Cyber Resilience Act

Arafel er.krali at gmail.com
Thu Sep 17 08:54:06 UTC 2026


On 9/17/26 08:52, user1234 wrote:
> 
> So basically the RCA is made as a tool to taxes the tech-giants. It is a 
> bit obscure how and if the sword will hit you. that depends on how each 
> particular EU member decides to deal wi the RCA.
> 
> The risks are
> 
>> Non-compliance with the essential requirements or manufacturer 
>> obligations can attract fines of up to €15 million or 2.5% of total 
>> worldwide annual turnover, whichever is higher. Lower ceilings apply 
>> to other infringements and to supplying incorrect information.
> 
> So in a nutshell. Unless you are a tech giant you can ignore the RCA.

In order to reinforce this point and to focus the discussion, I would 
like to point out that non-profit open source is fully exempted [1]:

> The CRA recognises that, to foster the development and deployment of free and open-source software, special attention should be paid to the nature of the different development models of software distributed and developed under free and open-source software licences.  
> 
> This is why only **free and open-source software** that is made available on the market, and therefore supplied for distribution or use in the course of a commercial activity, falls in scope of the Cyber Resilience Act. Notably, the provision of products with digital elements qualifying as free and open-source software that are not monetised by their manufacturers should not be considered to be a commercial activity. Additionally, the CRA does not apply to developers who contribute with source code to free and open-source software that are not under their responsibility.

Then it goes on to include some nuances for those cases where somebody 
provides paid support for otherwise free and open source software ("open 
source software stewards").

I know I'll be in the minority or even alone here, but, all in all, and 
without having read the full details, I do think that it is a good step 
in the right direction. Wild deregulation and no responsibility 
whatsoever for bugs and vulnerabilities is not any good for anybody in 
the long term.

[1]: https://digital-strategy.ec.europa.eu/en/policies/cra-open-source


More information about the Digitalmars-d mailing list