EU Cyber Resilience Act (CRA)
The Cyber Resilience Act (Regulation (EU) 2024/2847) obliges manufacturers of products with digital elements to ensure cybersecurity across the entire lifecycle: risk assessment, vulnerability handling, SBOM and security updates. The regulation entered into force on 10 December 2024; the reporting obligations under Art. 14 apply from 11 September 2026, the full manufacturer obligations from 11 December 2027. Anyone shipping community open source must actively own its security.
SOURCE: Regulation (EU) 2024/2847 (EUR-Lex) ↗
CRA Readiness Assessment by ALVPHA Upstream →
Open source steward (CRA)
With the “open-source software steward”, the CRA introduces a category of actor of its own: organisations — foundations, for example — that provide sustained, systematic support for the development of specific open-source products intended for commercial activities. Stewards face a reduced set of obligations, not the full manufacturer catalogue. Importantly: merely building open source into your own products does not make you a steward — it makes you a manufacturer with the regular obligations for the overall product.
SOURCE: Regulation (EU) 2024/2847, Art. 24 (EUR-Lex) ↗
BSI TR-03183
Technical Guideline TR-03183 of the German Federal Office for Information Security (BSI) specifies cyber-resilience requirements for manufacturers and products; its second part defines formal and content requirements for SBOMs. In Germany it serves as the practical benchmark for setting up SBOM capability and vulnerability processes in a CRA-ready way.
NIS2
NIS2 (Directive (EU) 2022/2555) is the EU directive on network and information security. It obliges essential and important entities — including many operators of public infrastructure — to risk management, incident reporting and supply-chain security; national implementation specifies scope and duties. For organisations with a large open-source estate this means: demonstrable processes for inventory, vulnerabilities and the supply chain, including for software without a vendor.
SOURCE: Directive (EU) 2022/2555 (EUR-Lex) ↗
BSI IT-Grundschutz
IT-Grundschutz is the BSI’s methodology for information security management, firmly established in German public administration: modules, threats and requirements from which an auditable security concept is derived — compatible with ISO 27001. For open-source operations it provides the evidence framework that inventory, vulnerability management and operating processes feed into.
Evidence for NIS2 and IT-Grundschutz in the public-sector offering →
Digital sovereignty
Digital sovereignty is the ability of states and organisations to shape and operate their digital infrastructure autonomously — without critical dependence on individual vendors. Open source is a central building block for this, but it shifts responsibility inward: with no vendor behind the software, a clearly assigned operational owner is needed for security, lifecycle and further development.
openDesk
openDesk is the open-source workplace for German public administration, built from established open-source components and stewarded by the Centre for Digital Sovereignty (ZenDiS). It exemplifies the administration’s strategic turn towards open source — and the follow-on question of who permanently owns operations, security processes and upstream work for the components in use.
SOURCE: opendesk.eu ↗
Direct award & negotiated procedure
Direct award (Direktauftrag) and the negotiated procedure without a call for competition (Verhandlungsvergabe) are simplified procedures of German procurement law below the EU thresholds: a direct award places a contract without a formal procedure, while in a negotiated procedure selected companies are invited directly to submit offers. Which value limits apply depends on the contracting authority and the current rules — the assessment always rests with the contracting authority.
Procurement notes for German federal authorities →