Eclipse Foundation & OWASP Unite for CRA Open Source Security

The News

The Eclipse Foundation and OWASP have signed a Memorandum of Understanding to jointly strengthen open source security and help organizations prepare for the EU Cyber Resilience Act. The partnership combines the Eclipse Foundation’s governance and regulatory expertise with OWASP’s globally recognized security projects, standards, and community reach. Initial deliverables will include practical CRA readiness guidance for open source stewards, joint webinars, SBOM adoption resources, and maintainer support programs.

Analyst Take

The CRA Countdown Is No Longer Abstract

September 11, 2026 is six weeks away. For any organization shipping products with digital elements into the EU market, that date marks the start of mandatory vulnerability and incident reporting obligations under the Cyber Resilience Act. The Eclipse Foundation and OWASP partnership arrives at exactly the right moment, not as a proactive initiative but as a reactive necessity. The open source ecosystem has spent years operating on a distributed trust model where security responsibility is diffuse by design. The CRA upends that model by imposing legal accountability on manufacturers, including those whose products incorporate open source dependencies. That changes the calculus for every enterprise shipping into Europe.

The Eclipse Foundation’s Open Regulatory Compliance Working Group already provides a convening structure. OWASP brings the practitioner-facing content: the Top Ten, the Application Security Verification Standard, dependency-track tools, and decades of developer trust. The combination is sensible. What makes this pairing credible is that both organizations have explicitly stated they will not create competing frameworks, a commitment that matters because framework proliferation is itself a security liability. Developers who must choose between conflicting guidance tend to choose none of it.

Supply Chain Security Is Already a Boardroom Priority — The Regulatory Pressure Amplifies It

Even before the CRA, software supply chain security was rising fast on enterprise investment agendas. According to ECI Research’s 2026 Application Development: Day 0 survey, 47.4% of respondents selected “Software supply chain security” among their top investment priorities for the next 12 months. That’s a significant signal: supply chain security is now competing for budget alongside AI-enabled development tools and cloud cost optimization. The Eclipse-OWASP collaboration lands squarely inside that investment wave and gives organizations a coordinated set of resources to point their security spend at rather than assembling point solutions independently.

For developers, the practical implications are concrete. ECI Research’s 2026 Application Development: Day 0 survey found that 58.4% of respondents have implemented vulnerability scanning as a software supply chain security control, while 53.8% reported policy enforcement at deploy time. SBOM generation, a specific focus of the new partnership, sits at 36.2%. That gap between vulnerability scanning adoption and SBOM generation is exactly where the CRA creates compliance exposure, and exactly where joint OWASP-Eclipse guidance can accelerate adoption. Organizations that have already invested in scanning but not yet in provenance tracking or SBOM generation are the most immediate audience for what this partnership will produce.

The AI Complication

Mike Milinkovich’s statement explicitly calls out AI as an accelerant for both software development and vulnerability discovery, and that framing deserves attention. AI-assisted coding is now standard in enterprise engineering environments. ECI Research’s 2026 Application Development: Day 0 survey found that 52.6% of respondents have standardized AI-assisted coding tools across teams. The security risk implications of that adoption are actively felt: ECI Research’s 2026 DevSecOps and AppSec survey found that 45.3% of respondents said AI-assisted development has “increased risk moderately,” with a further 17.2% reporting it has “increased risk significantly.” When AI generates code at scale, it also generates dependencies, and those dependencies flow directly into the supply chain surface area that the CRA now regulates. A partnership that helps maintainers and enterprises build SBOM hygiene and provenance tracking into AI-assisted workflows has a genuinely large addressable problem to solve.

Looking Ahead

The immediate test for this partnership is execution speed. The September deadline is fixed, and organizations without established vulnerability management and incident reporting processes are already behind. Expect the first joint deliverables, specifically CRA readiness checklists and SBOM tooling guidance, to be time-pressured and narrowly scoped. The longer arc is more interesting: as the CRA’s full requirements phase in through 2027, the collaboration has an opportunity to build durable alignment between OWASP’s developer-facing standards and the Eclipse Foundation’s enterprise governance structures, creating a compliance reference path that serves both maintainers and the organizations that depend on their work.

This partnership could create modest pressure on commercial security vendors who have been positioning CRA readiness as a paid advisory engagement. Freely available, credible guidance from two trusted foundations narrows the gap between what enterprises can achieve independently and what they need to purchase. That’s a favorable dynamic for the market broadly, and it positions both organizations as indispensable infrastructure for the post-CRA software development landscape. Watch for enterprise membership growth at both foundations as compliance urgency converts procurement interest into formal organizational commitments.

Authors

  • Paul Nashawaty

    Paul Nashawaty, Practice Leader and Lead Principal Analyst, specializes in application modernization across build, release and operations. With a wealth of expertise in digital transformation initiatives spanning front-end and back-end systems, he also possesses comprehensive knowledge of the underlying infrastructure ecosystem crucial for supporting modernization endeavors. With over 25 years of experience, Paul has a proven track record in implementing effective go-to-market strategies, including the identification of new market channels, the growth and cultivation of partner ecosystems, and the successful execution of strategic plans resulting in positive business outcomes for his clients.

    View all posts
  • With over 15 years of hands-on experience in operations roles across legal, financial, and technology sectors, Sam Weston brings deep expertise in the systems that power modern enterprises such as ERP, CRM, HCM, CX, and beyond. Her career has spanned the full spectrum of enterprise applications, from optimizing business processes and managing platforms to leading digital transformation initiatives.

    Sam has transitioned her expertise into the analyst arena, focusing on enterprise applications and the evolving role they play in business productivity and transformation. She provides independent insights that bridge technology capabilities with business outcomes, helping organizations and vendors alike navigate a changing enterprise software landscape.

    View all posts