EU CRA: What does it mean for open source? - Bert Hubert's writings
a day ago
- The EU Cyber Resilience Act (CRA) regulates commercial activity, not open source projects that are not monetized.
- Open source contributors and non-profit organizations are generally exempt if they do not engage in commercial activities.
- Commercial users of open source are responsible for due diligence, including vulnerability reporting and sharing patches.
- Open source software stewards (e.g., foundations) have a light-touch regulatory regime with no monetary fines for non-compliance.
- The CRA encourages industry sponsorship of security attestations and audits for open source components.
- The Debian statement criticized earlier versions, but the final text clarifies that redistribution and non-commercial open source are out of scope.
- The open source community can contribute to standard-setting processes (CEN/CENELEC) and engage with EU institutions.