Open Regulatory Compliance Working Group
The Open Regulatory Compliance Working Group is a non-profit initiative under the Eclipse Foundation that coordinates an open community of 63 member organizations to help open source communities navigate EU Cyber Resilience Act compliance through documentation, training, standards engagement, and policy advocacy.
- Company typePrivate
- Founded2024
- Headquarters—
- Headcount1–10
- GTM typeB2B
- OfferingServices
What Open Regulatory Compliance Working Group does
The Open Regulatory Compliance Working Group (ORC WG) is a collaborative non-profit initiative established in 2024 under the Eclipse Foundation AISBL, headquartered in Brussels, Belgium, with a stated mission of helping open source communities navigate regulatory compliance, particularly the EU Cyber Resilience Act (CRA). The working group brings together stakeholders from industry (Microsoft, Google, GitHub, Red Hat, Siemens, Nokia, Huawei, Mercedes-Benz, Sonatype), open source foundations (Apache, OWASP, Python, Eclipse, OpenSSF), SMEs, research institutions (IMEC), and individual maintainers and contributors into a single coordinated forum. As of December 2025, membership stood at 63 organizations spanning 13+ countries.
ORC WG's deliverables are documentation, specifications, and educational resources rather than commercial technology products. Core outputs include the community-built CRA FAQ (cra.orcwg.org), the CRA Hub GitHub repository, the Cyber Resilience Practices Specification (an Eclipse Foundation project), the Voluntary Security Attestations Framework under CRA Article 25, the ORC Learning Hub training platform with free introductory courses for open source community members and manufacturers, the bi-weekly CRA Mondays webinar series, and the annual Code & Compliance Community Day held in Brussels. The organization also publishes white papers, with its first focused on the CRA definition and obligations of Open Source Software Stewards.
The business model is non-commercial: participation is free and open to any individual or organization with an interest in regulatory compliance. The group is funded indirectly through Eclipse Foundation membership fees and sponsorships, with the Eclipse Foundation providing administrative infrastructure, event coordination, and institutional representation in CRA Expert Group meetings. Go-to-market is community-led, relying on events (FOSDEM, EU Open Source Week, Embedded World, Code & Compliance), content distribution via blog, YouTube, GitHub, LinkedIn, Bluesky, and Mastodon, and direct engagement with CEN/CENELEC and ETSI standards bodies to influence CRA horizontal and vertical standards development ahead of the September 2026 enforcement deadline.
Open Regulatory Compliance Working Group firmographics
Firmographics- Name
- Open Regulatory Compliance Working Group
- Legal name
- Eclipse Foundation AISBL
- Website
- https://orcwg.org
- Company type
- Private
- Founded year
- 2024
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- The Open Regulatory Compliance Working Group is a non-profit initiative under the Eclipse Foundation that coordinates an open community of 63 member organizations to help open source communities navigate EU Cyber Resilience Act compliance through documentation, training, standards engagement, and policy advocacy.
- Ownership category
- akta.pro rank
Open Regulatory Compliance Working Group industry classification
Industry- Product category
- Open Source Regulatory Compliance
- NAICS
- Professional Organizations (81392), Business Associations (813910)
- SIC
- Services-Membership Organizations (8600)
- akta.pro primary industry
- Conformity Assessment, Testing, Inspection & Certification Cooperation (BPADANAD)
- akta.pro secondary industries
- Governance, Risk & Compliance (GRC) Platforms (BPAEAPAA), Compliance Technology, GRC Platforms & Controls Automation Advisory (BPAHAFAO), Risk, Controls & Governance (GRC) Platforms (FSAFAOAG)
Keywords
Open Regulatory Compliance Working Group business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Marketing or Sales, Technology or R&D, Others
Revenue model
- Working Group Membership: The ORC Working Group operates under the Eclipse Foundation as a collaborative initiative. Organizations join as members to participate and shape regulatory compliance guidance for open source. The Eclipse Foundation is a non-profit association (AISBL) that relies on membership fees and sponsorships.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Pay-as-you-go | Free Training Courses |
| Subscription | Multi-year contract | Code & Compliance Event Registration |
Go-to-market motion1 record
Distribution channels4 records
Marketing channels9 records
Open Regulatory Compliance Working Group product offering
Product offeringCore offering
The Open Regulatory Compliance Working Group (ORC WG) is a collaborative working group under the Eclipse Foundation that coordinates industry stakeholders, open source foundations, SMEs, maintainers and contributors to produce practical guidance, specifications, training, and community resources supporting compliance with the EU Cyber Resilience Act and other government regulations affecting open source software. Outputs include the CRA FAQ, the Cyber Resilience Practices Specification, voluntary security attestations, white papers, training courses, and community events.
