{
  "id": 6903169,
  "title": "CRA ‘Free Patches’ Doesn’t Mean ‘No Subscription Needed’",
  "url": "https://urgent.news/2026/09/11/cra-free-patches-doesnt-mean-no-subscription-needed",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-11T23:03:28.000Z",
  "source": {
    "name": "HackerNoon",
    "slug": "hackernoon",
    "url": "https://hackernoon.com/cra-free-patches-doesnt-mean-no-subscription-needed?source=rss"
  },
  "original_language": "en",
  "account": "The Cyber Resilience Act (CRA) clarifies that its requirement for suppliers to provide security updates \"free of charge\" does not mean businesses must abandon their subscription models in Europe. Enterprise Linux and other commercial open-source providers will still need to offer security patches, but it doesn't eliminate the need for a subscription for the software itself. The CRA's support period is not always five years and not limited to EU vendors; it depends on the product's expected use. The act is not aimed at making patches free, but rather at ensuring cybersecurity within product cybersecurity law. It helps users by ensuring security is integrated into products, not an afterthought, and prevents users from having to buy security fixes separately. It does not force vendors to stop selling software or support packages.",
  "summary": "What does the CRA really mean by “free” security updates? Why free patches do not eliminate subscriptions, support, or paid extended maintenance.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}