The Open Source Security Foundation (OpenSSF) welcomes the European Commissions proposed amendments to the NIS 2 Directive as an important step toward a more coherent, scalable, and simplified EU cybersecurity framework.
OpenSSF
NGO · United States · EU Transparency Register 440231552636-41
Counts here are a floor, never a total: they cover the 326 consultation files tracked so far (29,503 submissions, mostly 2025–26), so an organization's real filing history is larger, not smaller.
Who they are
Among the 784 non-governmental organisations on this site, they rank #136 by legislative files engaged — a count of participation, not a measure of influence.
- Register category
- Non-governmental organisations
- Registered as
- Open Source Security Foundation (OpenSSF)
- Head office
- San Francisco, United states
Self-declared to the EU Transparency Register (snapshot 30 Aug 2026); cost bands are floors, not audited totals. Reused under Commission Decision 2011/833/EU.
Track OpenSSF in PolicySpeak: request access →
Work at OpenSSF? so we know who speaks for it.
Their record over time
OpenSSF filed 6 positions between 14 Apr 2025 and 15 Jul 2026, across 4 of the 326 legislative files tracked here, attaching a full position paper 6 times.
What they argued
OpenSSF welcomes the positive direction reflected in the revised Cybersecurity Act proposal and strongly supports the recognition of OSS stewards within the revised CSA framework. The submission highlights the importance of deeper cooperation between ENISA and open source communities to strengthen Europes cybersecurity resilience, software supply chain security, and secure-by-design objectives.
This is the Open Source Security Foundation (OpenSSF) Global Cyber Policy Working Groups response to the European Commissions Public Consultation for The EU Cybersecurity Act Call for Evidence (with comments from the OpenSSF Public Policy Committee). See the attached file for details of our response.
The Open Source Security Foundation (OpenSSF) welcomes the European Commissions draft Guidance on the application of Regulation (EU) 2024/2847 (Cyber Resilience Act) and appreciates the opportunity to contribute to this consultation.
Attached is the feedback from the Open Source Security Foundation (OpenSSF) on the Technical description of important and critical products with digital elements for the CRA. We used the comment template as requested. Thank you for the opportunity to comment.
The Open Source Security Foundation (OpenSSF) welcomes the review of the European Interoperability Framework (EIF) and supports its objectives of strengthening interoperability, digital sovereignty, resilience and competitiveness. While the Call for Evidence rightly emphasizes resilience and trust, it gives comparatively little attention to the cybersecurity dimension needed to achieve these objectives.
Looking for an argument rather than an organization? Search every submission for a phrase and see everyone who used it.
Turns up on the same files
Organizations that also filed on at least two of the same consultations. A shared interest in the same dossiers — not evidence of coordination, and we do not suggest any.
- DIGITALEUROPE · 3 files in common
- ITI - Information Technology Industry Council · 3 files in common
- UNIFE · 3 files in common
- DECATHLON SE · 3 files in common
- Associazione Italiana Internet Provider · 3 files in common
Showing 5 of 52.
Is this your organization?
Everything on this page comes from OpenSSF’s own submissions to the European Commission — we have added nothing and interpreted nothing. If something is wrong or out of date, email info@policyspeak.com and we will correct it. If you are an individual named in a record, our privacy policy sets out your rights to correction, objection and removal.
Quotes are verbatim from submissions published by the European Commission, trimmed to their opening passage and never summarized by a model. Organizations only, never individuals. Reused under Commission Decision 2011/833/EU; the European Commission is not liable for this reuse.