Hasty Briefsbeta

Bilingual

EU CRA: What does it mean for open source? - Bert Hubert's writings

a day ago
  • The EU Cyber Resilience Act (CRA) regulates commercial activity, not open source projects that are not monetized.
  • Open source contributors and non-profit organizations are generally exempt if they do not engage in commercial activities.
  • Commercial users of open source are responsible for due diligence, including vulnerability reporting and sharing patches.
  • Open source software stewards (e.g., foundations) have a light-touch regulatory regime with no monetary fines for non-compliance.
  • The CRA encourages industry sponsorship of security attestations and audits for open source components.
  • The Debian statement criticized earlier versions, but the final text clarifies that redistribution and non-commercial open source are out of scope.
  • The open source community can contribute to standard-setting processes (CEN/CENELEC) and engage with EU institutions.