Opens in a new tab
vmblog logo 2024 wht (updated)

Thabang Mashologu on Open Regulatory Compliance (ORC) Momentum and the Launch of the OCCTET Project – VMblog QA

Share: 

David Marshall | Published: August 15, 2025

 

The open source community is mobilizing in unprecedented fashion as the European Union’s Cyber Resilience Act (CRA) approaches its September 2026 reporting deadline, with penalties reaching up to �15 million or 2.5% of global turnover for non-compliance. The Eclipse Foundation’s Open Regulatory Compliance (ORC) Working Group has more than doubled its membership to over 50 organizations in just months, attracting technology giants Microsoft and Red Hat as strategic members alongside GitHub, Google, Nokia, and Mercedes-Benz.

This surge in industry participation coincides with the launch of the European Commission-funded OCCTET Project, designed to deliver free, open source compliance tools specifically targeting small and medium-sized enterprises. With the CRA’s three-year transition period already underway since December 2024 and full enforcement looming in December 2027, the Eclipse Foundation is positioning itself as the critical bridge between regulatory authorities and the open source ecosystem, leveraging its formal liaison status with European standardization bodies to ensure open source perspectives shape compliance requirements from the ground up.

Read this VMblog Q&A as Thabang Mashologu, Vice President of Community and Outreach at the Eclipse Foundation, discusses the surge of industry support for the Open Regulatory Compliance (ORC) Working Group, the group’s first major deliverable, and a new European Commission-funded initiative, the OCCTET Project. 

VMblog:  Before we jump into the announcements, can you give us a quick background on the Eclipse Foundation?

Thabang Mashologu:  The Eclipse Foundation is a Brussels-based open source software foundation and one of the largest in the world. While many know us for technologies that millions of developers and industries around the world rely on every day, such as the Eclipse IDE, the Open VSX extension registry, Jakarta EE, and Adoptium, our scope extends far beyond that. We currently host more than 400 open source projects across a range of technology domains, software defined vehicles, AI, cloud and edge applications, embedded, IoT, open source RISC-V cores, and more.

VMblog:  Now for the news. You have two separate but related announcements today. Can you walk us through them?

Mashologu:  Absolutely. First, the Open Regulatory Compliance (ORC) Working Group, which we launched in September 2024 to help organisations navigate governmental regulations, such as the EU’s Cyber Resilience Act (CRA), has just prepared its first major deliverable: a curated set of resources that organisations can use as they begin their compliance journey.

We’re also welcoming a wave of high-profile new members: Microsoft and Red Hat as strategic members, joined by ekxide, GitHub, Google, and Open Source Matters. Since its launch, ORC has more than doubled to over 50 members, including leading open source foundations and global technology companies such as Nokia, Mercedes-Benz, and now Microsoft, Red Hat,  GitHub, and Google. The caliber of these organisations reflects the working group’s momentum and growing influence.

Alongside this, we’re introducing the OCCTET project, an EU-funded initiative designed to address the challenges of CRA compliance head-on. By delivering open, practical, and accessible tools and resources, OCCTET aims to reduce the complexity and cost of compliance, enabling small- and medium-sized enterprises to focus on innovation without compromising security.

VMblog:  For those unfamiliar, what role does the ORC Working Group play?

Mashologu:  ORC, as a diverse coalition of software supply chain stakeholders, bridges a critical gap between regulatory authorities and the open source ecosystem. By collaborating with regulators and standards bodies, we help formalize industry best practices so they can be properly referenced in legislation, ensuring policymakers understand the nuances of the open source ecosystem. This approach enables all open source stakeholders, including industry leaders, small and medium-sized enterprises (SMEs), and OSS foundations, to meet regulatory requirements while improving software quality and security.

VMblog:  And for the second announcement, the OCCTET project?

Mashologu:  Yes, the Open Source Compliance: Comprehensive Techniques and Essential Tools (OCCTET) project is a separate but complementary initiative funded by the European Commission. It brings together a consortium of industry leaders, cybersecurity experts, and open source advocates to build free, open source tools that make regulatory compliance more accessible, transparent, and cost-effective.

The OCCTET toolkit will include:

  • A CRA compliance checklist
  • Automated evaluation methods and tools
  • A reporting tool for generating compliance documentation
  • A federated database for publishing OSS component assessments
  • Inventories of automatic dependency analysis tools

These solutions are particularly aimed at SMEs, helping them meet compliance obligations without stifling innovation.

VMblog:  Is CRA compliance really that urgent? 

Mashologu:  Absolutely. The CRA officially came into force in December 2024, triggering a three-year transition period (see http://orcwg.org/cra for details). CRA reporting requirements begin on 11 September 2026, and all requirements take effect on 11 December 2027.

At the same time, the European Commission is moving quickly on the standardisation agenda. A draft request for harmonized standards was issued in April, and these standards must be finalized well ahead of enforcement to give the industry time to adapt.

The CRA establishes mandatory cybersecurity requirements for all digital products sold in the EU, including software. It applies to manufacturers, software vendors, and indirectly to maintainers, requiring secure development practices and transparent vulnerability handling across entire software supply chains. Non-compliance can result in penalties of up to �15 million or 2.5 percent of global turnover, whichever is greater. The stakes are high, and the deadlines are approaching fast, so preparation should already be underway.

VMblog:  How exactly will the ORC Working Group help with CRA compliance?

Mashologu:  Our first deliverable is an inventory of CRA-relevant resources: specifications, best practices, and reference materials tailored for developers, maintainers, manufacturers, and foundations that rely on open source software. We’ve also prepared a community-driven roadmap to guide the creation of additional content and materials to support the open source ecosystem as it works to meet CRA compliance.

Importantly, the working group operates under the Eclipse Foundation’s vendor-neutral governance and benefits from our formal liaison status with CEN, the European Committee for Standardization, the European Committee for Electrotechnical Standardization (CENELEC), and its active participation in the European Telecommunication Standards Institute (ETSI), and the European Commission’s CRA Expert Group. This gives the ORC an effective channel to represent open source perspectives in regulatory and standards policy discussions.

VMblog:  Will the Eclipse Foundation address other regulations beyond the CRA?

Mashologu:  Yes, we’re prepared to engage with any regulation that impacts the open source community. In addition to the CRA, we’re tackling developments in areas like AI, data sovereignty, and the software supply chain.

Just as importantly, all are welcome to participate. Organisations interested in joining the ORC Working Group can visit https://orcwg.org/participate/, and those interested in contributing to the OCCTET Project can learn more at https://occtet.eu.

##