# Excessive regulations could be a threat to the OSS industry

**URL:** <https://discourse.sustainoss.org/t/excessive-regulations-could-be-a-threat-to-the-oss-industry/1130>\
**Category:** ⚙️ Technology and Open Source\
**Created:** [November 16, 2022, 3:29am UTC](https://discourse.sustainoss.org/t/excessive-regulations-could-be-a-threat-to-the-oss-industry/1130 "2022-11-16T03:29:18Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![nebairevelations](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sustainoss.org/nebairevelations/32/715_2.png) [@nebairevelations](https://discourse.sustainoss.org/u/nebairevelations)\
**Post date:** [November 16, 2022, 3:29am UTC](https://discourse.sustainoss.org/t/excessive-regulations-could-be-a-threat-to-the-oss-industry/1130/1 "2022-11-16T03:29:18Z")

</div>

The EU Cyber Resilience Act imposes so much compliance overhead over OSS developers. The CRA supposedly would bring support to open-source, but instead, the current proposal will overload small developers with compliance work and hamper software innovation.

> **[Open-source software vs. the proposed Cyber Resilience Act](https://blog.nlnetlabs.nl/open-source-software-vs-the-cyber-resilience-act/)**
>
> By Maarten Aertsen
> 
> NLnet Labs is closely following a legislative proposal by the European Commission affecting almost all hardware and software on the European market. The Cyber Resilience Act (CRA) intends to ensure cybersecurity of products with...

Personal Commentary: I think that is dangerous that governments attemp to interfeering into the spontaneous processes that drive OSS communities, based on knowledge sharing and collaborative efforts. May asking for financial support to politicians is not a good idea after all.

---

<div class="post-metadata">

**Author:** ![osioke](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sustainoss.org/osioke/32/886_2.png) [@osioke](https://discourse.sustainoss.org/u/osioke)\
**Post date:** [November 16, 2022, 5:57am UTC](https://discourse.sustainoss.org/t/excessive-regulations-could-be-a-threat-to-the-oss-industry/1130/2 "2022-11-16T05:57:27Z")

</div>

There are quite a lot of other analyses on the act and on skimming [the proposal](https://digital-strategy.ec.europa.eu/en/library/cyber-resilience-act) itself, it feels like this may be a bit too hard on the act making it seem bad, meanwhile the groupings or classes split OSS into sections that allow OSS developers exist outside the purview of the government/act.

We should check the categories. Currently I see:

1. Class I
2. Class II
3. Unclassified or Default

Where Class I are:

- Identity and access management software
- Browsers
- Password managers
- Malicious software detection
- Products that use virtual private networks
- Network management, configuration, monitoring, and resource management tools
- Security information and event management systems
- Update and patch management tools
- Mobile device and application management software
- Remote access software
- Physical network interfaces
- Microcontrollers
- Integrated circuits and gate arrays intended for use by essential entities described in the NIS2 directive
- Operating systems, firewalls, routers, modems, microprocessors, industrial automation and control systems, and industrial IoT that are not covered by Class II of the Cyber Resilience Act

And Class II are:

- Operating systems
- Hypervisors and container runtime systems
- Public key infrastructure and digital certificate issuers
- Firewalls for industrial use
- Industrial intrusion detection/prevention systems
- General purpose microprocessors
- Microprocessors for programmable logic controllers and secure elements
- Routers for industrial use
- Modems for industrial use
- Industrial switches
- Secure elements
- Hardware Security Modules
- Secure cryptoprocessors
- Smartcards, readers, and tokens
- Industrial Automation & Control Systems intended for the use by essential entities described in NIS2
- Industrial Internet of Things devices intended for the use by essential entities described in NIS2
- Robot sensing and actuator components and robot controllers
- Smart meters

I may be wrong but these mean a large percent of OSS would fall under unclassified or Default. And these ones are self-assessed.

And for those within the classes they seem to be setting up institutions to act as auditors, so this feels to me like a similar setup like the ISO and other similar certification, but now the government is fully leading the charge and not leaving it to top companies to lead and thus control.

These are my uninformed thoughts though, I spoke based on what I read in the shared article, a read of some specific sections in the main 87 page proposal and this analysis:

> **[An Overview of the EU's Cyber Resilience Act](https://datainnovation.org/2022/09/an-overview-of-the-eus-cyber-resilience-act/)**
>
> Summary: On September 15, 2022, the European Commission published its long-awaited draft regulation on the cybersecurity of digital products—the Cyber Resilience Act. Below is an overview of the Cyber Resilience Act, the essential requirements it...

What do others think?
