Milestones, standards, and the conformance behind our work — so OEMs, Tier 1 suppliers, and industrial clients can verify, not just trust.
A documented, verifiable program for identifying and satisfying the license obligations attached to the open source we use and ship.
Self-certified · 2026A structured process for tracking known vulnerabilities in open source components and responding to them — supply-chain security, not an afterthought.
Self-certified · 2026Most of the CRA conversation right now is aimed at 11 December 2027. That's the wrong date to plan around first. Article 14 reporting starts on 11 September 2026, and it covers products already on the EU market — on a clock measured in hours, not quarters.
Read more →norxs has self-certified its open source program against two international standards published through the OpenChain Project: ISO/IEC 5230:2020 for open source license compliance, and ISO/IEC 18974:2023 for open source security assurance.
Read more →