The EU Cyber-Resilience Act would mandate expensive 3rd-party audits for some categories of software (including open-source) before they can be sold commercially, https://news.ycombinator.com/item?id=33594440
> the big players who can afford certification will be able to use ANY open-source component for free but the people who built it will have a tough time to go to the market because they will require the funds they don't necessarily have.
The list of "critical" software categories can be updated by the EU based on perceived cybersecurity risk. It currently includes:
Operating systems (server/client/mobile)
Hypervisors and container runtimes
Public key infrastructure
Firewalls for industrial use
Routers for industrial use