Open-source software vs. the proposed Cyber Resilience Act (NLnet Labs)
NLnet Labs has put up ablog entry warning about the possible effects of the "Cyber ResilienceAct" proposal in the European Commission.
We feel the current proposal misses a major opportunity. At a highlevel the 'essential cybersecurity requirements' are notunreasonable, but the compliance overhead can range from tough toimpossible for small, or cash-strapped developers. The CRA couldbring support to open-source developers maintaining the criticalfoundations of our digital society. But instead of introducingincentives for integrators or financial support via the CRA, thecurrent proposal will overload small developers with compliancework.