When a FOSS Patch Becomes a Legal Obligation: CRA Vulnerability Handling and the New Responsibility of Integrators

17.04.2026

Dr. Andreas Kotulla

Cyber Resilience Act

The Cyber Resilience Act (CRA) introduces a subtle but profound shift in how manufacturers must think about open source software. For years, integrating free and open-source software (FOSS) into products largely meant relying on upstream maintainers for fixes, monitoring vulnerabilities, and updating when patches became available. Under the CRA, that passive model no longer holds. In certain situations, a vulnerability

Read more

CRA and Security Incidents Outside EU

11.03.2026

Dr. Andreas Kotulla

Cyber Resilience Act

When a Security Incident Happens Outside the EU: Does the CRA Still Apply? The global nature of cybersecurity raises a practical question for manufacturers. If an actor exploits a vulnerability outside the European Union, do the Cyber Resilience Act (CRA) reporting and remediation obligations still apply? The short answer is yes. If a manufacturer places a product on the EU

Read more

SaaS Is Not a blanket exemption: Remote Data Processing, SBOMs, and the CRA

11.03.2026

Dr. Andreas Kotulla

Cyber Resilience Act

Software companies often rely on a familiar distinction: they regulate products, but not services. They have viewed cloud delivery models, subscription-based offerings, and remote processing as business innovations. They have also seen them as ways to reduce regulatory exposure. The EU Cyber Resilience Act (CRA) challenges this assumption. Under the CRA, the key question is not whether a company markets

Read more

Cyber Resilience Act and Legacy Products

10.03.2026

Dr. Andreas Kotulla

Cyber Resilience Act

One of the frequently asked questions surrounding the Cyber Resilience Act (CRA) concerns legacy products. Manufacturers ask whether they can sell older products in the EU after 11 December 2027 without updates. This blog explores the issue amid evolving CRA standards and upcoming compliance deadlines. CRA Scope and Market Placement The CRA applies to products placed on the market from

Read more

Understanding the Cyber Resilience Act and Its Impact on the Automotive Industry

28.03.2025

Dr. Andreas Kotulla

Cyber Resilience Act

As cars become more like computers on wheels, cybersecurity is becoming a major concern. With vehicles now connected to the internet and relying heavily on software, protecting them from cyber threats is essential. The Cyber Resilience Act (CRA) is a new European law designed to improve cybersecurity for digital products. While it does not directly apply to cars themselves (since

Read more

Understanding the Cyber Resilience Act and Its Impact on the Automotive Industry

28.03.2025

Dr. Andreas Kotulla

Cyber Resilience Act

As cars become more like computers on wheels, cybersecurity is becoming a major concern. With vehicles now connected to the internet and relying heavily on software, protecting them from cyber threats is essential. The Cyber Resilience Act (CRA) is a new European law designed to improve cybersecurity for digital products. While it does not directly apply to cars themselves (since

Read more