
The EU Cyber Resilience Act puts a responsibility on the manufacturer for all components used. A SBOM is required and for each component, the manufacturer needs to do due diligence – both for open source and commercial components.
In order to help, there has been multiple projects that create some sort of assessment on the projects, in many cases with a “security badge”.
This talk is a call to action: Is it helpful to create more badges? There are so many that open source developers are overwhelmed, which unfortunately leads to them not doing anything. What can we do to simplify for Open Source projects and still assist manufacturers?
Conference partners







Organiser
