Open source uncertainty
Despite carve-out, open source ecosystem concerned:
- Boundary between "non-commercial" and "commercial" supply unclear.
- Open source steward obligations expanding.
- Contributor liability concerns.
- Maintainer burnout risk if compliance burden shifts.
SaaS exclusion
Cloud services excluded:
- Major application class outside CRA scope.
- SaaS cybersecurity falls to NIS2 (operator) but not product-level.
- Inconsistency raises questions.
Conformity assessment capacity
Notified Bodies for important/critical products limited:
- Capacity bottleneck for designation.
- Cost pressure on conformity assessment.
- Small-vendor disadvantage.
Definitional ambiguity
"Product with digital elements" interpretation challenges:
- Software-as-a-product vs software-as-component.
- Modular products with mixed scope.
- Update mechanisms vs new product placement on market.
Support period commitment risk
Manufacturers must commit to support period:
- Long-tail support commitments costly.
- Pricing pressure.
- Smaller vendors disadvantaged vs larger with cross-product support amortization.
Counterpoint
- Genuine product-cybersecurity gap addressed.
- Vulnerability disclosure mandate overdue.
- Brussels effect potential for global product security uplift.
- Risk-tiered approach focuses heavy obligations on important/critical.