The EU's new Cyber Resilience Act is about to tell us how to code - Bert Hubert's writings
a day ago
- The EU Cyber Resilience Act (CRA) imposes mandatory cybersecurity requirements on almost all software and connected devices sold in the EU, with fines up to €15 million or 2.5% of annual turnover.
- Key requirements include secure-by-default configurations, no known exploitable vulnerabilities, protection against unauthorized access, data encryption, minimization, and denial-of-service resilience.
- Open source software has a vague carve-out, but many fear it will apply if any commercial activity is involved, potentially chilling open source innovation.
- Standards to interpret the essential requirements will be set by European bodies (CEN, CENELEC, or ETSI) in a process that lacks transparency and may be dominated by large corporations.
- Critical products require third-party audits by notified bodies, but there is currently insufficient capacity and no established standards for such audits.
- The CRA may harm European innovation and international cooperation, as non-EU projects might avoid EU contributors or users to evade liability.
- The author recommends contacting national ministries and suggests the act should not be rushed; a narrower initial scope could reduce negative impacts.