Security Slam 2026 – Fall Edition is a 30-day virtual event from October 5 through November 6, 2026.

What Is the Security Slam?

The Open Source Security Foundation (OpenSSF) is partnering with the Cloud Native Computing Foundation (CNCF) Security Technical Advisory Group (TAG Security) to support the 2026 Security Slam at KubeCon + CloudNativeCon North America. 

The 30-day challenge runs from October 5 through November 6 and highlights OpenSSF projects as practical tools that help improve project security posture. Participants will use OpenSSF projects, among others, to achieve security hygiene milestones tailored to their project’s maturity level.

OpenSSF project leads, staff, and maintainers have assisted in the creation of the “Slam Library,” a set of web resources to guide participants through each challenge, and will continue to be available throughout the month via the official Security Slam website.

How to Participate

Register now to receive reminders and instructions before the event kicks off on October 5. Stop by the OpenSSF booth #313 in the KubeCon Solutions Showcase anytime during the week of November 10-12 to pick up participant achievement awards.

A Growing Community Effort

The Security Slam is a CNCF community activity that has taken many different shapes over the years. Now on its sixth iteration, the Slam is designed to help projects understand and improve their high level security posture.

Expanded Eligibility

Previously limited to CNCF projects due to the nature of the evaluation tools available, the Slam is now taking advantage of new tools to greatly broaden the qualifications for participation: Any open source project is invited to participate!

The event has had several permutations in its length. In the case of the Kubernetes Lightning Round, the slam was a day of onboarding new contributors to Kubernetes with a focus on security hygiene improvements to seven different subprojects. Taking it a step further, the 2025 event featured weeks of preparatory work with maintainers, and 45-minute live sessions with maintainers and anyone who wanted to join from the audience at KubeCon + CloudNativeCon Europe.

This year returns to the 30-day format that produced strong results in 2023. Then, projects were given their own iron-on badges and a framed plaque to highlight the milestones that they completed during the 30-day event. Not only were the plaques seen at project tables long after the event ended, but we received reports of significant project wins due to the efforts achieved during that event. The 2026 Fall Security Slam builds on the success of earlier events, including the Spring event, where projects achieved major security milestones.

What to Expect for the 2026 Fall Edition

Here are some key similarities you will see:

And there are new elements as well:

Key Dates to Remember:

Registration is now open: Sign up to receive reminders and instructions related to the event!