Open Source Conference Luxembourg

The Cyber Resilience Act and Open Source: where do we stand? LibreOffice's conformity journey as a working example

Where does the Cyber Resilience Act leave Open Source projects? The first obligations for manufacturers apply from 11 September 2026: actively exploited vulnerabilities and severe incidents must be reported, with an early warning at 24 hours and a notification at 72 hours. Article 24(3) extends part of this to Open Source stewards, the Regulation's new category for foundations, but only where they take part in development or host its infrastructure. The Regulation applies in full, with a declaration of conformity and CE marking, from 11 December 2027.

The first part is a state of play for Open Source: who is in scope, how the commercial activity test works, and where manufacturers, stewards and contributors sit; what the Commission's guidance of 27 July 2026 settled; what the implementing regulation on important and critical products changed through its core functionality test; and what remains open while no harmonised standard is cited in the Official Journal, leaving no presumption of conformity.

The second part puts this into practice with The Document Foundation, which aims for the most demanding level of conformity for LibreOffice and treats its own status, whether manufacturer, steward or distributor, as something to establish rather than assume. We will walk through the work done with inno³ since spring 2026: Articles 13 and 14, the Annex I essential requirements, the Annex VII technical documentation, the resulting gap analysis and where TDF stands today. Reusable material will feed the next CRA and Open Source guide from inno³ and the CNLL.


Part 1 - State of play: the CRA for Open Source projects (about 10 minutes)

  • The two dates that matter: reporting obligations under Article 14 from 11 September 2026, including for products already on the market, and full application on 11 December 2027.
  • Who is in scope: the commercial activity trigger, manufacturers, open-source software stewards (Articles 3(14) and 24), and where individual contributors stand.
  • What the Commission guidance of 27 July 2026 (C(2026) 5252) settled, and what it did not.
  • Implementing Regulation (EU) 2025/2392 and the core functionality test for important and critical products, plus the lighter route of Article 32(5) for products released as free and open source software.
  • What is still open: no harmonised standard has yet been cited in the Official Journal, so the Article 27 presumption of conformity is not available. SBOM granularity, support periods and small teams remain unsettled.

Part 2 - Practice: LibreOffice and The Document Foundation (about 10 minutes)

  • Why a foundation with no commercial activity of its own still ends up doing this work, and how it approached its own qualification rather than assuming one.
  • The method used with inno3 since spring 2026: three workshops mapping Article 13 and Article 14 obligations and the Annex I essential requirements onto what the project already does, then a gap analysis.
  • The recurring finding: what is missing is rarely security work, it is written evidence of practices that already exist. Under the CRA an auditor treats those two as the same thing.
  • The SBOM question in practice: perimeter before fields, and why declaring what an SBOM covers matters more than making it exhaustive.
  • What other projects can take away, and what will feed the next version of the CRA & Open Source guide maintained with the CNLL.

Takeaways for the audience

Attendees should leave able to tell whether the CRA applies to their project, under which qualification, what the first hard deadline actually requires of them, and which pieces of evidence to start writing down now.

Benjamin JEAN

Known for his work on open source and open data, Benjamin Jean is currently CEO of inno³, an independent consultancy specialising in open models at the intersection of private (industrial and social economy), public (administrations and municipalities) and community actors. He is also co-founder and former president of " Open Law*, Le droit ouvert ", a French non-profit organisation promoting activities to support the transformation of the legal sector through digital co-creation programmes based on the principles of open data, open source and open innovation. Strongly mobilised by the opportunities offered by these open models in the digital transformation of professions and major industrial sectors, Benjamin Jean regularly intervenes as an expert at several events and conferences on these topics. In fact, in addition to his full-time job at inno3, he teaches intellectual property law at several universities, is a Master Conferences at Science Po and works as a consultant at the law firm Vercken & Gaullier. Actively involved in the open digital ecosystem, he collaborates and participates with many committed actors in this field. He is also present in several free software communities, administrator of Framasoft, and co-founder of Veni Vidi Libri and the annual conference cycle " European Open source & Free Software Law Event " (EOLE).