Flock to Fedora 2026

The EU CRA vs. Community: Why You’re Safe, and How Stewards Help
2026-06-15 , Topaz + Quartz

The European Union's Cyber Resilience Act (CRA) is the first "horizontal" law to formally recognize the role of open source in the commercial software supply chain. While any new regulation at this scale naturally brings questions, the CRA actually offers an opportunity to standardize and elevate security across the entire industry. The law also promotes collaboration between all FOSS ecosystem players - contributors, maintainers, foundations and commercial companies - by introducing the new role of steward. This session is an introduction into what the CRA really means for the community (spoiler - don’t be scared, you’re safe!) and how the true responsible stewards like Red Hat can help..

In the first part, we’re going to strip away the jargon and explain exactly what the CRA is. We’ll cover the basics of the Act: who it applies to, what it asks for, and how it acknowledges the unique nature of open source. We’ll look at the specific exemptions designed to protect the "way we work," making it clear why individual contributors and community-led development remain in a safe, protected space.

The second half of the talk introduces a concept of the Open Source Steward, designed specifically to support community projects. We’ll discuss how Red Hat, as a steward for Fedora, takes on the responsibility for high-level security policies, vulnerability reporting, and coordination with authorities. Join us to learn how this partnership allows the Fedora community to keep innovating freely and preserve its unique culture, style and processes. Red Hat is here to help navigate the new regulatory requirements and improve the project's security posture to keep delivering the best quality Linux distribution to its users.

See also: Slides (7.1 MB)

Jaroslav Řezník is a Principal Program Manager responsible for security standards and upcoming compliance activities under Red Hat's Product Security Compliance team. In his 18 years at Red Hat, he has touched many different areas from very different angles, from the community work on Fedora that is still his passion to compliance with government standards like Common Criteria and FIPS.

This speaker also appears in:

Roman is a cybersecurity expert, engineer, and leader with over 18 years of hands-on experience securing complex systems and products at scale. At Red Hat Roman leads open-source security strategy, upstream collaboration, and cross-industry initiatives focused on building trusted ecosystems. He has built and scaled programs across security architecture, threat modeling, secure development, vulnerability management, incident response, and security education - for both engineers and senior leadership. His work spans trusted AI, privacy, compliance, and secure software supply chains. Previously, Roman led Product Security & Privacy for Data Center and AI software at Intel. He is a Security Champion for several open-source projects and an active contributor to working groups under the OpenSSF, Eclipse Foundation, and other global initiatives. He is an official member of CEN/CLC and ETSI standardization groups, contributing to the EU Cyber Resilience Act (CRA).

This speaker also appears in: