New CRA Act target open-source

According to open-source leaders, the European Union’s planned Cyber Resilience Act (CRA), which aims to “bolster cybersecurity rules to ensure more secure hardware and software products,” could have serious consequences for open-source software.

The proposed Act is said to introduce CE marking for software products with four specific goals. Which manufacturers must improve digitally enhanced product security “across the entire life cycle?” The second goal is to create a “coherent cybersecurity framework” for determining compliance. The third goal is to improve product transparency when it comes to digital security, and the fourth goal is to allow customers to “securely use products containing digital elements.”

The issue raised by open-source leaders appears to be concerning free software developers who are unable to afford the new direct compliance costs for new cybersecurity requirements, conformity assessment, documentation, and reporting obligations. The additional costs are estimated to be EUR 29 billion ($31.54 billion). This would also result in higher consumer prices.

The CRA also intends to prohibit the sale of unfinished software for purposes other than testing. This has serious consequences for open-source software. The absence of unfinished software on the market can harm open-source software by reducing the number of potential contributors and users.

Others cannot use, modify, or improve on software that is not available. This can result in a lack of interest and engagement in the open-source community, slowing or even halting development. Furthermore, without access to the software, users may be unaware of its potential benefits, further limiting interest and engagement. Overall, the lack of completed software can limit the growth and impact of the open-source software community.

The sources for this piece include an article in Devclass.

Top Stories

Related Articles

May 31, 2025 A coordinated supply chain attack has compromised between 500 and 1,000 e-commerce websites by exploiting vulnerabilities in 21 more...

May 31, 2025 A widely used open-source Go library, easyjson, used in healthcare, finance and even defence has come under scrutiny more...

May 31, 2025 (EDITORIAL) A messaging tool used by Trump administration officials to archive encrypted Signal messages has been hacked — more...

April 22, 2025 Anthropic, a leading artificial intelligence company, anticipates that AI-powered virtual employees could begin operating within corporate networks as more...

Jim Love

Jim Is and author and pud cast host with over 40 years in technology.