What the CRA Actually Gives Software Users

https://hackernoon.imgix.net/images/O2fUY2CJvlNKbCnxvP09hPZYkj92-4n822x7.png

For software users, that means security as part of what they buy, a manufacturer who remains responsible, notice when exploitation requires action, a support life that matches expected use, a visible end date, no second bill for the mandated fix, and released patches that stay available to fetch.

The Cyber Resilience Act (CRA) is usually explained from the manufacturer’s side: requirements to meet, processes to run, vulnerabilities to report, conformity to demonstrate.

We spend so much time on CRA compliance that it is easy to miss the obvious point. Those obligations exist to protect the people who buy and run products with digital elements. The manufacturer duties are the mechanism. The user protections are the reason.

That is also why the CRA is worth explaining in plain language from that side.

There is a practical reason too. If you only see the CRA as a list of duties, you will...

Copyright of this story solely belongs to hackernoon.com. To see the full text click HERE

Read more