Cyber Resilience Act position

Vault note, not reviewed against the source. Written in the knowledge vault on 2026-05-12 by models working with Stefan Coetzee and published as it stands, with private addresses, e-mail addresses and an employer name redacted. Check claims against the primary source before relying on them.

What it does well

  • Product-level cybersecurity previously gap.
  • Vulnerability disclosure mandate addresses real industry weakness.
  • Support period requires manufacturers commit to security maintenance.
  • CE marking integration uses existing market-surveillance infrastructure.
  • Open-source carve-out (post-trilogue) limits OSS burden.

What it does poorly

  • Open-source complexity. Even with carve-outs, integration with OSS ecosystem unclear.
  • Conformity assessment capacity. Notified Bodies for critical products limited.
  • SaaS exclusion leaves cloud services gap.
  • Definitional ambiguity for "product with digital elements" in some edge cases.
  • Implementation guidance lag. Commission technical specifications still in development.

Evidence

  • Applicable mid-2026 onwards (vulnerability reporting); main obligations late 2027.
  • Industry working through implementation through 2025-2027.
  • ENISA preparing technical guidance.

Personal calibration

  • For software products placed on EU market: CRA applies.
  • For SRE / consultancy services: not directly in scope (services not products).
  • For AI-feature products: AI Act + CRA + GDPR potentially all apply.

See also