OpenCRE

An interactive knowledge graph for security standards and guidelines when designing, developing, auditing, testing, and procuring for cybersecurity. It links and unlocks these resources into one unified overview.

About OpenCRE

Go to https://www.opencre.org to see OpenCRE working and more explanation. OpenCRE stands for Open Common Requirement enumeration. It is an interactive content linking platform for uniting security standards and guidelines. It offers easy and robust access to relevant information when designing, developing, testing and procuring secure software.

OpenCRE consists of:

  • The application: a python web and cli application to access the data, running publicly at opencre.org

  • The catalog data: a catalog of Common Requirements (CREs)

  • The mapping data: links from each CRE to relevant sections in a range of standards

  • Tools and guidelines to contribute to the data and to run the application locally

Project Leaders

Rob van der Veer

Project Leader

Email

Spyros Gasteratos

Project Leader

Email

Project Information

Production Project
Classification
Tool
Language
Python
License
Creative Commons Zero CC0 v1.0 Universal
OWASP Logo
OWASP is a nonprofit foundation improving software security through open-source projects, global communities, and education. All resources are free and open to everyone.
OWASP, the OWASP logo, and Global AppSec are registered trademarks and AppSec Days, AppSec California, AppSec Cali, SnowFROC, OWASP Boston Application Security Conference, and LASCON are trademarks of the OWASP Foundation, Inc.
© 2026, OWASP Foundation Inc. All rights reserved.
OpenCRE