{
  "id": 7818094,
  "title": "What the CRA Actually Gives Software Users",
  "url": "https://urgent.news/2026/09/16/what-the-cra-actually-gives-software-users",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-16T12:20:06.000Z",
  "source": {
    "name": "HackerNoon",
    "slug": "hackernoon",
    "url": "https://hackernoon.com/what-the-cra-actually-gives-software-users?source=rss"
  },
  "original_language": "en",
  "account": "The Cyber Resilience Act (CRA) aims to provide software users with concrete protections and benefits throughout the product's lifecycle. Manufacturers must design and produce products with cybersecurity as a core requirement, ensuring users receive a secure configuration, easy access to security updates, and ongoing vulnerability management during the product's declared support period.\n\nUsers should be aware of how the product should be used securely, including its intended purpose, relevant security properties, and update installation procedures. This baseline expectation applies even if every product isn't secure in practice, as the user needs to understand whether security was part of the shipped solution.\n\nThe manufacturer remains responsible for maintaining the cybersecurity of the product after it is sold, irrespective of where the vulnerability resides in the supply chain. They must provide security responses, including fixes and, when applicable, user notifications outlining necessary actions. This process includes notifying component maintainers and sharing any available fixes. This obligation extends to open-source components as well, as the commercial solution still has a manufacturer regardless of the open-source nature of its components.\n\nWhen a vulnerability is being actively exploited, manufacturers must promptly report the issue to relevant authorities and inform impacted users (and, where appropriate, all users) about the problem and potential mitigation or corrective measures. The manufacturer should also provide a clearly identifiable contact for vulnerability reporting, rather than relying on automated forms. If the manufacturer fails to notify users in a timely manner, the responsible CSIRT may inform them instead.\n\nFinally, once a security update is available, manufacturers must generally disclose what was fixed, the affected product, severity, and remediation steps. They may delay publication until users have had a chance to apply the patch, but once fixed, updates will be added to the European Vulnerability Database (EUVD), allowing users globally to search and retrieve vulnerability information via its API.",
  "summary": "Learn what the EU Cyber Resilience Act means for software users, from free security updates and vulnerability notices to support periods and patch availability.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}