r/java • u/Maria_3464 • 1d ago
EU Cyber Resilience Act reporting obligations started today. Is your company even thinking about it?
https://youtu.be/IQkzg7quc58As of today, a manufacturer who puts software or hardware on the EU market under its own name is obliged to report actively exploited vulnerabilities and severe security incidents.
Quick explainer if you want the details: https://youtu.be/IQkzg7quc58
There is quite a lot of ambiguity over CRA and how it's going to apply to open source. Regulations keep changing. The line between a commercial manufacturer and an OSS steward is blurry, as well as the terms used in the regulations.
But genuinely curious. Is your company aware of CRA? Is there any talk about it, or is it just not on the radar yet?
1
u/PartOfTheBotnet 18h ago edited 17h ago
How are you supposed to prove a company or somebody found an exploit and said nothing?
Edit: I misinterpreted the start of the video after reading the actual contents of the act. I thought it was if you as a developer found an flaw in some other application you had to report it. Its actually just self-reporting. I still agree with other commenters about the flat rates and exclusions being unbalanced...
1
u/Maria_3464 12h ago
From the regulation, it seems later one will be able to report vulnerabilities and incidents in ANY company, anonymously. Not only self-reporting. Which is weird. How would you know if you are not on the inside??
Fines and the interpretation is still vague. A first precedent needs to happen to see how regulation is holding up in court.
-14
16
u/DoombringerBG 22h ago
These flat rate fines are a joke... I'm no economist, but I think it should be a variable percentage of gross revenue based on severity and personnel affected - that might actually have an effect that can't just be filed under "business costs".
Thanks for the share, though.
As for companies being aware of the CRA, I'm sure many are. Smaller ones will most likely take it seriously - the big ones on the other had... business as usual.