Skip to content
SOVEREIGNTYBALANE
Back to the wiki
Law · 1 min read

Cyber Resilience Act

In shortSoftware becomes a product with safety duties. Including the software you run yourself.

The Cyber Resilience Act treats software and connected devices like any other product: whoever places them on the EU market is liable for their security properties. The main obligations apply from December 2027; the reporting duties for actively exploited vulnerabilities already from September 2026.

What it requires

Security has to be considered during development, not after it. Products must ship without known exploitable vulnerabilities. Security updates must be available across a defined support period — as a rule at least five years. And there must be a bill of materials for the components used, the SBOM.

Actively exploited vulnerabilities and severe incidents must be reported within 24 hours.

What this has to do with sovereignty

Two things.

First, the bill of materials. Producing one shows you, for the first time completely, whose code your product is made of — and from which countries. It is the same exercise as the supplier list under NIS2, one layer down. See NIS2.

Second, the support period. It makes enforceable a promise that used to be a matter of negotiation: how long will this product still receive updates? That is the question dependency actually hangs on — a system without updates is a system with an expiry date.

The unsettled part

Exemptions apply to open source software as long as it is not supplied in the course of a commercial activity; a lighter regime applies to "open source software stewards". Exactly where the line runs is being worked out in practice right now.

For you as a user the effect is the same: ask every vendor for its support period and its SBOM. From 2027 it has to be able to answer.

Sources

See also

Related terms