Files
fsfe-website/fsfe.org/news/2026/news-20260224-01.en.xhtml
tobiasd 560a611b65
continuous-integration/drone/push Build is passing
merge Feat/structure po4a compliant
2026-06-11 14:53:55 +02:00

97 lines
4.4 KiB
HTML
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
<?xml version="1.0" encoding="utf-8"?>
<html newsdate="2026-02-24">
<version>3</version>
<head>
<title>Addressing your questions about the Cyber Resilience Act</title>
</head>
<body>
<h1>Addressing your questions about the Cyber Resilience Act</h1>
<p>During FOSDEM 2026, the FSFE held a Q&amp;A session on the Cyber Resilience Act together with a representative of the German market surveillance authority and the European Commission as there are still uncertainties and recurring questions.</p>
<figure>
<img src="https://pics.fsfe.org/uploads/medium/1a/80/ed069f969182b846404a18dc6181.jpeg" alt=" Two presenters stand at the front of a room during FOSDEM 2026 giving a talk titled &quot;CRA Role of Free Software Q&amp;A&quot; to an audience seated at desks with laptops and notes. "/>
</figure>
<p>One question, that we also explored in a survey, is the role of the
steward. People are still unsure whether and under what circumstances
they should or want to become a steward. One part of the question is
relatively easy to answer: no one has to become a steward. The Cyber
Resilience Act (CRA) is a product regulation that aims to place
obligations on manufacturers. As long as you are not a manufacturer and
your software is not incorporated into a product, the CRA does not
apply to you. It becomes more complex if you develop Free Software that
is used in products. In this case, the manufacturer must ensure that
they can fulfil the obligations under the CRA. If the manufacturer
decides to use your project, you may consider whether you would like to
become a steward. If you do not want to become a steward, the
manufacturer should look for alternatives or, for example, fork your
project so that they can fulfil the obligations under the CRA. However,
they cannot force you to become a steward.</p>
<p>This gives you the opportunity to work with the manufacturer and be
compensated for working on your Free Software.</p>
<p>Besides the option of becoming a steward, there is also the option
of attestation (Art. 25 CRA). In order to facilitate the due diligence
obligation, voluntary security attestation programmes could be
established. This could also be an interesting option for you to help
ensure the maintenance of your software is sustained in the long run.
There is still uncertainty about attestation, which is to be clarified
by a delegated act of the European Commission. For this purpose, <a href="https://dialog-cybersicherheit.limesurvey.net/113884">we
have launched another survey</a>, and you are welcome to participate <strong>by 28
February 2026, midnight AoE</strong>. to contribute your ideas and
suggestions.</p>
<p>We will evaluate the results and make them available to
decision-makers and relevant stakeholders, incorporating them into the
process. Here, too, we will focus our efforts on ensuring that Free
Software contributors and small projects are protected and
supported.</p>
<div>
<p>Resources:</p>
<ul>
<li><a href="https://dialog-cybersicherheit.limesurvey.net/113884">CRA survey</a>
</li>
<li><a href="https://fosdem.org/2026/schedule/event/QEZ3LB-cra_-_role_of_free_software_and_q_a/">CRA
Role of Free Software and Q&amp;A @ FOSDEM </a>
</li>
<li><a href="https://fosdem.org/2026/schedule/track/cra-in-practice/">CRA in practice dev room @ FOSDEM</a>
</li>
<li><a href="https://fosdem.org/2026/schedule/event/PTHENV-sustaining-foss-with-attestations/">Could
Compliance Costs Sustain FOSS? A Theory of Voluntary
Attestations @FOSDEM</a>
</li>
<li><a href="https://fosdem.org/2026/schedule/event/EERURR-implementing_the_cyber_resilience_act_-_engaging_with_open_source/">Implementing
the Cyber Resilience Act - engaging with open source @FOSDEM</a>
</li>
</ul>
</div>
</body>
<tags>
<tag key="community">Community</tag>
<tag key="ada-zangemann">Ada and Zangemann</tag>
<tag key="no">Norway</tag>
<tag key="education">Education</tag>
<tag key="software-freedom">Software Freedom</tag>
<tag key="front-page"/>
<tag key="highlights">highlights</tag>
</tags>
<discussion href="https://mastodon.social/deck/@fsfe/116125821329361398"/>
<image url="https://pics.fsfe.org/uploads/medium/1a/80/ed069f969182b846404a18dc6181.jpeg" alt=" Two presenters stand at the front of a room during FOSDEM 2026 giving a talk titled &quot;CRA Role of Free Software Q&amp;A&quot; to an audience seated at desks with laptops and notes. "/>
<translator/>
</html>