There will be a post in 9 months from software companies crying about the PLD and CRA because their leaders were asleep at the wheel for the last half decade.
There will be a post in 9 months from software companies crying about the PLD and CRA because their leaders were asleep at the wheel for the last half decade.
Are they shipping within EU? Then they literally are in the field of shipping within the EU.
For example, a CRA self assessment including CE will require around $20k in liquid capital that you need out of pocket even if all you want to do is sell a single piece of jewelry with some electronics embedded into it. Not to mention the indirect costs such as guaranteeing 5 years of security updates.
There is also the issue that PLD for cloud services effectively means that you cannot easily update your software anymore while it is under investigation by a claimant because that could constitute destruction of evidence. This leads to a catch 22 with the CRA, where you are legally obligated to patch a security vulnerability within 72 hours.
The conflict here is that for physical products, the owner receives a unique reproduction of the design plans, whereas with cloud software, the customer is using shared infrastructure that can affect other customers if it is under investigation. So the entire cluster running the software turns into the equivalent of a smartphone. If you want to sell an updated product, you need to sell a new smartphone aka run a new cluster.
Well, how small business can report anything during 24 hours through weekends, long weekends, 1-week Christmas, 3-4-weeks summer vacations?
https://www.enisa.europa.eu/topics/product-security/single-r...
> Reporting process starts at the moment manufacturer becomes aware of active exploitation of vulnerability or incident.
If your business is closed (due to vacation or sickness for example) you don't become aware until you are back.
I think it only hurts super small one man part time developers but even then: If I pay for a piece of software I expect it to be secure and have a bit of support.