{"version":"1.0","type":"rich","provider_name":"Acast","provider_url":"https://acast.com","height":250,"width":700,"html":"<iframe src=\"https://embed.acast.com/$/653769c09c713d0012562f78/6a9309fbb11fad0966635ea1?\" frameBorder=\"0\" width=\"700\" height=\"250\"></iframe>","title":"MOSE Shorts 41 - Cyber Resilience Act - You Need to Act NOW","thumbnail_width":200,"thumbnail_height":200,"thumbnail_url":"https://open-images.acast.com/shows/653769c09c713d0012562f78/1788021179756-2413bb96-0de5-4c29-980b-102fed526667.jpeg?height=200","description":"<p>Sometimes regulations that don't target open source still affect the wider ecosystem, and the Cyber Resilience Act (CRA) in Europe is one of these. And there some deadlines you need to be aware of.</p><p><br></p><p>In this segment of the My Open Source Experience podcast Christopher CRob Robinson talks about the legislation, incuding some deadlines and requirements.</p><p><br></p><p>Learn more about:</p><p>- CRA as one of the most impactful legislations in recent-ish history</p><p>- Sometimes you need legislations for essential tasks, which are not features, to get done</p><p>- Software lifecycle and cataloging the pieces of your digital products will become a requirement if you're selling a product or service on the EU market</p><p>- If you're outside the EU, but your app is used by people who are in Europe, then you're on the hook</p><p>- Unaware and Insecure LF Research Survey report on CRA awareness</p><p>- Reporting obligations start on September 11, 2026</p><p>- Roles and obligations under the CRA</p><p>- Open source maintainers get bullied under the name of the CRA</p><p>- If you're an open source maintainer, you have no obligations beyond fixing the vulnerability reports under the CRA</p><p><br></p><p>#opensource #community #collaboration #experience #podcast</p>","author_name":"Ildiko Vancsa"}