EOLE 2024 synthesis: Cyber Resilience Act & Open Source

Summary of the Cyber Resilience Act (CRA) session at EOLE 2024, part of Navigating the New EU Regulatory Landscape in Open Source.

Context. The EU’s cybersecurity approach evolved from the NIS Directive (2016) and the Cybersecurity Act (2019) to NIS 2 (2022), culminating in the CRA, which sets cybersecurity requirements for products with digital elements across their whole lifecycle. Published on 20 November 2024, it gives economic actors until 11 December 2027 to comply.

Scope. Products with digital elements made available on the market in the course of a commercial activity. Excluded: non-commercial distribution, funding by donations or grants, no associated paid services, and research.

Five roles, each with distinct obligations: manufacturer, Open Source steward, authorised representative, importer, and distributor.

Compliance tools. Technical documentation, cybersecurity risk assessments, EU declarations of conformity and SBOMs that are standardised, qualitative and exhaustive (the CRA focuses on first-level dependencies, while best practice goes deeper). Voluntary security attestation programs are encouraged.

Oversight & sanctions. Market surveillance authorities, ENISA, ADCO and CSIRTs; fines up to €15M or 2.5% of annual turnover.

Public administrations. Article 5(2) requires CRA compliance to be considered in procurement, a competency-gap challenge for public buyers.

Open questions. Characterising “commercial use”, vulnerability management, licence validation, and project sustainability (upstreaming fixes rather than keeping them private).

Resources

Session slides: CRA and Open Source – EOLE

CNLL & inno³ guide to the CRA (FR & EN): commons-studies/guide-cra: Guide CRA — migré depuis code.inno3.eu/ouvert/guide-cra - Forgejo: Beyond coding. We Forge.

Full EOLE 2024 synthesis: EOLE 2024 – Navigating the New EU Regulatory Landscape in Open Source – EOLE

What’s your experience preparing for the CRA? Share questions and resources below.