
EU Enacts Comprehensive Cyber Security Rules to Safeguard IoT Devices and Open Source Developers
The European Union's Parliament and Council have reached an agreement on the Cyber Resilience Act (CRA), which imposes mandatory cybersecurity requirements for hardware and software products. The CRA includes a 24-hour disclosure period for security flaws, five years of security patch support, and thorough documentation of security features. Manufacturers, importers, and distributors have 36 months to comply or face fines. Concerns have been raised about the impact on open source software, but the latest version of the CRA exempts free and open source software developed outside of commercial activity.
