mappings:
- id: M-OSPS-AC-01-CRA
relationship: relates-to
source: OSPS-AC-01
targets:
- entry-id: 1.2d
- entry-id: 1.2e
- entry-id: 1.2f
- id: M-OSPS-AC-02-CRA
relationship: relates-to
source: OSPS-AC-02
targets:
- entry-id: 1.2f
- id: M-OSPS-AC-03-CRA
relationship: relates-to
source: OSPS-AC-03
targets:
- entry-id: 1.2f
- id: M-OSPS-AC-04-CRA
relationship: relates-to
source: OSPS-AC-04
targets:
- entry-id: 1.2d
- entry-id: 1.2e
- entry-id: 1.2f
- id: M-OSPS-BR-01-CRA
relationship: relates-to
source: OSPS-BR-01
targets:
- entry-id: 1.2f
- id: M-OSPS-BR-02-CRA
relationship: relates-to
source: OSPS-BR-02
targets:
- entry-id: 1.2f
- id: M-OSPS-BR-03-CRA
relationship: relates-to
source: OSPS-BR-03
targets:
- entry-id: 1.2d
- entry-id: 1.2e
- entry-id: 1.2f
- entry-id: 1.2i
- entry-id: 1.2j
- entry-id: 1.2k
- id: M-OSPS-BR-04-CRA
relationship: relates-to
source: OSPS-BR-04
targets:
- entry-id: 1.2d
- entry-id: 1.2f
- entry-id: 1.2h
- entry-id: 1.2j
- entry-id: 1.2l
- entry-id: "2.5"
- id: M-OSPS-BR-05-CRA
relationship: relates-to
source: OSPS-BR-05
targets:
- entry-id: 1.2b
- entry-id: 1.2d
- entry-id: 1.2f
- entry-id: 1.2h
- entry-id: 1.2j
- entry-id: "2.1"
- entry-id: "2.2"
- entry-id: "2.3"
- id: M-OSPS-DO-01-CRA
relationship: relates-to
source: OSPS-DO-01
targets:
- entry-id: 1.2b
- entry-id: 1.2j
- entry-id: 1.2k
- id: M-OSPS-DO-02-CRA
relationship: relates-to
source: OSPS-DO-02
targets:
- entry-id: 1.2c
- entry-id: 1.2l
- entry-id: "2.1"
- entry-id: "2.2"
- entry-id: "2.5"
- entry-id: "2.6"
- id: M-OSPS-DO-03-CRA
relationship: relates-to
source: OSPS-DO-03
targets:
- entry-id: 1.2d
- id: M-OSPS-DO-05-CRA
relationship: relates-to
source: OSPS-DO-05
targets:
- entry-id: 1.2c
- entry-id: "2.6"
- id: M-OSPS-DO-06-CRA
relationship: relates-to
source: OSPS-DO-06
targets:
- entry-id: "2.1"
- id: M-OSPS-GV-02-CRA
relationship: relates-to
source: OSPS-GV-02
targets:
- entry-id: 1.2l
- entry-id: "2.3"
- entry-id: "2.4"
- entry-id: "2.6"
- id: M-OSPS-GV-03-CRA
relationship: relates-to
source: OSPS-GV-03
targets:
- entry-id: 1.2l
- entry-id: "2.4"
- id: M-OSPS-GV-04-CRA
relationship: relates-to
source: OSPS-GV-04
targets:
- entry-id: 1.2d
- entry-id: 1.2l
- entry-id: "2.1"
- entry-id: "2.2"
- entry-id: "2.5"
- entry-id: "2.6"
- id: M-OSPS-LE-01-CRA
relationship: relates-to
source: OSPS-LE-01
targets:
- entry-id: 1.2b
- entry-id: 1.2f
- id: M-OSPS-LE-02-CRA
relationship: relates-to
source: OSPS-LE-02
targets:
- entry-id: 1.2b
- id: M-OSPS-LE-03-CRA
relationship: relates-to
source: OSPS-LE-03
targets:
- entry-id: 1.2b
- id: M-OSPS-QA-01-CRA
relationship: relates-to
source: OSPS-QA-01
targets:
- entry-id: 1.2b
- entry-id: 1.2f
- entry-id: 1.2j
- id: M-OSPS-QA-02-CRA
relationship: relates-to
source: OSPS-QA-02
targets:
- entry-id: "2.1"
- entry-id: "2.2"
- entry-id: "2.3"
- id: M-OSPS-QA-03-CRA
relationship: relates-to
source: OSPS-QA-03
targets:
- entry-id: 1.2f
- entry-id: 1.2k
- id: M-OSPS-QA-04-CRA
relationship: relates-to
source: OSPS-QA-04
targets:
- entry-id: 1.2b
- entry-id: 1.2f
- id: M-OSPS-QA-05-CRA
relationship: relates-to
source: OSPS-QA-05
targets:
- entry-id: 1.2b
- id: M-OSPS-QA-06-CRA
relationship: relates-to
source: OSPS-QA-06
