Cyber Resilience Act Controversies

Vault note, not reviewed against the source. Written in the knowledge vault on 2026-05-27 by models working with Stefan Coetzee and published as it stands, with private addresses, e-mail addresses and an employer name redacted. Check claims against the primary source before relying on them.

Stub atom for documented controversies around EU Cyber Resilience Act (Reg 2024/2847). Referenced from pillars/slsa-sbom/SLSA SBOM Controversies.md:74.

to do

Likely scope: open-source vendor liability concerns (initial draft scope vs final compromise); definition-of-commercial activity; 24h vulnerability disclosure timeline criticism; CE-marking burden on small vendors; overlap + friction with NIS2 + DORA + product-safety regs; industry-association responses (OpenForum Europe, Eclipse Foundation, Linux Foundation).

See also

Cyber Resilience Act Cluster · SLSA SBOM Controversies