LINUX FOUNDATION RESEARCH

We’re investigating the impact of open source collaboration to solve the world’s most pressing challenges.

LF Research about page cover tiles

About LF Research

LF Research publishes actionable and decision-useful insights into open source software, hardware, standards, and data based on empirical research methodologies. Through leveraging community networks, project databases, surveys, and qualitative findings, and through its commitment to best practices in primary research, Linux Foundation Research is the definitive home for data-driven insights into open source for the benefit of governments, enterprises, and society at large.

Pathways to Cybersecurity Best Practices in Open Source

This case study report from the Linux Foundation investigates the impacts of the Cyber Resilience Act on open source software.

 

Web Assets_Pathways to Cybersecurity Best Practices in Open Source_2025 Report_Thumbnail_Cover

Participate in Our Research

Join the LF Research Forum and participate in our surveys and interviews to give back to your community and earn events & training discounts!

Interested in conducting research?

Review our prospectus for more information, and email us at research@linuxfoundation.org

 

lfresearch_benefits

Unaware and Uncertain: The Stark Realities of Cyber Resilience Act Readiness in Open Source

Download Report
This survey-based report investigates the awareness and readiness of the open source community to comply with the EU's Cyber Resilience Act (CRA). The report reveals significant knowledge gaps in the open source ecosystem that must be addressed to adequately comply with the new regulation while maintaining sustainable open source development.
 
The survey data shows that most respondents are unfamiliar with the CRA, are uncertain about compliance deadlines, and are unaware of non-compliance penalties. The recommendations developed from these findings include establishing a more active role for manufacturers in cybersecurity, increasing funding and legal support to open source projects, and developing guidance and best practices to prevent unintended negative impacts on development.
 
Authors
  • Adrienn Lawson, The Linux Foundation
  • Stephen Hendrick, The Linux Foundation
  • Foreword by Christopher (CRob) Robinson, Open Source Security Foundation (OpenSSF)
Additional Resources

Our Team

Filter by: