The News
The Eclipse Foundation and OWASP have signed a Memorandum of Understanding to jointly strengthen open source security and help organizations prepare for the EU Cyber Resilience Act. The partnership combines the Eclipse Foundation’s governance and regulatory expertise with OWASP’s globally recognized security projects, standards, and community reach. Initial deliverables will include practical CRA readiness guidance for open source stewards, joint webinars, SBOM adoption resources, and maintainer support programs.
Analyst Take
The CRA Countdown Is No Longer Abstract
September 11, 2026 is six weeks away. For any organization shipping products with digital elements into the EU market, that date marks the start of mandatory vulnerability and incident reporting obligations under the Cyber Resilience Act. The Eclipse Foundation and OWASP partnership arrives at exactly the right moment, not as a proactive initiative but as a reactive necessity. The open source ecosystem has spent years operating on a distributed trust model where security responsibility is diffuse by design. The CRA upends that model by imposing legal accountability on manufacturers, including those whose products incorporate open source dependencies. That changes the calculus for every enterprise shipping into Europe.
The Eclipse Foundation’s Open Regulatory Compliance Working Group already provides a convening structure. OWASP brings the practitioner-facing content: the Top Ten, the Application Security Verification Standard, dependency-track tools, and decades of developer trust. The combination is sensible. What makes this pairing credible is that both organizations have explicitly stated they will not create competing frameworks, a commitment that matters because framework proliferation is itself a security liability. Developers who must choose between conflicting guidance tend to choose none of it.
Supply Chain Security Is Already a Boardroom Priority — The Regulatory Pressure Amplifies It
Even before the CRA, software supply chain security was rising fast on enterprise investment agendas. According to ECI Research’s 2026 Application Development: Day 0 survey, 47.4% of respondents selected “Software supply chain security” among their top investment priorities for the next 12 months. That’s a significant signal: supply chain security is now competing for budget alongside AI-enabled development tools and cloud cost optimization. The Eclipse-OWASP collaboration lands squarely inside that investment wave and gives organizations a coordinated set of resources to point their security spend at rather than assembling point solutions independently.
For developers, the practical implications are concrete. ECI Research’s 2026 Application Development: Day 0 survey found that 58.4% of respondents have implemented vulnerability scanning as a software supply chain security control, while 53.8% reported policy enforcement at deploy time. SBOM generation, a specific focus of the new partnership, sits at 36.2%. That gap between vulnerability scanning adoption and SBOM generation is exactly where the CRA creates compliance exposure, and exactly where joint OWASP-Eclipse guidance can accelerate adoption. Organizations that have already invested in scanning but not yet in provenance tracking or SBOM generation are the most immediate audience for what this partnership will produce.
The AI Complication
Mike Milinkovich’s statement explicitly calls out AI as an accelerant for both software development and vulnerability discovery, and that framing deserves attention. AI-assisted coding is now standard in enterprise engineering environments. ECI Research’s 2026 Application Development: Day 0 survey found that 52.6% of respondents have standardized AI-assisted coding tools across teams. The security risk implications of that adoption are actively felt: ECI Research’s 2026 DevSecOps and AppSec survey found that 45.3% of respondents said AI-assisted development has “increased risk moderately,” with a further 17.2% reporting it has “increased risk significantly.” When AI generates code at scale, it also generates dependencies, and those dependencies flow directly into the supply chain surface area that the CRA now regulates. A partnership that helps maintainers and enterprises build SBOM hygiene and provenance tracking into AI-assisted workflows has a genuinely large addressable problem to solve.
Looking Ahead
The immediate test for this partnership is execution speed. The September deadline is fixed, and organizations without established vulnerability management and incident reporting processes are already behind. Expect the first joint deliverables, specifically CRA readiness checklists and SBOM tooling guidance, to be time-pressured and narrowly scoped. The longer arc is more interesting: as the CRA’s full requirements phase in through 2027, the collaboration has an opportunity to build durable alignment between OWASP’s developer-facing standards and the Eclipse Foundation’s enterprise governance structures, creating a compliance reference path that serves both maintainers and the organizations that depend on their work.
This partnership could create modest pressure on commercial security vendors who have been positioning CRA readiness as a paid advisory engagement. Freely available, credible guidance from two trusted foundations narrows the gap between what enterprises can achieve independently and what they need to purchase. That’s a favorable dynamic for the market broadly, and it positions both organizations as indispensable infrastructure for the post-CRA software development landscape. Watch for enterprise membership growth at both foundations as compliance urgency converts procurement interest into formal organizational commitments.
Stay Ahead of Application Development Trends
Get weekly analyst insights, research notes, event coverage, and AppDevANGLE updates delivered directly to your inbox.
Subscribe for Weekly Insights
Join technology leaders, practitioners, and GTM teams following the trends shaping modern software delivery.
Looking for deeper research access?
Explore ECI Research reports, survey insights, and market analysis through the ECI Research Portal.
