CRA Controversies

Vault note, not reviewed against the source. Written in the knowledge vault on 2026-05-12 by models working with Stefan Coetzee and published as it stands, with private addresses, e-mail addresses and an employer name redacted. Check claims against the primary source before relying on them.

Open source uncertainty

Despite carve-out, open source ecosystem concerned:

  • Boundary between "non-commercial" and "commercial" supply unclear.
  • Open source steward obligations expanding.
  • Contributor liability concerns.
  • Maintainer burnout risk if compliance burden shifts.

SaaS exclusion

Cloud services excluded:

  • Major application class outside CRA scope.
  • SaaS cybersecurity falls to NIS2 (operator) but not product-level.
  • Inconsistency raises questions.

Conformity assessment capacity

Notified Bodies for important/critical products limited:

  • Capacity bottleneck for designation.
  • Cost pressure on conformity assessment.
  • Small-vendor disadvantage.

Definitional ambiguity

"Product with digital elements" interpretation challenges:

  • Software-as-a-product vs software-as-component.
  • Modular products with mixed scope.
  • Update mechanisms vs new product placement on market.

Support period commitment risk

Manufacturers must commit to support period:

  • Long-tail support commitments costly.
  • Pricing pressure.
  • Smaller vendors disadvantaged vs larger with cross-product support amortization.

Counterpoint

  • Genuine product-cybersecurity gap addressed.
  • Vulnerability disclosure mandate overdue.
  • Brussels effect potential for global product security uplift.
  • Risk-tiered approach focuses heavy obligations on important/critical.

See also