Description
Reticketed from #39. This is a BFD.
The Cyber Resilience Act (CRA) is a piece of European Union legislation that regulates software as a product. Toys and electronics and appliances and such must meet certain safety standards and carry the CE mark to be sold in Europe. The CRA is on its way to enter into force in 2027, at which point "products with digital elements" (i.e., software) will likewise need to meet certain safety (i.e., security) standards and carry the CE mark.
The Product Liability Directive (PLD) is a related document that is also getting an update to make it clear that software manufacturers are on the hook for bugs in their code, even far downstream.
This ticket includes a reading list and my first attempts to take on board some of the implications of this legislation.