HN 提问:还有其他人也在为欧盟网络韧性法案做准备吗?

2 分•作者: dirkk0•26 天前
我在德国经营一家一人有限责任公司(GmbH)。我正考虑销售一款现成手持设备的固件——该设备离线运行,完全不包含WiFi或网络堆栈,更新通过USB重新刷写。我只销售软件,不销售硬件。 事实证明,《欧盟网络韧性法案》(EU Cyber Resilience Act,简称CRA)适用于我。欧盟开始像对待硬件产品一样对待软件产品,而CRA对此进行了监管(从客户的角度来看,这是理所当然的!)。 报告义务将于今年九月开始;其他所有义务将于2027年12月生效。因此,我花了一些时间阅读了法规本身[1]和欧盟委员会2026年7月27日的指南[2](C(2026) 5252,约80页,包含67个具体案例,明确针对中小企业),而不是评论。 到目前为止,我了解到以下几点,并希望得到纠正: 1. 销售软件现在就像销售硬件一样。适用相同的制度——技术文件、符合性声明、软件上的CE标志。我曾以为CE标志是硬件专属的;但根据CRA,情况不再如此。 2. 我无法通过免费赠送软件来规避。豁免适用于在商业活动之外提供的开源软件——免费不等于非商业。我为支持我销售的产品而发布的固件,无论我收取多少费用,都明显属于商业范畴。 3. 没有规模门槛。一人公司承担的义务与大公司相同。第33条的标题是“为微型企业及中小型企业提供的支持措施”,其中的每一项规定都是帮助,而非豁免。 4. 但实际工作量很小。我的产品不属于附件III,因此属于自我评估:无需指定机构,无需付费,无需提交任何文件,也无需获得任何批准。这项工作似乎只需要我编写几份一次性的文件。基本上,你自己就可以贴上CE标志。 5. 但存在第13条第9款。你发布的每一次安全更新,必须在你发布后保留10年,或在支持期结束前,以较长者为准。对于2027年推出的产品,可能只售出一次,这意味着要持续到2040年代的相当长一段时间。 6. 报告义务不会随着支持的结束而终止。指南明确指出(第210段):漏洞处理在支持期结束后停止,但报告义务在此之后继续。 我先说到这里,但还有一些其他的影响。 哦,在你提问之前:你住在哪里并不重要,重要的是你是否向欧盟销售产品。 总而言之:我没有找到任何“独立开发者”来源处理这些问题,所以我的主要问题是——是否还有其他人正在为这种情况做准备?如果是,你们是如何处理的?特别想听听那些在小规模情况下真正经历过此事的人,或者来自市场监管机构的人的看法。 [1] https://eur-lex.europa.eu/eli/reg/2024/2847/oj [2] https://digital-strategy.ec.europa.eu/en/library/commission-publishes-new-guidance-support-timely-cyber-resilience-act-implementation
查看原文
I run a one-person GmbH in Germany. I am thinking about selling firmware for an off-the-shelf handheld - offline, no WiFi, no network stack compiled in at all, updates by reflashing over USB. I don&#x27;t sell hardware, just software.<p>Turns out that the EU Cyber Resilience Act applies to me. The EU starts to handle software products similar to hardware products and the CRA regulates that (and from a customer&#x27;s standpoint - rightfully so!).<p>Reporting duties start this September; everything else in December 2027. So I spent some time reading the sources rather than the commentary: the Regulation itself [1], and the Commission&#x27;s guidance of 27 July 2026 [2] (C(2026) 5252, around 80 pages with 67 worked examples, explicitly aimed at SMEs).<p>This is what I found out so far, and this is where I&#x27;d like to be corrected:<p>1. Selling software now works like selling hardware. Same regime - technical file, declaration of conformity, CE marking on a piece of software. I&#x27;d assumed CE was a hardware thing; with the CRA not anymore.<p>2. I can&#x27;t escape it by giving the software away. The exemption is for open source supplied outside commercial activity - free isn&#x27;t the same as non-commercial. Firmware I publish to support a product I sell is plainly commercial, whatever I charge for it.<p>3. There&#x27;s no size threshold. A one-person company carries the same obligations as a large one. Article 33 is titled &quot;Support measures for microenterprises and small and medium-sized enterprises&quot; and every provision in it is help, not exemption.<p>4. But the actual work is small. My product isn&#x27;t in Annex III, so it&#x27;s self-assessment: no notified body, no fee, nothing filed, nobody approves anything. The work seems to be a handful of documents I write once. You basically stick the CE label on by yourself.<p>5. But there is Art. 13(9). Every security update you ship has to stay available for 10 years after you issue it, or the rest of the support period, whichever is longer. That&#x27;s a serious amount of time into the 2040s for a product launched in 2027, maybe sold only once.<p>6. Reporting obligations don&#x27;t end when support does. The guidance is explicit (para 210): vulnerability handling stops with the support period, reporting continues afterwards.<p>I&#x27;ll stop here, but there&#x27;s a couple more implications.<p>Ah, and before you ask: it doesn&#x27;t matter where you live, it matters that you sell to the EU.<p>In a nutshell: I didn&#x27;t find any &#x27;indie&#x27; sources dealing with these matters, so my main question is - is anyone else preparing for this scenario? If so, how do you handle it? Especially interested in anyone who has actually been through this at a small scale, or anyone from a market surveillance authority.<p>[1] https:&#x2F;&#x2F;eur-lex.europa.eu&#x2F;eli&#x2F;reg&#x2F;2024&#x2F;2847&#x2F;oj<p>[2] https:&#x2F;&#x2F;digital-strategy.ec.europa.eu&#x2F;en&#x2F;library&#x2F;commission-publishes-new-guidance-support-timely-cyber-resilience-act-implementation