EU CRA and the Open Source Ecosystem: A Suggestion - Bert Hubert's writings
2 days ago
- The EU Cyber Resilience Act (CRA) aims to improve hardware and software security but has ambiguous regulations that could directly affect open source projects and foundations.
- Open source software is integral to most commercial products, yet many open source projects lack budgets for compliance, creating a risk to innovation.
- The author suggests amending the CRA to require commercial manufacturers using open source to invest in its security, possibly through industry consortia, rather than regulating open source projects directly.
- Manufacturers currently use open source components without contributing to their security; the CRA's due diligence clause could be leveraged to foster industry-funded improvements.
- The proposed approach would enhance open source security, allocate responsibility to profit-making entities, and avoid stifling open source innovation with unclear rules.
- The CRA's current definitions of 'open-source software steward' and 'collaborative development' are confusing and could create legal uncertainty for small projects.
- The act should clarify what constitutes 'commercial activity' to avoid unintended regulation of non-profit open source efforts.