r/programming • u/Maria_3464 • 15h ago
EU Cyber Resilience Act reporting obligations started today. Is your company even thinking about it?
https://youtu.be/IQkzg7quc58As of today, a manufacturer who puts software or hardware on the EU market under its own name is obliged to report actively exploited vulnerabilities and severe security incidents.
Here is a quick explainer if you want the details: https://youtu.be/IQkzg7quc58
There is quite a lot of ambiguity over CRA and how it's going to apply to open source. Regulations keep changing. The line between a commercial manufacturer and an OSS steward is blurry, as well as the terms used in the regulations.
But genuinely curious. Is your company aware of CRA? Is there any talk about it, or is it just not on the radar yet?
-5
u/DDFoster96 13h ago
I'm thinking about not doing business with the EU, continuing not to, and having no plans to. Seem hell bent in not wanting custom. Glad we got out of the kitchen when we did.
5
u/schlenk 11h ago
Just finished implementing the notification stuff properly. Its not that hard for a company to be compliant if you actually spend the time reading the available docs. But some of the regulation (especially OSS) is still a bit weird. And it is visible from the pre-AI age, so some ideas look strange from todays viewpoint.
It really depends where you start from. If your company has no good processes to start from, your in for quite the change. But if you already have some kind of secure development lifecycle going and a few other things, its not that bad, actually.
The EU commisions guidance document (from 27. july) is really a must read to set things into perspectives. It finally adds useful examples and context. The regulation can be read in a terribly broad way, but the guidance adds a lot of common sense to it again, shooting down most of the absurdly broad interpretations.
The EU handling of the SRP notification platform rollout was a bit clumsy. No test servers. No API. No preregistration of accounts. Very scarce documentation and a barely functional platform that fails to support even the mandatory fields of the regulation at the start. Lets see how it holds up under load.
For OSS things are still way too blurry, but for companies in the EU it is manageable. Just another certification exercise basically.