Cyber Resilience Act: What Companies Need to Consider When It comes to Open Source Software

24. July 2026 Vincent Cyber Resilience Act Open-Source-Software Cybersicherheit CRA

Cyber Resilience Act: What Companies Need to Consider When It comes to Open Source Software

The Cyber Resilience Act (CRA)** is a new EU law that will apply from 2025 and requires companies to ensure the cybersecurity of their digital products. This also applies to the use of **open source software** – i.e. free software whose source code is publicly visible and changeable. But what does this mean specifically for companies that use such programs?

## What is open source software?

Open source software (OSS) is software whose code is freely available and developed by the community. Examples are the operating system Linux, the browser Firefox or the email program Thunderbird. Many companies use OSS because it is often inexpensive, flexible and well supported. However, it also carries risks: Since the code is public, vulnerabilities can be detected faster – but also exploited.

## Duties under the CRA

The CRA requires manufacturers and users of digital products to minimize **security risks** and** actively manage vulnerabilities**. For companies using open source software, this means:

**Risk Assessment**: You must check which open source components are used in your products or systems and which security risks are associated with them. 2. **Vulnerability management**: Companies are required to monitor known vulnerabilities and quickly fix them. This also applies to open source libraries that are integrated into their own applications. **Documentation**: It must be traceable which open source software is used and how security gaps are dealt with. 4. **Notification of incidents**: In the case of serious security incidents, these must be reported to the competent authorities.

## Why is this important?

Cyberattacks are becoming increasingly sophisticated. A current example: manipulated links in ChatGPT allowed attackers to install autonomous AI agents with stolen access rights in company networks. Such incidents show how important it is to keep an eye on all software components – including open source programs. The CRA should ensure greater transparency and security here.

## What does this mean for your company?

For you as an entrepreneur or employee, this means that you will have to examine more closely in the future which open source software is used in your IT infrastructure, products or services. This applies not only to self-developed applications, but also to standard programs such as e-mail clients or CRM systems. Create an overview of all open source components used and determine how to handle security updates. This way you not only avoid fines, but also protect your data and that of your customers.

## Current developments in open source software

A positive example of the further development of open source software is the email client **Thunderbird**. The new version 153 “Meadow” offers native support for Microsoft Exchange for the first time – a feature that was previously only available in paid programs. This shows how open source software is becoming increasingly powerful and offers companies flexible alternatives.

## What this means for users

The groupware functions of xynap include e-mail (IMAP/SMTP) and calendar (CalDAV). If you use open source components in your instance, you must also include them in your risk assessment under the CRA. Make sure that all used modules are regularly checked and updated for security updates.


Sources (4)

  1. activemind.de
  2. the-decoder.de
  3. heise.de
  4. t3n.de

Sources (4)

  1. www.activemind.de
  2. the-decoder.de
  3. www.heise.de
  4. t3n.de