Skip to main content


How do the supply chain security obligations under the EU #NIS2 affect those that develop the #opensource used by "essential providers" of digital infrastructure?
@fsfe @openssf and @nlnetlabs are concerned that the term 'supplier' includes economic actors publishing #FOSS that are not a suitable counterparty for the type of reqs the draft imposes on NIS2 entities in their relation with direct suppliers.
Analysis of feedback: https://blog.nlnetlabs.nl/supply-chain-security-obligations-for-nis2-regulated-entities-vs-developers-of-open-source-software/
⇧