Cyber Resilience Act

Adam Wilson flyboynw at gmail.com
Sat Sep 19 20:25:15 UTC 2026


On Saturday, 19 September 2026 at 18:19:41 UTC, Gregor Mückl 
wrote:
> On Saturday, 19 September 2026 at 18:01:44 UTC, Adam Wilson 
> wrote:
>> All of this is a very complex way of saying that DLF will have 
>> to hire EU counsel to write these policies and provide ongoing 
>> oversight of code changes and responses to security incidents 
>> to ensure continuing compliance.
>>
>
> No, it's actually not. Just make sure to follow proper best 
> practices regarding secure software development, CRA or not. As 
> long as you do that, you're in the clear and you reduce your 
> users' compliance workload implicitly.

I would point out that this is entirely your personal opinion. No 
lawyer I've talked would ever say "Yea man, just wing it bro", 
which is effectively what you're saying we should do. If a policy 
is required by statute than the policy must be written, enforced, 
and on-going compliance oversight maintained either by counsel or 
independent audit.

The DLF has neither the money nor the human-time capacity to 
"reduce users' compliance workload implicitly." Compliance with 
local statutes has always been the sole responsibility of the 
end-user of any software.

The DLF is not and cannot be responsible for ensuring compliance 
with local security statutes for exactly the same reason as the 
DLF is not and cannot be responsible for ensuring compliance with 
local copyright statutes. The logic is no different, even if the 
text of the law is.

The community will continue to fix bugs, including security 
vulnerabilities, as fixes are offered and such fixes meet our 
engineering standards. But we cannot compel any human to do such 
work without compensation as that would be slavery and is highly 
illegal.

If you want to help the DLF comply with your local statutes then 
you or your employer will have to pay the bill for your time. The 
DLF simply does not have the capability to make any compliance 
guarantees of any kind for any reason, be it Copyright or 
Security laws.


More information about the Digitalmars-d mailing list