13 ms·
What are the penalties? Will they crack down on the buggy WiFi routers which often times have open source software that they never maintain? Also I see this as
by pkaye 1y ago
What are the penalties? Will they crack down on the buggy WiFi routers which often times have open source software that they never maintain?
Also I see this as a benefit for the major commercial Linux Distribution like Red Hat, Ubuntu and maybe SuSe because small companies can't provide that level of assurance.
- pabs3 1y agoFound a FAQ about it: "Failure to comply with vulnerability reporting, cyber incident reporting, or essential cybersecurity requirements could trigger administrative fines of up to €15 million or 2.5% of global turnover. Other obligations include €10 million or 2% of global turnover." https://www.windriver.com/resource/eu-cyber-resilience-act-faq https://www.windriver.com/resource/eu-cyber-resilience-act-f... Also more details in this one: https://codific.com/cra-fines/ https://codific.com/cra-fines/ Apart from fines, "Beyond financial penalties, non-compliant products may also be prohibited or restricted from being made available on the EU market, or authorities may order their withdrawal or recall. This can lead to significant reputational damage and loss of market access."
- pabs3 1y agoSMEs and start-ups have reduced requirements under the CRA too. https://openssf.org/blog/2025/02/20/does-the-eu-cra-affect-my-business/ https://openssf.org/blog/2025/02/20/does-the-eu-cra-affect-m... https://www.cra-guide.com/2025/06/09/cras-impact-on-small-and-medium-sized-enterprises-smes/ https://www.cra-guide.com/2025/06/09/cras-impact-on-small-an...