[1] https://berthub.eu/articles/posts/eu-cra-what-does-it-mean-f...
[1] https://berthub.eu/articles/posts/eu-cra-what-does-it-mean-f...
It only covers pure hobby projects by pure hobby developers.
> (10c) the mere fact that an open-source software product receives financial support by manufacturers or that manufacturers contribute to the development of such a product should not in itself determine that the activity is of commercial nature.
> (10) Accepting donations without the intention of making a profit should not be considered to be a commercial activity.
> (10c).. for the purpose of this Regulation, the development of products qualifying as free and open-source software by not-for-profit organisations should not be considered a commercial activity as long as the organisation is set up in a way that ensures that all earnings after cost are used to achieve not-for-profit objectives.
See https://berthub.eu/articles/posts/eu-cra-what-does-it-mean-f...
The notion of "accepting donations without the intention of making a profit" seems insane, too.
So an organisation can pay developers to work on it, cover hosting costs etc. but they have to be careful not to accept donations for more than that. A non-profit can accept more provided it is used for the right objects.
I have no idea (neither does the author of the article) where that leaves an individual developer who accepts donations to cover the value of their time.
That is still a problem: https://berthub.eu/articles/posts/eu-cra-what-does-it-mean-f...
> the mere fact that an open-source software product receives financial support by manufacturers or that manufacturers contribute to the development of such a product should not in itself determine that the activity is of commercial nature.
That just means that a business can donate to a non-profit project. Such a business would still need to not profit from the project in anyway. Why would a business help develop something it does not profit from?
> for the purpose of this Regulation, the development of products qualifying as free and open-source software by not-for-profit organisations should not be considered a commercial activity as long as the organisation is set up in a way that ensures that all earnings after cost are used to achieve not-for-profit objectives
So again, an organisation can, provided it no profit.
These are very narrow exemptions.
https://berthub.eu/articles/posts/eu-cra-what-does-it-mean-f...
They will most likely bring that clause back in a few years after the current bill is passed. Once they realise that their current law is essentially subsidizing security of the whole world, by making only EU businesses pay for it.
Laws like this should only be applied to billion dollar companies not small businesses or startups. It just hurts EU innovators while benefiting everyone else.
Laws don’t matter, they almost always sound sweet in decent governments like EU. What effects those laws cause in the real world when accounting for all players in the market matter a lot more.
And this law will yet again benefit non-EU startups while hurting EU startups.
No, the legislators hadn't considered open source software at the early stages. Once that gap was realised, there were negotiations and exceptions were carved out.
> It just hurts EU innovators while benefiting everyone else
Believe it or not, but the EU's higher priority is EU people and consumers, not startups. It will be possible to run a startup under CRA, just as it is now possible under GDPR.
The requirements are described in Annex IV, V and VI. You must do a conformity assessment and provide a declaration of conformity. For non-critical software you can do the assessment yourself see the first five points in Annex VI. The only thing that maybe requires a bit of effort is that you must write some technical documentation including a cybersecurity risk assessment. For critical software the process is more involved because it requires certification by a "notified body".
If a startup in the EU fails because they have to write a bit of documentation once in a while they deserve to fail. Also if a startup wants to create security relevant software I expect that they follow some security standard and the CRA makes sure of that. None of these requirements are something only a billion dollar company can do.
[1] https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...