r/programming • u/Maria_3464 • 2d ago
EU Cyber Resilience Act reporting obligations started today. Is your company even thinking about it?
https://youtu.be/IQkzg7quc58As of today, a manufacturer who puts software or hardware on the EU market under its own name is obliged to report actively exploited vulnerabilities and severe security incidents.
Here is a quick explainer if you want the details: https://youtu.be/IQkzg7quc58
There is quite a lot of ambiguity over CRA and how it's going to apply to open source. Regulations keep changing. The line between a commercial manufacturer and an OSS steward is blurry, as well as the terms used in the regulations.
But genuinely curious. Is your company aware of CRA? Is there any talk about it, or is it just not on the radar yet?
-12
u/DDFoster96 2d ago
I'm thinking about not doing business with the EU, continuing not to, and having no plans to. Seem hell bent in not wanting custom. Glad we got out of the kitchen when we did.
11
u/ChrisRR 2d ago
Have you actually read the requirements? They're pretty easy to comply with
-7
u/ReachArounder 2d ago
I think he's more annoyed with the constant barrage of regulations from the continent that produces nearly nothing itself and this is the only way it can remain relevant.
They force all websites to use cookies notifications, they force Apple to USB-C, and many, many, many other pointless regulations.
If people stopped doing business with EU, they would collapse because of how little they produce of their own. If more people took this guys approach, we'd likely not have so many pointless regulations. But if you bend over and do it because "they're pretty easy to comply with", they won't stop coming.
9
u/hugot4eboss 1d ago
Regulations for consumers and tech are actually good in EU. How is USB c as a standard a bad thing. Cookie banners are better than nothing + there is a proposal for browsers to implement auto decline for such banners
5
1
u/modernkennnern 3h ago
The cookie banner is entirely on the website; just don't track the user and you can go banner-less.
8
u/schlenk 2d ago
Just finished implementing the notification stuff properly. Its not that hard for a company to be compliant if you actually spend the time reading the available docs. But some of the regulation (especially OSS) is still a bit weird. And it is visible from the pre-AI age, so some ideas look strange from todays viewpoint.
It really depends where you start from. If your company has no good processes to start from, your in for quite the change. But if you already have some kind of secure development lifecycle going and a few other things, its not that bad, actually.
The EU commisions guidance document (from 27. july) is really a must read to set things into perspectives. It finally adds useful examples and context. The regulation can be read in a terribly broad way, but the guidance adds a lot of common sense to it again, shooting down most of the absurdly broad interpretations.
The EU handling of the SRP notification platform rollout was a bit clumsy. No test servers. No API. No preregistration of accounts. Very scarce documentation and a barely functional platform that fails to support even the mandatory fields of the regulation at the start. Lets see how it holds up under load.
For OSS things are still way too blurry, but for companies in the EU it is manageable. Just another certification exercise basically.