Loading…
Tuesday October 6, 2026 4:45pm - 5:10pm CEST
The Cyber Resilience Act settled the legal side of the open source relationship: product responsibility stays with the manufacturer, stewards carry a light-touch regime, maintainers shielded from manufacturer-grade duties. The operational side is far less settled. Manufacturers must consume and interpret upstream security signals, but what that takes is rarely described from the manufacturer's seat.

This session walks that seat in concrete terms. From 11 September 2026, a manufacturer has 24 hours from awareness of active exploitation to file an early warning. Awareness at that speed is only dependable when machine-readable upstream signals (SBOMs, VEX, provenance, project health) are continuously correlated against what was actually shipped, per product, per configuration, with the record written as it happens, not assembled afterwards.

It also covers the return path: contributions rather than contracts, funding rather than warranties, and a defence of the transparency-versus-assurance boundary that keeps the voluntary model sustainable.

Presented three and a half weeks after the reporting duty goes live, it closes with first field observations from September.
Speakers
avatar for William Janssen

William Janssen

CTO & Head of Engineering, TrustEngine
William Janssen is CTO and Head of Engineering, and author of a Dutch-language book on the EU Cyber Resilience Act. He spent his career building and maintaining software products, from patient portals in healthcare to a PaaS platform, and knows what shipped software costs to support... Read More →
Tuesday October 6, 2026 4:45pm - 5:10pm CEST
Panorama Hall

Attendees (1)


Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link