= Paid content
3 min read

Sovereign Tech Resilience launches four new security services

The Sovereign Tech Resilience programme adds four new services: memory safety transition, post-quantum encryption readiness, software supply chain security and Cyber Resilience Act compliance. It also expands two existing services. Applications are open for critical open-source infrastructure projects. (SOVEREIGNTECH)

Sovereign Tech Resilience relaunches with four new services
Sovereign Tech Resilience adds four new services, memory safety transition, post-quantum readiness, supply chain security, and Cyber Resilience Act compliance, and expands two existing services. Applications are open. The Sovereign Tech Resilience program has been running since 2023, after the German Bundestag allocated funds in the federal budget for a bug bounty program. The program's approach combines hands-on engineering, audits, and bug-and-fix bounties, delivered together with industry partners at no cost to participating free and open source software (FOSS) projects. It helps critical open source projects build better capacity to avoid, absorb, and handle security issues over time.Sovereign Tech Resilience's first partners, Neighbourhoodie Software and the Open Source Technology Improvement Fund (OSTIF), worked directly with maintainers to strengthen their projects. Neighbourhoodie wrote over 10,000 lines of new tests for systemd and triaged 221 CVEs for the Yocto Project. OSTIF organized security audits that uncovered an arbitrary-code-execution flaw in conda-forge and logic bugs in Rails' Active Storage that could allow unauthorized file access. The bug-and-fix bounties, run in partnership with YesWeHack, have received more than 790 submissions, with over 80 paid, including 3 rated “critical” and 19 rated “high” in severity.AI tools are accelerating vulnerability discovery. The curl project ended its paid bug bounty in January 2026 over a flood of low-quality AI reports. By spring, its maintainer Daniel Stenberg reported that these had largely stopped, but that security reports were now arriving at twice the previous year's rate, and far more of them were real. In May, Linus Torvalds called the Linux kernel team's security inbox "almost entirely unmanageable." Finding bugs is getting easier; fixing them is not. The relaunched Sovereign Tech Resilience program expands the services we provide to maintainers of critical open source infrastructure.Four new servicesSovereign Tech Resilience is adding four services, each delivered by a specialized implementation partner.Transition to memory safety, with Tweede golf: helps projects identify where moving to memory-safe languages or practices would have the most impact, then supports that transition. Memory safety issues account for up to 70% of serious security bugs according to public reports.Post-quantum encryption readiness, with IAV GmbH: audits a project's cryptographic dependencies and supports migration to standardized post-quantum algorithms, including hybrid approaches. The German Federal Office for Information Security (BSI) and 20 other European security agencies have urged critical infrastructure providers to start the transition now.Software supply chain security, with Liquid Reply: covers reproducible builds, signing and verification of release artifacts, and secure dependency management. This includes the use of Software Bills of Materials (SBOMs), machine-readable lists of every component a piece of software relies on. In 2025, 21 cybersecurity agencies from 15 countries, including the BSI, jointly called on organizations to adopt them.Compliance with the Cyber Resilience Act, with EY Consulting: helps projects assess where they stand against the regulation and close the gaps. Vulnerability reporting obligations under the Cyber Resilience Act went into effect on 11 September 2026; full compliance is required by December 2027.More capacityFor the two existing services we are increasing the number of available service providers to increase capacity and cover a wider range of programming languages and ecosystems:Technical debt management, with Badger Systems, Liquid Reply, and a consortium led by Open Elements GmbHSecurity audits, now with Ada Logics, EY Consulting, and mgm security partnersThe bug bounty platform, with YesWeHack, continues.ApplySovereign Tech Resilience commissions these services from industry partners and delivers them to participating projects. Applications are reviewed on a rolling basis. Critical digital infrastructure projects interested in direct investment should consider the Sovereign Tech Fund.Apply to Sovereign Tech ResilienceLearn more about Sovereign Tech Resilience and the application criteria. Categories: Resilience More articles Call for tenders: Sovereign Tech Resilience programJoin the Bug Resilience Program and get support for vulnerability management!
Subscribe to our newsletter

Subscribe to our newsletter to get the latest updates and news

Member discussion