CRA ‘Free Patches’ Doesn’t Mean ‘No Subscription Needed’
What does the CRA really mean by “free” security updates? Why free patches do not eliminate subscriptions, support, or paid extended maintenance.
The Cyber Resilience Act (CRA) clarifies that its requirement for suppliers to provide security updates "free of charge" does not mean businesses must abandon their subscription models in Europe. Enterprise Linux and other commercial open-source providers will still need to offer security patches, but it doesn't eliminate the need for a subscription for the software itself.
The CRA's support period is not always five years and not limited to EU vendors; it depends on the product's expected use. The act is not aimed at making patches free, but rather at ensuring cybersecurity within product cybersecurity law. It helps users by ensuring security is integrated into products, not an afterthought, and prevents users from having to buy security fixes separately. It does not force vendors to stop selling software or support packages.
Written by urgent.news from HackerNoon's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.