The European Cyber Resilience Act
The European Cyber Resilience Act
Posted Sep 20, 2023 21:56 UTC (Wed) by kleptog (subscriber, #1183)In reply to: The European Cyber Resilience Act by wtarreau
Parent article: The European Cyber Resilience Act
Hosted software has to comply with the NIS (and now the NIS2) Directive which has similar goals to the CRA but for services rather than products. The world did not end when that was introduced.
Notifications only apply to security issues found in deployed products, so not every bug needs notification. This actually ties into the discussion that was here recently about when CVEs should be allocated. This Act cannot solve this problem (nor does it try). If you want to reduce the impact of this Act, then it would be a good idea to stop assigning CVEs for issues that aren't important.