问HN:还有其他人在为欧盟网络韧性法案做准备吗?
我在德国经营一家一人有限责任公司(GmbH)。我正在考虑为一款现成的手持设备出售固件——该设备离线使用,没有WiFi,也没有任何网络堆栈,更新通过USB重新闪存。我只销售软件,不销售硬件。
结果发现,欧盟网络韧性法案(Cyber Resilience Act)适用于我。欧盟开始将软件产品的管理与硬件产品相似,而该法案对此进行了规范(从客户的角度来看,这也是合理的!)。
报告义务将从今年九月开始;其他内容将在2027年12月生效。因此,我花了一些时间阅读相关资料,而不是评论:法规本身[1],以及欧盟委员会于2026年7月27日发布的指导文件[2](C(2026) 5252,大约80页,包含67个实例,明确针对中小企业)。
以下是我目前的发现,以及希望得到纠正的地方:
1. 现在销售软件的方式与销售硬件相似。相同的制度——技术文件、合格声明、软件上的CE标志。我原以为CE标志只与硬件有关,但根据网络韧性法案,现在不再是这样。
2. 我不能通过免费提供软件来逃避责任。豁免适用于在非商业活动中提供的开源软件——免费并不等同于非商业。为了支持我销售的产品而发布的固件显然是商业行为,无论我对此收费多少。
3. 没有规模门槛。一人公司承担的义务与大公司相同。第33条标题为“对微型企业和中小企业的支持措施”,其中的每一条规定都是帮助,而不是豁免。
4. 但实际工作量很小。我的产品不在附录III中,因此是自我评估:没有通知机构、没有费用、没有文件提交、没有人批准任何东西。工作似乎只是我写的一小部分文件。基本上,你可以自己贴上CE标签。
5. 但第13条第9款规定,每次发布的安全更新必须在发布后保持可用10年,或在支持期内,取其较长。这对于2027年推出的产品来说,可能意味着到2040年代的相当长时间,可能只销售一次。
6. 报告义务在支持结束时并不会终止。指导文件明确指出(第210段):漏洞处理在支持期结束时停止,但报告在此之后继续。
我就说到这里,但还有几个其他的影响。
哦,在你问之前:居住地并不重要,重要的是你是否向欧盟销售。
简而言之:我没有找到任何与这些问题相关的“独立”来源,因此我主要的问题是——是否还有其他人正在为这种情况做准备?如果有,你是如何处理的?特别希望了解那些在小规模上经历过此事的人,或来自市场监管机构的人。
[1] https://eur-lex.europa.eu/eli/reg/2024/2847/oj
[2] https://digital-strategy.ec.europa.eu/en/library/commission-publishes-new-guidance-support-timely-cyber-resilience-act-implementation
查看原文
I run a one-person GmbH in Germany. I am thinking about selling firmware for an off-the-shelf handheld - offline, no WiFi, no network stack compiled in at all, updates by reflashing over USB. I don't sell hardware, just software.<p>Turns out that the EU Cyber Resilience Act applies to me. The EU starts to handle software products similar to hardware products and the CRA regulates that (and from a customer's standpoint - rightfully so!).<p>Reporting duties start this September; everything else in December 2027. So I spent some time reading the sources rather than the commentary: the Regulation itself [1], and the Commission's guidance of 27 July 2026 [2] (C(2026) 5252, around 80 pages with 67 worked examples, explicitly aimed at SMEs).<p>This is what I found out so far, and this is where I'd like to be corrected:<p>1. Selling software now works like selling hardware. Same regime - technical file, declaration of conformity, CE marking on a piece of software. I'd assumed CE was a hardware thing; with the CRA not anymore.<p>2. I can't escape it by giving the software away. The exemption is for open source supplied outside commercial activity - free isn't the same as non-commercial. Firmware I publish to support a product I sell is plainly commercial, whatever I charge for it.<p>3. There's no size threshold. A one-person company carries the same obligations as a large one. Article 33 is titled "Support measures for microenterprises and small and medium-sized enterprises" and every provision in it is help, not exemption.<p>4. But the actual work is small. My product isn't in Annex III, so it's self-assessment: no notified body, no fee, nothing filed, nobody approves anything. The work seems to be a handful of documents I write once. You basically stick the CE label on by yourself.<p>5. But there is Art. 13(9). Every security update you ship has to stay available for 10 years after you issue it, or the rest of the support period, whichever is longer. That's a serious amount of time into the 2040s for a product launched in 2027, maybe sold only once.<p>6. Reporting obligations don't end when support does. The guidance is explicit (para 210): vulnerability handling stops with the support period, reporting continues afterwards.<p>I'll stop here, but there's a couple more implications.<p>Ah, and before you ask: it doesn't matter where you live, it matters that you sell to the EU.<p>In a nutshell: I didn't find any 'indie' sources dealing with these matters, so my main question is - is anyone else preparing for this scenario? If so, how do you handle it? Especially interested in anyone who has actually been through this at a small scale, or anyone from a market surveillance authority.<p>[1] https://eur-lex.europa.eu/eli/reg/2024/2847/oj<p>[2] https://digital-strategy.ec.europa.eu/en/library/commission-publishes-new-guidance-support-timely-cyber-resilience-act-implementation