interoperability.

// Build now: First artefact: plain-English CRA guidance plus philanthropic tooling grants; statutory UK steward concept is the later end-state.

Why urgency 3

CRA obligations phase in through 2026-27 with no UK-facing help, so compliance left to individual maintainers risks geofencing or relocation during a live legislative window.

ATTEMPTS · 0 ACTIVEnon-exclusive
// nobody on this yet: be first
// no account: your claim posts publicly and lands in the thread below
THREAD · 0 POSTSreplies post via github, in publicopen on github ↗
// quiet so far. the dossier is the first post: reply below or take the gap.

More in Open source & public goods

Candidate entry from the July 2026 research pass, not yet validated by practitioner interviews. Added 2026-07-07 · last verified 2026-07-07 · review by 2027-01-07. Facts citing live processes (bills, consultations, contracts) decay quickly; re-verify against sources before acting.