Meeting Minutes: Board and BAC Monthly (2026-07-20)
Below are the minutes from the recent BAC and Board of Directors meeting. All members receiving this notification are encouraged to review the minutes and actively participate in the discussion. That's one of the opportunities to engage directly with BAC members by replying in the thread below. Your input helps us ensure the OpenSSL community remains transparent, collaborative, and responsive to your needs.
Attendees
@Anton Arapov, @Jaroslav Reznik, @Jeff Johnson
(A short, reduced vacation-season session.)
High-level topics covered
CRA: reporting obligations start 11 September; standards comment windows are open now
AI-assisted security research collaboration
FIPS 140-3 / CMVP status
OpenSSL Conference: call-for-papers status
Communities housekeeping
Detailed points and discussion
1) CRA: reporting obligations and standards timelines
Jaroslav gave an overview of where CRA implementation stands. From 11 September, actively exploited vulnerabilities and severe incidents must be reported through ENISA's single reporting platform, with the initial report due within 24 hours. The mechanics are still settling: reporting is expected to start as a manual web form behind individual EU Login accounts, ENISA guidance and training materials are expected over the summer, and open questions remain — exactly when the 24-hour clock starts, how embargoed, not-yet-public issues are treated, and whether reports go to ENISA, the national CSIRT, or both. The obligation applies to OpenSSL too: manufacturers and stewards alike carry the reporting duty. Jaroslav shared ENISA's current FAQ with the group.
On standardization, the CRA vertical standards (operating systems, virtualization and containers, networking, PKI, and others) are in or entering public inquiry, with comment windows running roughly through September — now is the time for anyone shipping these technologies to review them. Important class I products can self-assess, while class II products require evaluation by third-party notified bodies, which are targeted — ambitiously — to be ready by November. On cryptography, compliant products will effectively be limited to the EU's Approved Cryptographic Mechanisms (ACM) list plus per-standard additions; the comment period on the current ACM draft closes at the end of July, and the drafts are being looked at from an OpenSSL perspective, since what is approved in the EU will directly shape what users and customers can deploy.
2) AI-assisted security research
Jeff gave a short update on Cisco's continuing AI-assisted security research over OpenSSL code, which is being extended to cover older release branches as well. Rather than forwarding raw tool output, the intent is to validate findings internally first and hand over vetted issues together with proposed patches. The group welcomed that approach. On the OpenSSL side, the conversation about direct access to the tooling will be revived.
3) FIPS 140-3 / CMVP
The FIPS provider 3.5.4 submission, which includes the post-quantum algorithms, has been in CMVP comment resolution since 2 July; historically this phase has taken two to three weeks, so validation is hoped to be close — with no guarantees. The broader aim is a more frequent submission cadence, so customers always have a clear story about which validated module to move to if one is ever invalidated.
4) OpenSSL Conference
The call for papers closed during the week with roughly 120 submissions; a short extension is being considered alongside stepped-up communication around the conference. The program-committee review process is being restructured this year — a simple rating scale plus a general comment, replacing last year's free-form reviews — with CFP-system accounts and an invitation describing expectations to follow for committee members.
5) Communities housekeeping
The delegate cleanup announced earlier is being completed: several companies have confirmed their delegates or nominated replacements, so each community's list will reflect only active delegates. The action items from the May face-to-face are being revived next, with named owners pushing each one forward — a separate post on this will follow.