No UK support scheme for open source maintainers facing EU Cyber Resilience Act obligations
The EU Cyber Resilience Act creates obligations for manufacturers and a novel open-source-software-steward category, phasing in through 2026-27. UK-based foundations, SMEs and maintainers whose software reaches the EU market must comply regardless of Brexit. The UK's own Cyber Security and Resilience Bill, at report stage in June 2026, focuses on NIS-regulated sectors and makes no equivalent provision for open source stewardship, and DSIT's Software Security Code of Practice from 2025 is voluntary and generic. EU communities get guidance through the Linux Foundation Europe and Eclipse CRA workstreams. No UK-facing help exists, and small UK maintainers are the people least equipped to interpret extraterritorial product law.
The UK hosts Europe's largest open source contributor base. If CRA compliance is left to individuals, projects will geofence the EU, relocate governance, or abandon maintenance, and each of those erodes the sovereign capability other gaps on this map aim to build.
A DSIT and NCSC CRA-readiness programme: plain-English guidance for UK maintainers and stewards, small tooling grants for compliance artefacts like SBOMs and security attestations, and a UK steward concept in future secondary legislation to keep UK-EU interoperability.
// Build now: First artefact: plain-English CRA guidance plus philanthropic tooling grants; statutory UK steward concept is the later end-state.
CRA obligations phase in through 2026-27 with no UK-facing help, so compliance left to individual maintainers risks geofencing or relocation during a live legislative window.