# EU CRA and the Open Source Ecosystem: A Suggestion

DevFeed: [EU CRA and the Open Source Ecosystem: A Suggestion](<https://devfeed.tech/articles/eu-cra-and-the-open-source-ecosystem-a-suggestion-36388.md>)

Original publisher: [Read original article](<https://berthub.eu/articles/posts/eu-cra-best-open-source-security/>)

Published: 2023-11-12T13:22:46Z

Content type: opinion

Language: en

Sources: [Bert Hubert's writings](<https://devfeed.tech/sources/bert-hubert-s-writings.md>)

Topics: [cyber resilience act](<https://devfeed.tech/topics/cyber-resilience-act.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [cyber-resilience-act](<https://devfeed.tech/tags/cyber-resilience-act.md>), [eu](<https://devfeed.tech/tags/eu.md>), [europe](<https://devfeed.tech/tags/europe.md>), [legal](<https://devfeed.tech/tags/legal.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [security](<https://devfeed.tech/tags/security.md>)

## AI overview

This commentary examines how the EU Cyber Resilience Act could affect open source projects and the broader open source ecosystem. It argues that commercial manufacturers relying on open source components should invest in their security, while regulation should avoid imposing compliance departments on individual open source developers. An update says a later agreed version of the Act appears to have addressed the concerns, making much of the original discussion historical.

## Source excerpt

UPDATE: On December 1st the EU agreed on a version of the Cyber Resilience Act that appears to have substantially addressed the concerns in the post below. Further analysis awaits, but do know that the text that follows is now mostly of historical interest! UPDATE 2: Here is the final compromise text of the Cyber Resilience Act. UPDATE 3: Here is an analysis of what it means for open source.