Product overview
The Open Regulatory Compliance Working Group (ORC WG) is a collaborative initiative under the Eclipse Foundation that provides a comprehensive suite of resources, training, and community-driven deliverables to help open source communities navigate the EU Cyber Resilience Act. The core offering is the Working Group itself, supported by the CRA Hub on GitHub for technical resources, the ORC Learning Hub for role-specific training courses, and the community-built CRA FAQ. Key programs include the CRA Mondays webinar series, Code & Compliance annual events, and the Voluntary Security Attestations Framework project. The group also produces white papers on topics like SBOMs, due diligence, and steward obligations, and maintains the Cyber Resilience Practices Specification project for technical standards implementation.
Differentiator
Problem solved
Functional benefit
Brands
- ORC Learning Hub: Practical, open source-focused training to help understand how the EU Cyber Resilience Act applies in real-world scenarios
- Cyber Resilience SIG
- CRA Hub
Products and services
- ORC Learning Hub Practical, open source-focused training platform providing role-specific courses including 'Introduction to the CRA for the Open Source Community' and 'Introduction to the CRA for Manufacturers' to help open source community members and manufacturers understand CRA obligations.
- CRA FAQ Community-built frequently asked questions resource addressing how the Cyber Resilience Act applies to open source software, available on a dedicated website (cra.orcwg.org).
- CRA Mondays Webinar Series
Quantifiable outcome
- Membership expanded to 63 organisations within one year
- +1 more outcomes
Companies that use Open Regulatory Compliance Working Group
Customer profileNamed customers19 records
Segments5 records
Ideal customer profiles4 records
Open Regulatory Compliance Working Group technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration8 records
Feature5 records
Open Regulatory Compliance Working Group partnerships and signals
Strategic signalPartnerships
30 partnerships are on record, tiered core, strategic and minor.
- Eclipse FoundationcoreThe Eclipse Foundation serves as the organisational host for the ORC Working Group, providing administrative infrastructure, event coordination, and institutional framework. The Foundation represents the open source ecosystem in CRA Expert Group meetings and regulatory discussions.
- The Apache Software FoundationcoreOne of three open source foundations selected for the CRA Expert Group. Provides insights into open source security challenges and contributes to policy discussions on behalf of Apache projects.
- OpenSSFcoreOpen Source Security Foundation selected for CRA Expert Group membership. Contributes expertise on open source security practices and coordinates policy engagement.
- Ecma InternationalstrategicCollaborated with OWASP to publish the CycloneDX specification as Ecma-424 standard, supporting SBOM standards for CRA compliance.
- OCCTET ProjectstrategicEU-funded initiative designed to help SMEs navigate cybersecurity compliance under the CRA. ORC collaborates on tooling and self-assessment approaches.
- GitHubstrategicPartnered with GitHub to host CRA panel during Maintainer Month 2025. GitHub joined as ORC member in June/July 2025.
- Eclipse Dataspace Working GroupminorORC partnered with Eclipse Dataspace Working Group to plan breakout sessions on Sovereignty by Design and regulatory compliance.
- CEN/CENELECcoreActive participation in standards development for CRA horizontal standards (pEN 4000 series). ORC provides feedback on standards development.
- ETSIcoreParticipating in ETSI TC Cyber working groups on CRA vertical standards. ETSI has opened early public consultations on CRA vertical standards.
- OWASPstrategicCollaborated with OWASP on CycloneDX specification published as Ecma-424. OWASP contributes to SBOM and security tooling discussions.
- Debian FranceminorJoined ORC Working Group in March 2025 as foundation member representing Debian ecosystem.
- Drupal AssociationminorJoined ORC Working Group in March 2025 as foundation member representing Drupal community.
- Ferrous Systems GmbHminorJoined ORC Working Group in March 2025.
- Nordic Institute for Interoperability Solutions (NIIS)minorJoined ORC Working Group in August 2025.
- Canonical GroupminorJoined ORC Working Group in October 2025.
- SOTECminorJoined ORC Working Group in October 2025.
- ZIUR FoundationminorJoined ORC Working Group in October 2025.
- Red HatstrategicJoined ORC Working Group in June/July 2025. Sharing CRA preparation experiences at Code & Compliance events.
- GooglestrategicJoined ORC Working Group in June/July 2025.
- MicrosoftstrategicJoined ORC Working Group in June/July 2025. Microsoft (with GitHub as subsidiary) represented in CRA Expert Group.
- SignPath FoundationminorJoined ORC Working Group in November 2025.
- OpenNebula SystemsminorJoined ORC Working Group in November 2025.
- Apell ASBLminorJoined ORC Working Group in April/May 2025.
- Apex.AI IncminorJoined ORC Working Group in April/May 2025.
- IMECminorJoined ORC Working Group in April/May 2025.
- Open Source MattersminorJoined ORC Working Group in June/July 2025.
- Ekxide IOminorJoined ORC Working Group in June/July 2025.
- ifrOSSminorJoined ORC Working Group in September 2025.
- Open Source Society MaltaminorJoined ORC Working Group in September 2025.
