What Happens When Your Open Source Maintainer Disappears (EU CRA Edition)

You find a vulnerability in an open source package. You check for a fix. There isn’t one, because the maintainer walked away from the project two years ago. Under the EU Cyber Resilience Act (CRA), what happens next isn’t ambiguous.

That was the question one attendee asked live during our recent webinar with Red Hat and Bitsea, and Roman Zhukov’s answer started with three words: “you own the problem.” What he laid out after that, including the specific options for handling it and where SBOMs fit into catching this before it becomes an incident, is one of the moments worth hearing in his own words in the recording.

It’s also a good preview of the webinar itself. We sat down with Roman Zhukov, Open-Source Security Strategy at Red Hat, and Dr. Andreas Kotulla, Founder & CEO of Bitsea, for “SBOMs or Bust: Automating Compliance for EU CRA and Beyond.” Alex Rybak, our Sr. Director of Product Management, hosted. The conversation covered where the CRA stands today, how a manufacturer the size of Red Hat is operationalizing compliance across eight internal workstreams, and what it actually takes for a mid-sized company to go from zero to CRA-ready.

Where attendees actually stand

Two dates matter more than any others on the CRA calendar: September 11, 2026, when vulnerability reporting obligations kick in, and December 11, 2027, when full compliance is required. We polled the room live, and the results say a lot about how much runway is actually left.

When we asked which regulations were most relevant to their organization, 9 out of 12 respondents named the CRA specifically, alongside NIS2, DORA, PCI DSS, and the EU Product Liability Directive. Nobody in the room is dealing with just one framework.

On compliance progress, 7 of 13 attendees said they’re in the middle of the process, 4 said they’d recently started, and 1 hadn’t started at all. Only one respondent said they’re fully compliant and it’s part of standard operating procedure. That means roughly 92% of the room is still actively working through it.

We also asked which vulnerability data source they trust most. NVD (the U.S. National Vulnerability Database) led with 5 of 12 votes, followed by CISA KEV with 3 and the EU Vulnerability Database (EUVD) with 2. One respondent told us they use a combination of NVD and vendor data because “our customers tend to use NVD most.”

Red Hat’s case for treating this as a program, not a project

Roman walked through how Red Hat structured its CRA response around three roles it plays at once: manufacturer, open source steward for projects like Fedora and Ansible, and upstream contributor. That triple role shaped an 8-workstream program spanning awareness, vulnerability management, conformity assessment, data collection, and legal, built roughly a year and a half ago.

His core point was one worth repeating to your own leadership: CRA compliance can’t sit with a single department, because it touches roadmaps, security, legal, and open source strategy all at once. He also flagged something we don’t hear often enough: early drafts of the CRA risked real harm to the open source ecosystem before industry input helped shape the final requirements.

Bitsea’s five-step path, and the timeline nobody wants to hear

Andreas walked through the five-step framework Bitsea built from the EU-funded OCTET project, starting with a free assessment to determine whether the CRA even applies to your product. From there it moves into gap analysis, SBOM generation, documentation, and ongoing risk monitoring.

The honest answer on timeline: when Alex asked what a mid-sized company should budget to go from step one to full compliance, Andreas didn’t sugarcoat it. We’ll let you hear the exact number he gave in the recording, but the software composition analysis step alone is the long pole.

Unified SBOM management to ease manual vulnerability management

Alex covered how Anchore Enterprise v6, which we announced earlier this month, helps teams generate unified SBOMs and VEX documents across application versions so security teams aren’t chasing every vulnerability manually. He also pointed attendees to Syft and Grype, our open source SBOM generator and vulnerability scanner, which together have over 50 million downloads.

Watch the full session

We covered a lot more than we can fit here: the full CRA timeline and product classification rules, Red Hat’s approach to continuous compliance without adding overhead, and the complete Q&A with both partners. If you’re one of the 92% still working through your CRA journey, this is 45 minutes worth blocking off.

Watch the on-demand webinar


Further resources

The EU CRA demands a shift from static security reports to continuous Live Telemetry. Learn how to operationalize compliance, enforce deterministic policy gates, and automate your path to an audit-ready software supply chain.