Hasty Briefsbeta

Bilingual

The EU's new Cyber Resilience Act is about to tell us how to code - Bert Hubert's writings

a day ago
  • The EU Cyber Resilience Act (CRA) imposes mandatory cybersecurity requirements on almost all software and connected devices sold in the EU, with fines up to €15 million or 2.5% of annual turnover.
  • Key requirements include secure-by-default configurations, no known exploitable vulnerabilities, protection against unauthorized access, data encryption, minimization, and denial-of-service resilience.
  • Open source software has a vague carve-out, but many fear it will apply if any commercial activity is involved, potentially chilling open source innovation.
  • Standards to interpret the essential requirements will be set by European bodies (CEN, CENELEC, or ETSI) in a process that lacks transparency and may be dominated by large corporations.
  • Critical products require third-party audits by notified bodies, but there is currently insufficient capacity and no established standards for such audits.
  • The CRA may harm European innovation and international cooperation, as non-EU projects might avoid EU contributors or users to evade liability.
  • The author recommends contacting national ministries and suggests the act should not be rushed; a narrower initial scope could reduce negative impacts.