Hasty Briefsbeta

Bilingual

EU CRA and the Open Source Ecosystem: A Suggestion - Bert Hubert's writings

2 days ago
  • The EU Cyber Resilience Act (CRA) aims to improve hardware and software security but has ambiguous regulations that could directly affect open source projects and foundations.
  • Open source software is integral to most commercial products, yet many open source projects lack budgets for compliance, creating a risk to innovation.
  • The author suggests amending the CRA to require commercial manufacturers using open source to invest in its security, possibly through industry consortia, rather than regulating open source projects directly.
  • Manufacturers currently use open source components without contributing to their security; the CRA's due diligence clause could be leveraged to foster industry-funded improvements.
  • The proposed approach would enhance open source security, allocate responsibility to profit-making entities, and avoid stifling open source innovation with unclear rules.
  • The CRA's current definitions of 'open-source software steward' and 'collaborative development' are confusing and could create legal uncertainty for small projects.
  • The act should clarify what constitutes 'commercial activity' to avoid unintended regulation of non-profit open source efforts.