SecurityBrief UK - Technology news for CISOs & cybersecurity decision-makers
United Kingdom
OpenSSF adds four members amid EU cyber rules push

OpenSSF adds four members amid EU cyber rules push

Tue, 6th Oct 2026 (Today)
Mara Sugue
MARA SUGUE News Editor

The Open Source Security Foundation has added four new general members and released new Cyber Resilience Act resources. The additions bring A-Team Systems, Emphere, DACHS IT GMBH, and JetBrains into the group.

The membership expansion comes as companies selling products into the European Union face tighter obligations under the Cyber Resilience Act, including mandatory vulnerability and incident reporting.

New OpenSSF material includes a CRA readiness practitioner guide, a user journey to help organisations assess their preparedness, and a case study based on work by Ericsson Software Technology.

OpenSSF said Ericsson Software Technology contributed more than 1,400 dependency updates and security fixes upstream after eliminating private forks, using principles promoted by the foundation. The case study is meant to show how companies can adapt their software maintenance practices to meet regulatory requirements.

The foundation also outlined a broader set of third-quarter milestones, including new role-based user journeys for developers, security engineers, OSPO leaders, marketers, and executives; a new release of the OpenBao secrets management tool; and the admission of BOMHort to the OpenSSF Sandbox.

OpenSSF described BOMHort as a Kubernetes-native tool for software bill of materials visualisation and governance, linking the move to rising demand for tools that help teams manage and query SBOM data as regulation expands.

Regulatory pressure has become a central issue for Europe's open source software ecosystem. The Cyber Resilience Act places new obligations on vendors, while the spread of artificial intelligence tools has reduced the time needed to identify potential weaknesses and increased the volume of reports software teams may need to handle.

Steve Fernandez, General Manager of OpenSSF, said the organisation sees this as an industry-wide problem rather than one confined to individual projects.

"Securing the open source ecosystem is no longer just about patching isolated vulnerabilities. It requires proactive, systemic collaboration across the entire industry," said Steve Fernandez, General Manager of OpenSSF.

"Initiatives like the Open Secure AI Alliance and pioneering projects such as Akrites reflect this critical shift. We are moving beyond fragmented defenses and building a unified front, equipping the global developer community with the comprehensive frameworks needed to secure the next generation of software. OpenSSF and our members are a key element in this shift," Fernandez said.

New members

The four new members tied their decision to join to the growing role of open source software in critical systems and the need to address security collectively.

"Open source software has been central to our work supporting Linux and FreeBSD systems in critical production environments for more than two decades. We depend on the security work happening throughout the open source ecosystem. OpenSSF provides part of the foundation that makes secure, reliable production operations possible. Joining OpenSSF reflects our commitment to materially supporting the people who make open source what it is today. We look forward to contributing an infrastructure operations perspective and supporting the important work OpenSSF is doing across the open source community," said Adam Strohl, President of A-Team Systems.

"Virtually every critical enterprise builds on an open source foundation. When everyone relies on that digital common ground, maintaining its safety is a shared responsibility. Securing the supply chain helps ensure that open source software remains safe, trusted, and open for everyone. Through our continuous work in the Linux Foundation and CNCF, we've helped build cloud-native ecosystems. Now, through OpenSSF, we're expanding that work to help protect and strengthen the security foundation they rely on," said Alexander Schaber, Founder and CEO of DACHS IT GMBH.

"Open source is shared code, and so is the responsibility to secure it. Emphere is glad to join OpenSSF to help the community outpatch attackers, human and AI alike," said Ankit Kumar, CEO of Emphere.

JetBrains linked its membership to AI-driven changes in software development, saying developers need to be able to understand and verify the software they produce as development practices shift.

"Software development is at an inflection point. AI is changing how software is built and creating new security challenges, making it more important than ever that developers can understand, verify, and trust the software they produce. JetBrains has supported professional software development for more than two decades, and we believe staying ahead of these challenges is best done collaboratively and in the open. OpenSSF brings together some of the strongest expertise in the industry, and we are glad to join the community and help shape the future of secure software development," said Katherine Druckman, Head of Community and Partnership Engagement at JetBrains.

OpenSSF operates as a cross-industry initiative under the Linux Foundation, bringing together companies, technical groups, and working groups focused on open source software security. The new members will take part in that effort as regulatory scrutiny increases and software producers face greater pressure to document, maintain, and secure the code underpinning modern digital infrastructure.