OpenSSF adds four members and publishes CRA readiness guidance
JetBrains, Emphere, A-Team Systems and DACHS IT joined the Linux Foundation initiative on October 6th, after manufacturer reporting under the EU Cyber Resilience Act began on September 11th.
By RuntimeWire Staff · Published
Primary source: Linux Foundation Newsroom
Why it matters
The CRA's manufacturer reporting clock has been running since September 11th, 2026, while open-source stewards' reporting obligations begin on December 11th, 2027. OpenSSF is trying to connect compliance guidance with upstream fixes and the companies that depend on them.

OpenSSF added JetBrains, Emphere, A-Team Systems and DACHS IT GmbH as General Members on October 6th, after the European Union's Cyber Resilience Act reporting obligations for manufacturers took effect on September 11th. The announcement places the foundation's latest membership growth alongside reporting obligations already in force for manufacturers.
OpenSSF, a Linux Foundation initiative that brings developers and security engineers together around open source security, also published new CRA readiness material at its Community Day Europe in Prague. The announcement bundled the four members with a practitioner's guide, a role-based user journey and an Ericsson case study. The package offers guidance for manufacturers subject to reporting obligations, while open-source stewards face a later date under the law.
The founders behind one new member
The membership announcement includes a startup built around a problem its founders experienced from opposite sides. Emphere CEO Ankit Kumar spent six years securing cloud infrastructure at Uber, where he filed vulnerability tickets; co-founder and CTO Pallav Gupta built systems at CarGurus and Twitter, where engineers had to fix them. The two met as roommates at Northeastern University and founded Emphere in 2025 to address the handoff between identifying vulnerabilities and getting fixes shipped.
"Emphere is glad to join OpenSSF to help the community outpatch attackers, human and AI alike," Kumar said in the announcement. In June, Emphere raised $2.1 million in pre-seed funding from AI2 Incubator and Outsiders Fund, GeekWire reported. That round backed a commercial remediation business; OpenSSF membership puts the founders in a forum where security work is shaped through shared tools and upstream collaboration.
The other new members bring different operating perspectives. A-Team Systems supports Linux and FreeBSD environments, according to its president, Adam Strohl, in the announcement. DACHS IT founder and CEO Alexander Schaber said the company has helped build cloud-native ecosystems through work with the Linux Foundation and CNCF, and is expanding that work to open source security. JetBrains, the Prague-founded developer-tools maker, said it wants to work collaboratively on security challenges as AI changes how software is built. Its representative in the announcement was Katherine Druckman, head of community and partnership engagement.
OpenSSF General Manager Steve Fernandez framed the work as a move toward coordination across the industry rather than isolated vulnerability fixes in the announcement. His background includes senior technology roles at NCR, AIG, L'Oreal and Coca-Cola, according to OpenSSF's staff biography. That enterprise experience is relevant to a foundation trying to turn open source security practices into work that product companies and infrastructure operators can adopt together.
A compliance deadline with two clocks
The European Commission says that, as of September 11th, 2026, manufacturers are required to report actively exploited vulnerabilities and severe incidents impacting the security of products with digital elements. The first warning is due within 24 hours of awareness, followed by a full notification within 72 hours. The CRA's reporting obligations for open-source software stewards begin on December 11th, 2027, according to the Commission's reporting guidance.

OpenSSF's CRA Readiness User Journey sorts resources by role, from maintainers and stewards to manufacturers. It points users to guides, training, working groups and technical projects. OpenSSF also highlighted a case study in which Ericsson Software Technology contributed more than 1,400 dependency updates and security fixes upstream after eliminating private forks. The figure comes from the foundation's account of the case; the announcement does not provide an independent measurement of the resources' adoption or their effect on incident rates.
Other third-quarter work listed in the announcement includes OpenBao v2.6, with per-namespace sealing and a workflow engine for cross-plugin communication, and BOMHort's entry into the OpenSSF Sandbox. BOMHort is a Kubernetes-native tool for visualizing and governing software bills of materials. Those projects broaden the announcement beyond policy guidance, while manufacturers need reporting processes and maintainers and stewards need clarity on their later obligations and how to support downstream users.
OpenSSF's membership expansion brings companies that build developer tools, operate infrastructure and sell security technology into that discussion. The announcement does not quantify new member contributions or show how many organizations have used the CRA materials. Its concrete test will be whether the guidance helps companies report on time and fix issues in upstream projects rather than creating another compliance document that sits beside the existing backlog.