The Cyber Resilience Act (CRA), adopted in December 2023, imposes new security obligations on all software products or products incorporating software in the EU. This regulation directly affects the Open Source sector, by requiring the provision of security certificates, documentation of the software components used, and the implementation of vulnerability management processes. To support the creators, integrators and users of open source software, the CNLL has drawn up a practical guide in collaboration with inno³, which proposes concrete solutions to help open source players comply with the CRA. The presentation will enable participants to grasp the issues and adopt practices adapted to this new regulatory framework. This is an essential opportunity for the open source community to anticipate the challenges and opportunities presented by these new cybersecurity requirements.