Eclipse Foundation Releases Free OCCTET Toolkit for EU CRA Preparation
5th article in the last 90 days, one of 8 articles referencing Eclipse Foundation. Previous coverage: Zero trust, SSE testing, and AI agent governance updates - Week of August 3, 2026 (Aug 2026).
Companies mentioned
Best suited for
- Seniority
- EVP / SVP / VP / AVP
- Job function
- Chief Information Security Officer
- Persona
- Security Operations Leader
- Buyer role
- Decision Maker / Budget Holder
- Buyer journey
- Need to Buy
- Adoption curve
- Early Majority
- Technology maturity
- Operational Expansion
- Industry
- Information Technology / Software & Services / Cybersecurity / Governance, Risk & Compliance (GRC) & Security Ratings
Our classification, not the publisher's statement. Best suited for, not only for.
The Eclipse Foundation made a free, open source OCCTET toolkit available to help organizations prepare for the European Union’s Cyber Resilience Act (CRA) and support documentation needs ahead of the CRA’s first reporting deadline.
The release arrived as the CRA’s first obligations took effect in stages, with manufacturers required to report actively exploited vulnerabilities and severe incidents affecting the security of products with digital elements starting 11 September 2026. Broader CRA requirements were scheduled to apply from 11 December 2027.
The OCCTET toolkit translated CRA requirements into structured steps for software development and security processes. It supported readiness assessment, identification of open source components used in products, vulnerability handling, and documentation of how security risks were addressed.
Mike Milinkovich, executive director of the Eclipse Foundation, said, “OCCTET makes that work more manageable by bringing together tools that help them understand their obligations, identify and address vulnerabilities, and maintain the records needed to support compliance.” The toolkit combined services including a CRA Self-Assessment Portal, Eclipse Apoapsis for component, dependency, and license identification with SBOM generation, Bitsea Curator for verifying software information and producing Vulnerability Exploitability eXchange (VEX) reports, and vulnerablecode.io and its PurlDB demonstrator and VulnerableCode integration for package and vulnerability data.
Forward-looking statements were not included in the provided text.
Press release, provided by Globe Newswire on behalf of Eclipse Foundation. Read the original.