this post was submitted on 04 Sep 2026
20 points (100.0% liked)

Europe

11930 readers
1314 users here now

News and information from Europe ๐Ÿ‡ช๐Ÿ‡บ

(Current banner: La Mancha, Spain. Feel free to post submissions for banner images.)

Rules

  1. This is an English-language community. Comments should be in English. Posts can link to non-English news sources when providing a full-text translation in the post description. Automated translations are fine, as long as they don't overly distort the content.
  2. No links to misinformation or commercial advertising. When you post outdated/historic articles, add the year of publication to the post title. Infographics must include a source and a year of creation; if possible, also provide a link to the source.
  3. Be kind to each other, and argue in good faith. Don't post direct insults nor disrespectful and condescending comments. Don't troll nor incite hatred. Don't look for novel argumentation strategies at Wikipedia's List of fallacies.
  4. No bigotry, sexism, racism, antisemitism, islamophobia, dehumanization of minorities, or glorification of National Socialism. We follow German law; don't question the statehood of Israel.
  5. Be the signal, not the noise: Strive to post insightful comments. Add "/s" when you're being sarcastic (and don't use it to break rule no. 3).
  6. If you link to paywalled information, please provide also a link to a freely available archived version. Alternatively, try to find a different source.
  7. Light-hearted content, memes, and posts about your European everyday belong in other communities.
  8. Don't evade bans. If we notice ban evasion, that will result in a permanent ban for all the accounts we can associate with you.
  9. No posts linking to speculative reporting about ongoing events with unclear backgrounds. Please wait at least 12 hours. (E.g., do not post breathless reporting on an ongoing terror attack.)
  10. Always provide context with posts: Don't post uncontextualized images or videos, and don't start discussions without giving some context first.

(This list may get expanded as necessary.)

Posts that link to the following sources will be removed

Unless they're the only sources, please also avoid The Sun, Daily Mail, any "thinktank" type organization, and non-Lemmy social media (incl. Substack). Don't link to Twitter directly, instead use xcancel.com. For Reddit, use old:reddit:com

(Lists may get expanded as necessary.)

Ban lengths, etc.

We will use some leeway to decide whether to remove a comment.

If need be, there are also bans: 3 days for lighter offenses, 7 or 14 days for bigger offenses, and permanent bans for people who don't show any willingness to participate productively. If we think the ban reason is obvious, we may not specifically write to you.

If you want to protest a removal or ban, feel free to write privately to the admin that applied the rule (check modlog first to find who was it.)

founded 2 years ago
MODERATORS
top 2 comments
sorted by: hot top controversial new old
[โ€“] Damage@feddit.it 1 points 12 minutes ago

Paywall, here are the contents

Cyber Resilience Act: EU Commission provides more clarity for open source

Source: heise online
Author: vbr


Before the first reporting obligations of the Cyber Resilience Act (CRA) take effect, the EU Commission is providing manufacturers, developers, and companies with a guide. The guide, published on Monday, explains in about 80 pages how the cybersecurity regulation is to be interpreted. This ranges from defining affected products and essential software updates to rules for open source. The CRA itself has been in force since December 2024 and stipulates uniform minimum requirements for the cybersecurity of digital products across the EU throughout their entire lifecycle.

According to the Commission, the handbook answers key questions from the industry. It is intended to help those affected to implement the requirements legally. The guide explains, for example, which products fall under the CRA, how crucial program revisions are to be classified, and by what standards support periods are to be determined.

In addition, it provides information on how risk analyses and reporting obligations can be practically fulfilled. The EU Commission places particular emphasis on startups and small and medium-sized enterprises. Numerous practical examples and application scenarios are intended to clarify ambiguities and avoid unnecessary administrative effort.

Open source should not be slowed down

The Commission devotes considerable space to free and open-source software. During the negotiations on the CRA, developers and open-source foundations warned that voluntary projects could be discouraged by new liability and documentation requirements.

The Commission is trying to allay these fears. Freely available open-source software generally does not fall under the CRA as long as it is not brought to market as part of a commercial activity. It now explains when such an activity exists. Anyone who sells open-source software, offers paid enterprise versions, or monetizes other services through a program is considered a manufacturer in the sense of the CRA.

The situation is similar if users are required to provide personal data for purposes other than security or interoperability, or if donations are effectively a prerequisite for accessing the software or essential updates. Conversely, voluntary contributions, public funding, or sponsorship funds alone do not constitute commercial activity. Paid consulting, training, or support services also do not automatically mean that an open-source project falls under the CRA โ€“ as long as the software itself remains freely available.

What exactly are open-source stewards?

Further clarification will likely be important for many developers. The Commission explicitly distinguishes between project managers and suppliers. Those who merely fix bugs or submit new features generally bear no responsibility under the CRA. The situation is different for individuals or organizations that publish a project and exercise control over releases, roadmaps, and steering. Merely having write access to the source code repository is not sufficient for this.

The role of "stewards" also becomes clearer. This can include foundations or other organizations that provide permanent organizational or technical support for open-source projects without marketing them themselves. Their obligations depend on the intensity of their involvement: Those who only handle community work have significantly fewer obligations than organizations that operate infrastructure or actively participate in development and security management. Depending on the type of support, reporting obligations for security incidents or exploited vulnerabilities may also apply to stewards.

Furthermore, the Commission explains when a change to a product is considered "essential". Updates that exclusively fix vulnerabilities or maintain or improve the existing security level generally do not trigger a new conformity assessment procedure. The situation may be different if new features alter a product's risk profile or create additional attack surfaces. The guide also provides clarity on repairs: If only identical replacement parts are supplied, this is not considered a re-release of the product.

The clock is ticking

The guide also specifies requirements, for example for risk analyses and future reporting obligations. Although the guide is not legally binding, it is likely to be decisive for manufacturers and national market surveillance authorities on how the regulation will be interpreted in practice. The German government has designated the Federal Office for Information Security (BSI) for this purpose.

EU Commission Vice-President Henna Virkkunen described the handbook as part of Brussels' relief agenda. It is intended to help companies implement their new obligations on time and legally. A secure Europe and a business-friendly Europe go hand in hand. In the Commission's view, the CRA is gaining importance due to the advances in powerful AI models with cyber capabilities. The first reporting obligations will take effect on September 11, 2026. Manufacturers must fully comply with the regulation from December 11, 2027.


This article was originally published in German. It was translated with technical assistance and editorially reviewed before publication.

[โ€“] blackbeans@lemmy.zip 1 points 4 hours ago* (last edited 4 hours ago)

Very surprising how little people talk about CRA when it basically covers every digital product we use in our daily lives and the software that goes with it.