AGP Picks
View all

Eclipse Foundation Releases Free Toolkit to Help SMEs Prepare for the EU Cyber Resilience Act

The EU-funded OCCTET project delivers open source tools to help organisations identify software components, address vulnerabilities, and prepare compliance documentation ahead of the first CRA reporting deadline

BRUSSELS, Sept. 10, 2026 (GLOBE NEWSWIRE) -- The Eclipse Foundation, one of the world’s largest open source software foundations, today announced the availability of a free, open source toolkit developed through the EU-funded OCCTET project to help small and medium-sized enterprises (SMEs) and open source projects prepare for the European Union’s Cyber Resilience Act (CRA).

The toolkit translates complex regulatory requirements into practical steps that organisations can incorporate into their software development and security processes. It helps them assess their readiness, identify which open source components are used in their products, manage vulnerabilities, and document how security risks are being addressed.

The release comes as the CRA’s first obligations take effect. Beginning 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents affecting the security of products with digital elements made available in the European Union. The CRA’s broader requirements will apply from 11 December 2027.

Early use of the OCCTET self-assessment platform has identified a common challenge: many SMEs have security measures in place but lack the visibility, documentation, and consistent processes needed to demonstrate how software risks are being managed.

“For organisations with limited compliance resources, preparing for the CRA is a major undertaking,” said Mike Milinkovich, executive director of the Eclipse Foundation. “OCCTET makes that work more manageable by bringing together tools that help them understand their obligations, identify and address vulnerabilities, and maintain the records needed to support compliance.”

A practical path from assessment to action

The OCCTET toolkit combines multiple services that support organisations from initial assessment through vulnerability management and documentation.

SMEs and open source projects can now access and test the following services:

  • Assess readiness: The CRA Self-Assessment Portal helps SMEs understand how the CRA applies to them, evaluate their current readiness, and identify areas requiring attention. The free, guided assessment translates CRA provisions into structured questions, scoring, and practical recommendations.
  • Identify software components: Eclipse Apoapsis (OCCTET instance) identifies open source components, dependencies, and licenses, based on the OSS Review Toolkit and known vulnerabilities. It can also generate a range of CRA-ready reports and compliance artefacts, including Software Bills of Materials (SBOMs), which provide a standardised inventory of the software components contained in a product.
  • Review findings and take action: Bitsea Curator (OCCTET instance) combines automated analysis with human review to help users verify software information, assess whether vulnerabilities affect their products, prioritise issues, and document their decisions. It also supports the creation of Vulnerability Exploitability eXchange (VEX) reports, which record whether a product is affected by a known vulnerability.
  • Reuse shared software information: The Federated OSS Assessment Database, vulnerablecode.io, provides information about open source packages, including their origins, licenses, security advisories, vulnerabilities, and reference SBOMs. Its public PurlDB demonstrator supports reference SBOM generation for more than 20 million packages, while its VulnerableCode integration connects vulnerability information with the software packages it affects.

The toolkit has been validated against complex, real-world software dependency scenarios across ten different technology ecosystems. Testing has included widely used open source projects, large-scale analysis of the Eclipse Foundation’s entire project portfolio, as well as a growing number of real-world SME use cases. This extensive validation demonstrates the toolkit’s ability to operate across diverse technologies, project sizes, and software supply chains.

This testing has demonstrated its ability to analyse complex dependency structures, identify vulnerabilities, support human review, and monitor security issues over time.

Get started with OCCTET

The Open Source Compliance: Comprehensive Techniques and Essential Tools (OCCTET) project brings together industry leaders, cybersecurity experts, SME representatives, and open source organisations to make software security and CRA preparation more accessible, transparent, and cost-effective.

SMEs and open source projects can explore the toolkit and available resources at occtet.eu. Organisations interested in testing the services using real products and development workflows, and providing feedback to support their continued improvement, can visit the OCCTET Get Engaged page.

OCCTET complements the Eclipse Foundation’s broader work to help organisations and open source communities prepare for the CRA. Through the Open Regulatory Compliance (ORC) Working Group, participants are developing community-driven specifications, guidance, training, and other resources to support CRA implementation across the open source ecosystem.

These resources include the free ORC Learning Hub, which provides practical, role-specific training to help open source developers, maintainers, project stewards, product teams, and security and compliance professionals understand how the CRA applies to their work and put its requirements into practice.

The community also comes together through Code & Compliance, the flagship ORC event for open source developers, project stewards, legal and compliance professionals, policymakers, and industry leaders. The next event takes place on 27 October 2026 in Brussels, providing a forum to exchange experiences, share practical guidance, and explore how the CRA and other emerging digital regulations are affecting the open source ecosystem. Register now to join the discussion.

About the OCCTET Project

Open Source Compliance: Comprehensive Techniques and Essential Tools (OCCTET) is an EU-funded initiative focused on helping SMEs and open source projects navigate cybersecurity and compliance requirements under the Cyber Resilience Act. Coordinated by the Eclipse Foundation, the project is developing an integrated suite of free, open source tools for readiness assessment, software dependency analysis, vulnerability management, SBOM generation, and compliance documentation.

The OCCTET project has received funding from the Digital Europe Programme under grant agreement No. 101190474. The content does not necessarily reflect the views of the European Commission. The European Commission is not liable for any use that may be made of the information contained herein.

Learn more at occtet.eu.

About the Eclipse Foundation
The Eclipse Foundation provides a global community of individuals and organisations with a vendor-neutral, business-friendly environment for open source collaboration and innovation. We host Adoptium, the Eclipse IDE, Jakarta EE, Open VSX, Software Defined Vehicle, and more than 450 high-impact open source projects. Headquartered in Brussels, Belgium, we are an international non-profit association supported by over 300 members. Our events, including Open Community Experience (OCX), bring together developers, industry leaders, and researchers from around the world. To learn more, follow us on X and LinkedIn, or visit eclipse.org.

Media contacts:
Schwartz Public Relations
Julia Rauch/Luca Myska
Sendlinger Straße 42A
80331 München
EclipseFoundation@schwartzpr.de
+49 (89) 211 871 -43/ -52

514 Media Ltd (France, Italy, Spain)
Benoit Simoneau
benoit@514-media.com
M: +44 (0) 7891 920 370

Nichols Communications (Global Press Contact)
Jay Nichols
jay@nicholscomm.com
+1 408-772-1551


Primary Logo

Legal Disclaimer:

EIN Presswire provides this news content "as is" without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

Share this page:

Advanced Search Options

Search for:

Search scope:

Type:

Search in:

Date range:

The last

Sort by:

Sign up for:

Indonesia Industry Times

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.