-
Notifications
You must be signed in to change notification settings - Fork 2
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Topic: EU Cyber Resilience Act #14
Comments
|
If we're focusing on Open source we need to take a wider scope and discuss what's happening in the US and why the OpenSSF exists and what they do... |
Yes, I think we should see and talk about this from an Open source angle, even with a focus at Open Source hackers/contributors. Staying true to who we are. |
Some suggestions if/when you want to dive in a bit deeper:
Happy to discuss the topic, if that is of any utility; I have been following the topic for a while now. |
FYI: the plan is to record an episode on this topic today. |
While intentions are good behind EUCRA, I get strong ISO9000 vibes here. However good the regulation will become, the business opportunity for certification companies arise. This could make it spread like cancer through the industry. Any, however small, software consulting could require anyone to be EUCRA certified. And how often does one need to be re-certified? Every year? While software developers outside the EU will not be bothered with this. Do we all move to Northern Ireland or Norway then? What would prevent this? An exemption for "small" businesses? |
The law specifies that standard bodies will have to define what exactly will the criteria be to be certified. As such
On certification:
Important to note: this does affect developers outside of the EU because it will use trade rules, just like the GDPR. So the only realistic way to dodge it if you are "outside" the EU is to never let an EU resident use your software but also never let a product sold in the EU use your code. Which is opposite to FOSS basic rules and "freedom". |
You might want to talk to @berthubert as well. He wrote a good article about it and is in discussions with lawmakers/civil servants. |
I really like the discussion here, so keep it going. The recording of the podcast is today, but that doesn't mean we can't discuss :-) |
The creation of new standards is not a route that will save open source projects from concern. First, far too long a timeline. Second, there's a critical lack of representation in ETSI and CEN/CENELEC. |
Since this topic has now been discussed in a recorded episode, I'm closing. |
... and possible effects on Open Source users and makers in the EU.
Maybe we can invite @oej to tell us about it?
Link: https://digital-strategy.ec.europa.eu/en/library/cyber-resilience-act
The text was updated successfully, but these errors were encountered: