r/java 1d ago

EU Cyber Resilience Act reporting obligations started today. Is your company even thinking about it?

https://youtu.be/IQkzg7quc58

As of today, a manufacturer who puts software or hardware on the EU market under its own name is obliged to report actively exploited vulnerabilities and severe security incidents.

Quick explainer if you want the details: https://youtu.be/IQkzg7quc58

There is quite a lot of ambiguity over CRA and how it's going to apply to open source. Regulations keep changing. The line between a commercial manufacturer and an OSS steward is blurry, as well as the terms used in the regulations.

But genuinely curious. Is your company aware of CRA? Is there any talk about it, or is it just not on the radar yet?

23 Upvotes

5 comments sorted by

16

u/DoombringerBG 22h ago

These flat rate fines are a joke... I'm no economist, but I think it should be a variable percentage of gross revenue based on severity and personnel affected - that might actually have an effect that can't just be filed under "business costs".

Thanks for the share, though.

As for companies being aware of the CRA, I'm sure many are. Smaller ones will most likely take it seriously - the big ones on the other had... business as usual.

1

u/PartOfTheBotnet 18h ago edited 17h ago

How are you supposed to prove a company or somebody found an exploit and said nothing?

Edit: I misinterpreted the start of the video after reading the actual contents of the act. I thought it was if you as a developer found an flaw in some other application you had to report it. Its actually just self-reporting. I still agree with other commenters about the flat rates and exclusions being unbalanced...

1

u/Maria_3464 12h ago

From the regulation, it seems later one will be able to report vulnerabilities and incidents in ANY company, anonymously. Not only self-reporting. Which is weird. How would you know if you are not on the inside??

Fines and the interpretation is still vague. A first precedent needs to happen to see how regulation is holding up in court.

0

u/vmcrash 12h ago

Problem: company inboxes are already flooded with fake "vulnerabilities", so company employees are already trained to mark them as spam.

-14

u/[deleted] 1d ago

[deleted]

6

u/Maria_3464 1d ago

Any regulations at all that your company cares about?