Open Source Conference Luxembourg

Florian Effenberger

Florian has been a free and open source enthusiast since 2004. He works for The Document Foundation, the nonprofit behind LibreOffice and previously volunteered in marketing and infrastructure. As a student, he designed educational computer systems for schools, including software deployment based on free software and was a frequent contributor to a variety of professional magazines worldwide on topics such as free software, open standards and legal matters. A proud uncle, he loves to spend time with the family and occasionally blogs about various topics, including community building, free and open source software and computer networks. Based around Munich, he helped to create the local open source meetings and shaped the tasty idea of open source cooking.


Sessions

10-07
14:00
30min
Why free software and digital sovereignty are made for one another
Florian Effenberger

While the term "digital sovereignty" came to fame in particular over the last couple of years, many of its underlying principles have ever since been shared with FLOSS projects throughout the globe. The use of open standards and file formats, a free software license, worldwide collaboration across the borders of continents, organized in democratically driven projects: this is the recipe to give everyone control over their data and their digital lives. While Digital Sovereignty is a global movement for our digital commons, it requires action and investment on a local level. It makes countries and governments more independent and more resilient and it helps every citizen to overcome the digital gap. Based on the example of LibreOffice, in this talk Florian explains the goal of the project, the mission of the nonprofit foundation behind, and gives insight into some of the recent adoptions and their success stories - and explains why a sole Europe-centric view does not match the reality of the worldwide project.

Topic: Community, culture, governance and business
Governance, compliance and business
10-07
14:30
30min
The Cyber Resilience Act and Open Source: where do we stand? LibreOffice's conformity journey as a working example
Benjamin JEAN, Florian Effenberger

Where does the Cyber Resilience Act leave Open Source projects? The first obligations for manufacturers apply from 11 September 2026: actively exploited vulnerabilities and severe incidents must be reported, with an early warning at 24 hours and a notification at 72 hours. Article 24(3) extends part of this to Open Source stewards, the Regulation's new category for foundations, but only where they take part in development or host its infrastructure. The Regulation applies in full, with a declaration of conformity and CE marking, from 11 December 2027.

The first part is a state of play for Open Source: who is in scope, how the commercial activity test works, and where manufacturers, stewards and contributors sit; what the Commission's guidance of 27 July 2026 settled; what the implementing regulation on important and critical products changed through its core functionality test; and what remains open while no harmonised standard is cited in the Official Journal, leaving no presumption of conformity.

The second part puts this into practice with The Document Foundation, which aims for the most demanding level of conformity for LibreOffice and treats its own status, whether manufacturer, steward or distributor, as something to establish rather than assume. We will walk through the work done with inno³ since spring 2026: Articles 13 and 14, the Annex I essential requirements, the Annex VII technical documentation, the resulting gap analysis and where TDF stands today. Reusable material will feed the next CRA and Open Source guide from inno³ and the CNLL.

Topic: Community, culture, governance and business
Governance, compliance and business