Loading…
25-27, August 2025
Amsterdam, Netherlands
View More Details & Registration
Note: The schedule is subject to change.

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for Open Source Summit Europe 2025 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

This schedule is automatically displayed in Central European Summer Time, CEST (UTC +2). To see the schedule in your preferred timezone, please select from the drop-down menu to the right. 

IMPORTANT NOTE: Timing of sessions and room locations are subject to change.

Venue: G105 clear filter
arrow_back View All Dates
Monday, August 25
 

11:20 CEST

Securing Software Supply Chains: OpenCode as Building Block for Sovereign Digital Infrastructure - Leonhard Kugler, Zentrum Digitale Souveränität
Monday August 25, 2025 11:20 - 12:00 CEST
As software becomes increasingly critical to the functioning of the state, economy, and society, ensuring its security and stability is a core task for governments. Secure software supply chains are a key component of this effort and a decisive factor for successful digitalisation. To effectively guarantee supply chain security, a new approach to IT security architecture is required, one that brings together the expertise of security experts, developers, and government agencies to standardise testing procedures and facilitate collaborative security analyses. The openCode platform, run by the German Centre for Digital Sovereignty (ZenDiS), is central in addressing this challenge: by establishing binding security standards, promoting transparency, and enabling the tracing of origins for critical software components, openCode helps build resilient, sovereign OS infrastructure for public administration. A recent strategy paper published by ZenDiS and the German Federal Office for Information Security develops a strategy on how to secure software supply chains with openCode, which will be presented in this talk. 
Speakers
avatar for Leonhard Kugler

Leonhard Kugler

Head of Open Source Platform, Zentrum Digitale Souveränität
Leonhard Kugler, head of ZenDiS' openCode software platform, has over 20 years of experience in IT, digitalisation, and organisational development. With a background that spans software development, founding a software development and services agency, and serving as an interim manager... Read More →
Monday August 25, 2025 11:20 - 12:00 CEST
G105
  OpenGovCon
  • Audience Experience Level Any

13:30 CEST

Designing Policy and Support for a Sustainable Open Source Adoption in the Public Sector - Johan Linåker & Sachiko Muto, RISE Research Institutes of Sweden
Monday August 25, 2025 13:30 - 14:10 CEST
The public sector has been an active user of Open Source Software (OSS) since its inception. Yet, adoption and reuse have fluctuated, along with the many policies and initiatives providing guidance and support. On the positive side, there is a wealth of experience to draw from.

In this presentation, we aim to inspire and provide insights from a study of 16 countries that are mature in their digital practices, as indicated through a set of digital maturity indicators. These countries are surveyed regarding government policies, rationales, support mechanisms, means of promotion, and success stories on OSS adoption.

We find diverse means in how policy is designed and motivated to support both the adoption and use, as well as development and release of OSS across sectors. The cases further provide in-depth examples of how the policies can be supported and enabled using Open Source Program Offices (OSPOs), communities, and codified knowledge.

Based on our findings, we will provide attendees as well as policy- and decisionmakers at national, regional, and local government levels, with recommendations for designing and fostering sustainable policies for OSS adoption.
Speakers
avatar for Sachiko Muto

Sachiko Muto

Senior Researcher, RISE Research Institutes of Sweden
Sachiko Muto is the Chair of OpenForum Europe and a senior researcher at RISE Research Institutes of Sweden. She originally joined OFE in 2007 and served for several years as Director with responsibility for government relations and then as CEO. Sachiko has degrees in Political Science... Read More →
avatar for Johan Linåker

Johan Linåker

Senior Researcher, RISE Research Institutes of Sweden
Monday August 25, 2025 13:30 - 14:10 CEST
G105
  OpenGovCon

15:35 CEST

The Chain of Command: Building Trust Across Public Sector Software Pipelines - John Kjell, ControlPlane
Monday August 25, 2025 15:35 - 16:15 CEST
The CNCF’s Cloud Native Public Sector User Group, founded in 2023, aims to advance cloud-native best practices within the public sector, with a focus on improving workflows and supply chain security.

Public sector organizations face unique and evolving challenges that complicate software supply chain security. These include the absence of standardized practices for what software can enter isolated networks, no shared root of trust, and a lack of frameworks for integrating public and private attestations. There's also no guidance for using shared, non-public infrastructure—hindering trust and automation.

This talk, based on learnings from the groups recent publications, explores how public sector consumers can receive trusted attestations that prove origin, integrity, and authorship—across companies, networks, and government entities. It also asks: what’s the minimum assurance needed for trust, and how do we balance stringent requirements without sidelining small suppliers?

Key Takeaways:

• Current challenges in public sector supply chain security

• Emerging needs for trust, attestations, and integration

• Ideas for equitable, scalable solutions across supplier sizes
Speakers
avatar for John Kjell

John Kjell

Principal Consultant, ControlPlane
John is a maintainer for the Witness and Archivista sub-projects under in-toto. Additionally, John is a co-chair to CNCF's TAG Security and active with multiple projects within the OpenSSF. Prior to ControlPlane, John was the Director of Open Source at TestifySec and an engineering... Read More →
Monday August 25, 2025 15:35 - 16:15 CEST
G105
  OpenGovCon

16:30 CEST

Prepare for the CRA: Open Source Governance in the Age of Cyber Resilience - Andrew Martin, ControlPlane
Monday August 25, 2025 16:30 - 17:10 CEST
The Cyber Resilience Act’s implementation deadline is 2027, but most organisations are reporting their current unreadiness. In this panel we lay bare the responsibilities individuals, maintainers, and foundations are required to conform to through four varying lenses: the CEO of open source foundation OpenUK; CTO of open source supply chain firm Kursai; OSPO PM for security multinational Sonatype; and CEO of open source security consultants ControlPlane. They hold current and previous security and open source leadership positions across The Linux Foundation, Canonical, OpenSSF, CNCF, FINOS, and OpenUK, and have been working on CRA responses and accountability since 2022.

Join us to discuss community responses to compliance, the Linux Foundation’s approach to self-attestation, and strategies for preparing your organisation's response to the impending legislation.
Speakers
avatar for Andrew Martin

Andrew Martin

CEO, ControlPlane
Andrew has an incisive security engineering ethos gained building and destroying high-traffic web applications. Proficient in systems development, testing, and operations, he is at his happiest profiling and securing every tier of a cloud native system, and has battle-hardened experience... Read More →
Monday August 25, 2025 16:30 - 17:10 CEST
G105
  OpenGovCon
 
  • Filter By Date
  • Filter By Venue
  • Filter By Type
  • Audience Experience Level
  • Timezone

Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date -