Skip content
Abstract blue and teal flowing data lines with glowing dots on a dark background, representing digital connectivity and technology.

LRQA partners with Source Code Control

Taking control of open-source risk

LRQA is pleased to announce a new partnership with Source Code Control. It marks a pivotal next step in how we support our customers with their supply chain risk requirements and gives a practical way to manage open-source risk and meet new EU cyber.

Source Code Control helps you understand and manage the risk your application code. Their tooling gives your teams clear visibility and control across your software supply chain. You can see exactly which components are affected by known vulnerabilities, focus on the issues that matter most, and remediate. 

Howard Hughes, Managing Director for Cyber at LRQA commented on the new partnership saying:  

“With reporting obligations already in force and full compliance on the horizon, now is the time to take control of your software supply chain. By working with Source Code Control, we can help our customers turn regulation into real resilience.”  

Why now?

The EU Cyber Resilience Act (CRA) sets mandatory cybersecurity standards for products with digital elements. Obligations, including reporting actively exploited vulnerabilities, have applied since 11 September 2026, and the full requirements follow in December 2027. 

Open-source code is a key challenge, most modern software relies on open-source components, each with its own layers of dependencies that are hard to see and monitor. As Log4j showed in 2021, one flaw can affect thousands of products at once. 

Under the CRA, businesses using open source are responsible for that code. They must know what they use, keep a software bill of materials (SBOM) and fix vulnerabilities throughout the product's lifetime. 

To find out how we can support your CRA readiness, get in touch with the LRQA Cyber team. 

Get in touch