- Open Source Automation Development Lab (OSADL)minorJoined ORC Working Group in September 2025.
Scale indicators4 records
Recent moves6 records
Expansion highlights5 records
Open Regulatory Compliance Working Group competitors and assessment
Company assessmentBroad incumbents
- OWASP Foundation: Larger open source security community that co-developed CycloneDX with ORC WG. Overlaps on SBOM, vulnerability disclosure, and application security guidance relevant to CRA.
- Linux Foundation: Larger, broader open source foundation that hosts multiple comparable working groups (OpenSSF, OpenChain, SPDX, CNCF). Competes for the same policy engagement and membership funding pool as the Eclipse Foundation/ORC WG.
- Apache Software Foundation: Major open source foundation and a Strategic ORC WG member; itself a CRA Expert Group participant and home to comparable governance, IP, and compliance practices relevant to the steward role ORC WG advises on.
- CNCF (Cloud Native Computing Foundation): Linux Foundation sub-foundation running TAGs (Technical Advisory Groups) and security working groups with comparable community-led deliverables and standards-setting posture; overlaps with ORC WG on cloud/supply-chain security topics.
Direct peers
- OpenSSF (Open Source Security Foundation): Linux Foundation-hosted community producing open source security best practices, SBOM tooling, and supply-chain guidance — the most direct policy/standards peer to ORC WG and a co-member of the CRA Expert Group.
- OpenChain: Linux Foundation project building open source license-compliance standards (OpenChain ISO/IEC 5230). Highly comparable: community-driven, standards-grade outputs aimed at reducing compliance burden for organisations using open source.
- Eclipse Foundation: Parent host of ORC WG and a comparable foundation that convenes industry working groups (e.g., Eclipse Dataspace, Software Defined Vehicle, Adoptium). Provides the same institutional/working-group model and is also represented in the CRA Expert Group.
- CycloneDX / OWASP CycloneDX Working Group: OWASP/Ecma International project producing the SBOM standard (Ecma-424) — co-developed with ORC WG. Directly comparable as an open source standards community producing CRA-relevant artifacts.
- SPDX Working Group (Linux Foundation): Linux Foundation-hosted community developing the SPDX SBOM/provenance standard. Closely comparable peer in the open source compliance-standards space and a near-substitute for SBOM deliverables ORC WG references.
Others
- Software Freedom Conservancy: Non-profit supporting open source projects with policy advocacy (e.g., copyleft, GPL enforcement). Functionally comparable as a small-staffed open source non-profit doing policy work, but focuses on licensing rather than security regulation.
Market position
Weaknesses5 records
Competitive moat3 records
Key risks5 records
Key highlights6 records
Customer concentration
Open Regulatory Compliance Working Group social profiles
Digital presenceOpen Regulatory Compliance Working Group financial estimates
Financial estimateRevenue estimate
Valuation estimate
Open Regulatory Compliance Working Group leadership team
Management profileNumber of profiles
Profiles5 records
Open Regulatory Compliance Working Group funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Open Regulatory Compliance Working Group M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Open Regulatory Compliance Working Group
What does Open Regulatory Compliance Working Group do?
The Open Regulatory Compliance Working Group (ORC WG) is a collaborative working group under the Eclipse Foundation that coordinates industry stakeholders, open source foundations, SMEs, maintainers and contributors to produce practical guidance, specifications, training, and community resources supporting compliance with the EU Cyber Resilience Act and other government regulations affecting open source software. Outputs include the CRA FAQ, the Cyber Resilience Practices Specification, voluntary security attestations, white papers, training courses, and community events.
Is Open Regulatory Compliance Working Group a public or private company?
Open Regulatory Compliance Working Group is a private company. It is classified as nonprofit foundation owned and is currently operating.
When was Open Regulatory Compliance Working Group founded?
Open Regulatory Compliance Working Group was founded in 2024. It employs 1 to 10 people.
How does Open Regulatory Compliance Working Group make money?
One revenue line is on record: working Group Membership.
Who are Open Regulatory Compliance Working Group's main competitors?
Broad incumbents on record are OWASP Foundation, Linux Foundation, Apache Software Foundation and CNCF (Cloud Native Computing Foundation). Direct peers are OpenSSF (Open Source Security Foundation), OpenChain, Eclipse Foundation, CycloneDX / OWASP CycloneDX Working Group and SPDX Working Group (Linux Foundation). Software Freedom Conservancy is listed as an others.
Does Open Regulatory Compliance Working Group have an API?
No public API is recorded for Open Regulatory Compliance Working Group.
What industry is Open Regulatory Compliance Working Group in?
Open Regulatory Compliance Working Group's product category is Open Source Regulatory Compliance. Its primary akta.pro industry code is BPADANAD, Conformity Assessment, Testing, Inspection & Certification Cooperation, with a secondary code of BPAEAPAA, Governance, Risk & Compliance (GRC) Platforms. Its NAICS code is 81392 and its SIC code is 8600.