Eclipse Foundation Implemented Cyber Resilience Tools

The foundation launched the OCCTET toolkit in September 2026 to help open-source projects meet EU regulatory requirements.

Updated on Sept. 29, 2026 in Software

Bold flat-color editorial illustration of interlocking geometric steel joints, representing systematic security compliance and supply chain tracking.
The Eclipse Foundation launched its OCCTET toolkit in September 2026 to help open-source projects meet EU Cyber Resilience Act compliance requirements. AI Illustration. Upload story photo >

Live Poll

Should companies that profit from open-source software be required to fund the communities keeping it secure?

The Eclipse Foundation released the OCCTET toolkit in September 2026 to assist with compliance under the EU Cyber Resilience Act. These resources arrived as manufacturers faced new mandatory reporting obligations that began on September 11, 2026.

Why it matters

The Cyber Resilience Act mandates security standards for software connected to the internal market, necessitating new documentation and tracking processes for open-source stewards. Eclipse is standardizing these workflows ahead of the December 2027 enforcement deadline for non-manufacturer stewards.

The Eclipse Foundation hosts more than 400 projects, all of which must now align with the EU Cyber Resilience Act. The new OCCTET toolkit provides a technical framework for managing vulnerabilities and tracking version history to meet these legal requirements.

The players

Eclipse Foundation

A global open-source community that hosts over 400 projects and provides governance for software development ecosystems.

OWASP

A non-profit foundation that works to improve software security through collaborative research and community-driven projects.

The details

The OCCTET toolkit operates by standardizing how open-source stewards publish reporting channels and maintain comprehensive version tracking. By formalizing these commercial terms, the toolkit ensures that software projects can demonstrate security compliance to regulators. This approach aligns with the ORC Learning Hub, which provides guidance on mapping organizational roles within the broader software supply chain.

Timeline

  1. September 11, 2026: Manufacturers' reporting obligations began.

  2. September 2026: The OCCTET toolkit was released.

  3. December 11, 2027: Software stewards' reporting obligations apply.

The Tech Race

This development follows the precedent set by the EU Cyber Resilience Act to bring security accountability to the open-source software ecosystem. The Eclipse Foundation's collaboration with OWASP marks a strategic effort to standardize compliance practices across the industry.

Developers and maintainers within the Eclipse ecosystem can now utilize the OCCTET toolkit to automate compliance readiness and vulnerability reporting. While individual developers are currently exempt, professional stewards must prepare their project infrastructure before the December 2027 deadline.

The takeaway

The transition to mandatory security reporting marks a shift for open-source projects from volunteer-led development to regulated commercial-grade software management. Stakeholders should track the December 11, 2027 enforcement date as the definitive benchmark for compliance.

What happens next

The Eclipse Foundation plans to launch a new module focused on Software Bill of Materials (SBOMs) and vulnerability management to further assist developers with compliance.

Further reading

For broader trends in code governance and regulatory compliance, explore our Software section.

Source note: This article includes information reported by Electronic Specifier.

Live Poll

Should companies that profit from open-source software be required to fund the communities keeping it secure?