targets:
- entry-id: "2.3"
- id: M-OSPS-SA-01-CRA
relationship: relates-to
source: OSPS-SA-01
targets:
- entry-id: 1.2a
- entry-id: 1.2b
- id: M-OSPS-SA-02-CRA
relationship: relates-to
source: OSPS-SA-02
targets:
- entry-id: 1.2a
- entry-id: 1.2b
- id: M-OSPS-SA-03-CRA
relationship: relates-to
source: OSPS-SA-03
targets:
- entry-id: "1.1"
- entry-id: 1.2j
- entry-id: 1.2k
- entry-id: "2.2"
- id: M-OSPS-VM-01-CRA
relationship: relates-to
source: OSPS-VM-01
targets:
- entry-id: "2.1"
- entry-id: "2.2"
- entry-id: "2.3"
- entry-id: "2.6"
- entry-id: "2.7"
- entry-id: "2.8"
- id: M-OSPS-VM-02-CRA
relationship: relates-to
source: OSPS-VM-02
targets:
- entry-id: "2.5"
- id: M-OSPS-VM-03-CRA
relationship: relates-to
source: OSPS-VM-03
targets:
- entry-id: "2.5"
- entry-id: "2.6"
- id: M-OSPS-VM-04-CRA
relationship: relates-to
source: OSPS-VM-04
targets:
- entry-id: 1.2a
- entry-id: 1.2b
- entry-id: "2.1"
- entry-id: "2.4"
- entry-id: "2.6"
- id: M-OSPS-VM-05-CRA
relationship: relates-to
source: OSPS-VM-05
targets:
- entry-id: 1.2a
- entry-id: 1.2b
- entry-id: 1.2c
- entry-id: "2.1"
- entry-id: "2.2"
- entry-id: "2.3"
- entry-id: "2.4"
- id: M-OSPS-VM-06-CRA
relationship: relates-to
source: OSPS-VM-06
targets:
- entry-id: 1.2a
- entry-id: 1.2b
- entry-id: 1.2c
- entry-id: "2.1"
- entry-id: "2.2"
- entry-id: "2.3"
- entry-id: "2.4"
metadata:
author:
id: openssf
name: OSPS Baseline Authors
type: Human
description: |
Cross-walk from the Open Source Project Security (OSPS) Baseline
controls to EU Cyber Resilience Act. Each mapping asserts a "relates-to"
relationship; strength, confidence-level, and rationale are left
unset and should be added as the mappings are individually
reviewed.
draft: true
gemara-version: 1.2.0
id: osps-baseline-to-cra
mapping-references:
- description: |
The Open Source Project Security (OSPS) Baseline is a set of security
criteria that projects should meet to demonstrate a strong security
posture.
id: osps-baseline
title: Open Source Project Security Baseline
url: https://github.com/ossf/security-baseline
version: draft
- description: Regulation (EU) 2024/2847 of the European Parliament and of the
Council of 23 October 2024 on horizontal cybersecurity requirements for
products with digital elements and amending Regulations (EU) No 168/2013
and (EU) 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act)
(Text with EEA relevance)
id: CRA
title: Cyber Resilience Act
url: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202402847#tit_1
version: 20.11.2024
type: MappingDocument
version: v0.0.0-dev-671f23f
source-reference:
entry-type: Control
reference-id: osps-baseline
target-reference:
entry-type: Guideline
reference-id: CRA
title: OSPS Baseline to EU Cyber Resilience Act Mapping
Search / openssf/osps-baseline-to-cra / v0.0.0-dev-671f23f
Release · v0.0.0-dev-671f23f
openssf/osps-baseline-to-cra Mapping Document
openssf/osps-baseline-to-cra
Cross-walk from the Open Source Project Security (OSPS) Baseline controls to EU Cyber Resilience Act. Each mapping asserts a "relates-to" relationship; strength, confidence-level, and rationale are left unset and should be added as the mappings are individually reviewed.
