OpenSSF Shares Expanded Membership and New Global Policy Resources During Community Day Europe

PR Newswire

Four new members and significant CRA resources released by the Foundation as systemic collaboration on open source security gains momentum

PRAGUE, Oct. 6, 2026 /PRNewswire/ — The Open Source Security Foundation (OpenSSF), a cross-industry initiative of the Linux Foundation focused on sustainably securing open source software, today announced new membership growth, welcoming A-Team Systems, Emphere, DACHS IT GMBH, and JetBrains to the foundation. The OpenSSF also notes new and renewed efforts to deepen Cyber Resilience Act (CRA) preparedness, in both the EU and beyond, releasing guides, user journeys, and a case study.

OpenSSF Shares Expanded Membership and New Global Policy Resources During Community Day Europe

“Securing the open source ecosystem requires proactive, systemic collaboration across the entire industry.”

Regulatory pressure grows for companies selling products to the EU, as the mandatory vulnerability and incident reporting aspect of the CRA came into effect last month. Clear, direct, and easy-to-understand guidance on this global legislation is critical, especially with AI significantly hastening vulnerability discovery and reporting. With bugs easier to find and reporting windows shrinking, OpenSSF continues to serve as a trusted, neutral hub for CRA education, collaboration, and security. 

“Securing the open source ecosystem is no longer just about patching isolated vulnerabilities. It requires proactive, systemic collaboration across the entire industry,” said Steve Fernandez, General Manager of OpenSSF. “Initiatives like the Open Secure AI Alliance and pioneering projects such as Akrites reflect this critical shift. We are moving beyond fragmented defenses and building a unified front, equipping the global developer community with the comprehensive frameworks needed to secure the next generation of software. OpenSSF and our members are a key element in this shift.”

New OpenSSF members include A-Team Systems, Emphere, DACHS IT GMBH, and JetBrains who join the Foundation as General Members. These organizations join a community of working groups, technical groups, and experts that are shaping the future of OpenSSF and software security. Their membership has a direct impact on the long term sustainability of open source and the projects that are critical to modern infrastructure.

Q3 Foundation Achievements
In addition to membership growth in the third quarter of 2026, OpenSSF achieved the following milestones:

  • Publication of the CRA Readiness practitioner’s guide — OpenSSF published practical compliance guidance for the EU Cyber Resilience Act. With CRA obligations now legally live, this guide converts policy analysis into actionable steps for maintainers and vendors who must comply. OpenSSF also released a CRA Readiness User Journey to support greater preparedness around the important regulation, regardless of where an organization is starting.
  • CRA case study: 1,400 upstream fixes from Ericsson — Ericsson Software Technology eliminated private forks and contributed over 1,400 dependency updates and security fixes upstream to meet CRA obligations, guided by OpenSSF principles. This case study is concrete proof that “fix it upstream, not in a fork” scales at enterprise level — behavior that fosters a more secure software supply chain.
  • User Journeys for role-based security — OpenSSF rolled out role-based “User Journeys,” for security practitioners looking to find the right guidance and resources. These curated navigation paths for developers, security engineers, OSPO leaders, marketers, and executives ensure that the right information makes it into the hands of those that seek it out.
  • OpenBao v2.6 release — A new version of the open source secrets management tool shipped with per-namespace sealing and a new workflow engine for cross-plugin communication.
  • BOMHort joined OpenSSF Sandbox — A new Kubernetes-native SBOM visualization and governance tool entered the OpenSSF Sandbox. As SBOMs shift from best practice to regulatory requirement (CRA, NIST SSDF, EO 14028), tooling that helps teams actually manage and query SBOMs at scale, not just generate them, fills an important security gap.

Supporting Quotes

“Open source software has been central to our work supporting Linux and FreeBSD systems in critical production environments for more than two decades. We depend on the security work happening throughout the open source ecosystem. OpenSSF provides part of the foundation that makes secure, reliable production operations possible. Joining OpenSSF reflects our commitment to materially supporting the people who make open source what it is today. We look forward to contributing an infrastructure operations perspective and supporting the important work OpenSSF is doing across the open source community.”
– Adam Strohl, President, A-Team Systems

“Virtually every critical enterprise builds on an open source foundation. When everyone relies on the digital common ground, maintaining its safety is a shared responsibility. Securing the supply chain helps ensure that open-source software remains safe, trusted, and open for everyone. Through our continuous work in the Linux Foundation and CNCF, we’ve helped build cloud-native ecosystems. Now, through OpenSSF, we’re expanding our work to help protect and nurture the security foundation they rely on.”
– Alexander Schaber, Founder and CEO, DACHS IT GMBH

“Open source is shared code, and so is the responsibility to secure it. Emphere is glad to join OpenSSF to help the community outpatch attackers, human and AI alike.”
– Ankit Kumar, CEO, Emphere

“Software development is at an inflection point. AI is changing how software is built and creating new security challenges, making it more important than ever that developers can understand, verify and trust the software they produce. JetBrains has supported professional software development for more than two decades, and we believe staying ahead of these challenges is best done collaboratively and in the open. OpenSSF brings together some of the strongest expertise in the industry, and we are glad to join the community and help shape the future of secure software development.”
– Katherine Druckman, Head of Community and Partnership Engagement, JetBrains

Events and Gatherings
OpenSSF members are gathering this week in Prague at OpenSSF Community Day Europe and hosting the Workshop: Operationalizing the Cyber Resilience Act on Friday, October 9. To get involved with the OpenSSF community, join us at the following upcoming events: AGNTCon + MCPCon North America (San Jose, California; October 22-23) and Open Source SecurityCon North America (Salt Lake City, Utah; November 9).

Additional Resources

About the OpenSSF
The Open Source Security Foundation (OpenSSF) is a cross-industry organization at the Linux Foundation that brings together the industry’s most important open source security initiatives and the individuals and companies that support them. The OpenSSF is committed to collaboration and working both upstream and with existing communities to advance open source security for all. For more information, please visit us at openssf.org.

About the Linux Foundation
The Linux Foundation is the world’s leading home for collaboration on open source software, hardware, standards, and data. Linux Foundation projects, including Linux, Kubernetes, Model Context Protocol (MCP), OpenChain, OpenSearch, OpenSSF, OpenStack, PyTorch, Ray, RISC-V, SPDX and Zephyr, provide the foundation for global infrastructure. The Linux Foundation is focused on leveraging best practices and addressing the needs of contributors, users, and solution providers to create sustainable models for open collaboration. For more information, please visit us at linuxfoundation.org.

The Linux Foundation has registered trademarks and uses trademarks. For a list of trademarks of The Linux Foundation, please see its trademark usage page: www.linuxfoundation.org/trademark-usage. Linux is a registered trademark of Linus Torvalds.

Media Contact
Grace Lucier
The Linux Foundation
pr@linuxfoundation.org 

Cision View original content to download multimedia:https://www.prnewswire.com/news-releases/openssf-shares-expanded-membership-and-new-global-policy-resources-during-community-day-europe-302898933.html

SOURCE OpenSSF

About The Author