EU CRA (Cyber Resilience Act)
EU CRA (Cyber Resilience Act)
Posted Jan 2, 2026 21:21 UTC (Fri) by hailfinger (subscriber, #76962)Parent article: Kroah-Hartman: Linux kernel security work
I know that various foundations have employed FUD tactics to get small FOSS projects to join them due to the perceived CRA threats. Unless you're a FOSS project the size of Debian, Mozilla or the Linux kernel, joining a larger organization is completely stupid from a CRA perspective.
Why, you ask? Simple. If you're a small FOSS project and don't make a profit from it, you're exempt from the obligations of the CRA (but you still get all the benefits from the CRA). Join a larger org (foundation, whatever) and suddenly you're subject to the CRA.
Now if you enjoy being regulated, feel free to join some of the foundations. Otherwise, steer clear of them.