Published by OSPS Baseline Authors
License No license declared
Install
OCI v1.1$grcli unpack --repository openssf/osps-baseline-to-cra --version v0.0.0-dev-671f23f grcli unpack verifies this signature against the
recorded identity below and fails closed before writing
any files — no separate verify step needed. Pass
--no-verify to skip.
- Coordinate
- oci.grc.store/openssf/osps-baseline-to-cra:v0.0.0-dev-671f23f
- Manifest digest
- sha256:7e84e4d7d85ac903579f712e5afb5ca39f1a4425646ad7f8048dce6754fda4c0
- Signed by
- no signature recorded
Identity recorded by this hub when the version was published;
unpack (above) checks the signature against it.
Verify in CI — check the signature without downloading
$grcli verify --repository openssf/osps-baseline-to-cra --version v0.0.0-dev-671f23f Read-only: downloads nothing and exits non-zero if the signature or the recorded identity doesn't match — use it as an admission/policy gate.
Provenance
1 layer| Digest | Media type | Size |
|---|---|---|
| e0efbfd8e1b9… | application/vnd.gemara.artifact.v1+yaml | 7.1 KiB |
Bundle config blob
{
"bundle-version": "1.0",
"gemara-version": "1.2.0",
"metadata": {
"provenance": {
"buildDefinition": {
"buildType": "https://grc.store/grcli/buildtype/v0",
"externalParameters": {
"artifact": {
"id": "osps-baseline-to-cra",
"type": "MappingDocument"
},
"target": {
"registry": "oci.grc.store",
"repository": "openssf/osps-baseline-to-cra",
"tag": "v0.0.0-dev-671f23f"
}
},
"internalParameters": {
"CI": "true",
"GITHUB_ACTIONS": "true",
"GITHUB_ACTOR": "eddie-knight",
"GITHUB_REF": "refs/heads/main",
"GITHUB_REPOSITORY": "eddie-knight/security-baseline",
"GITHUB_RUN_ATTEMPT": "1",
"GITHUB_RUN_ID": "26617016306",
"GITHUB_SHA": "671f23f015e4b0f6108ab8f82f0eba7f89d55dce",
"GITHUB_WORKFLOW": "Publish to grc.store",
"RUNNER_OS": "Linux"
},
"resolvedDependencies": [
{
"name": "/home/runner/work/_temp/staged/osps-to-cra.yaml",
"uri": "file:///home/runner/work/_temp/staged/osps-to-cra.yaml",
"digest": {
"sha256": "e0efbfd8e1b9e147fded9cd444c029800233ea2c3445451ad79f63f9b8fb1794"
}
},
{
"name": "source",
"uri": "git+https://github.com/eddie-knight/security-baseline@671f23f015e4b0f6108ab8f82f0eba7f89d55dce",
"digest": {
"gitCommit": "671f23f015e4b0f6108ab8f82f0eba7f89d55dce"
}
}
]
},
"runDetails": {
"builder": {
"id": "https://github.com/eddie-knight/security-baseline/actions/runs/26617016306",
"version": {
"go": "go1.25.0",
"go-arch": "amd64",
"go-os": "linux",
"grcli": "v0.2.2"
}
},
"metadata": {
"invocationId": "26617016306-1",
"startedOn": "2026-05-29T03:57:18.938772184Z",
"finishedOn": "2026-05-29T03:57:19.065443695Z"
},
"byproducts": [
{
"name": "osps-to-cra.yaml",
"digest": {
"sha256": "e0efbfd8e1b9e147fded9cd444c029800233ea2c3445451ad79f63f9b8fb1794"
}
}
]
}
}
},
"artifacts": [
{
"name": "osps-to-cra.yaml",
"type": "MappingDocument",
"id": "osps-baseline-to-cra",
"role": "artifact"
}
]
} No rich preview yet
This UI can't render MappingDocument artifacts richly yet. The raw content is shown below, and the artifact stays pullable via the coordinate above.