{"id":2230,"date":"2023-05-15T07:21:12","date_gmt":"2023-05-15T15:21:12","guid":{"rendered":"https:\/\/blog.mozilla.org\/netpolicy\/?p=2230"},"modified":"2023-06-09T01:35:22","modified_gmt":"2023-06-09T09:35:22","slug":"mozilla-weighs-in-on-the-eu-cyber-resilience-act","status":"publish","type":"post","link":"https:\/\/blog.mozilla.org\/netpolicy\/2023\/05\/15\/mozilla-weighs-in-on-the-eu-cyber-resilience-act\/","title":{"rendered":"Mozilla weighs in on the EU Cyber Resilience Act"},"content":{"rendered":"<p>Cybersecurity incidents and attacks have been on the rise in the past years. Enhancing security and trust is more relevant than ever to protect users online. Legislators worldwide have been contemplating new rules to ensure that hardware and software products become more secure, with the latest example being the EU\u2019s<a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/library\/cyber-resilience-act\"> Cyber Resilience Act<\/a>. Below we present our concrete recommendations on how legislators can ensure that the CRA can effectively achieve its objectives.<\/p>\n<p>In recent years, the European Commission has taken concrete steps to boost its cyber security capabilities across Europe. After successfully adopting the<a href=\"https:\/\/eur-lex.europa.eu\/eli\/dir\/2022\/2555\/oj\"> NISD2<\/a> and the<a href=\"https:\/\/eur-lex.europa.eu\/eli\/reg\/2019\/881\/oj\"> EU Cybersecurity Act<\/a>, the last missing piece of the puzzle is the Cyber Resilience Act (CRA). This latest proposal aims to bolster the security capabilities of hardware and software products in the EU market while ensuring a more coherent framework that facilities compliance.<\/p>\n<p>At Mozilla, we believe that individuals\u2019 security and privacy online and a safe Internet overall can only be guaranteed when all actors comply with high cybersecurity standards. We are constantly investing in the security of our products, the internet, and its underlying infrastructure. Therefore, we welcome and support the overarching goals of the CRA. To realize its full potential and achieve its objectives, we call on legislators to consider the following recommendations during the upcoming legislative deliberations:<\/p>\n<ul>\n<li aria-level=\"1\"><b>Clarify \u2018commercial activity\u2019 for open-source software <\/b>&#8211; free and open-source software promotes the development of the internet as a public resource. Many open-source projects (like Mozilla\u2019s products) have commercial characteristics (i.e., provided in exchange for a price) and, therefore, should abide by the CRA rules. However, there are several open-source projects that will be unintentionally captured by the CRA obligations. For example, merely charging a small fee for the technical support of the freely provided software to fund the financial existence of such projects should not be considered a commercial activity.<\/li>\n<li aria-level=\"1\"><b>Align the proposal with existing EU cybersecurity legislation<\/b> \u2013 given the number of legislative initiatives the EU\u2019s cybersecurity package has introduced in the past years, legislators should ensure that obligations around reporting incidents, timeframes, and competent authorities remain aligned across different laws. Such discrepancies can lead to confusion at a time when the efficiency of reporting cybersecurity incidents is paramount.<\/li>\n<li><b>Refrain from disclosing unmitigated vulnerabilities<\/b> &#8211; Mozilla has long advocated for reforms to how governments handle vulnerabilities. Stockpiling vulnerabilities can result in abusive use from governments themselves but also from malicious actors. Policies that mandate the disclosure of unpatched vulnerabilities should be scrutinized carefully. Even if well-intended, we believe that sharing such vulnerabilities with governments creates more risk than it solves.<\/li>\n<\/ul>\n<p>Clear, proportionate, and enforceable rules are the way forward to achieve cyber resilience of digital products and, eventually, safety for all Internet users. We look forward to working closely with policymakers to realize these goals.<\/p>\n<p>To read Mozilla&#8217;s position in detail, click <a href=\"https:\/\/blog.mozilla.org\/netpolicy\/files\/2023\/05\/Mozilla-CRA-Position-Paper.pdf\">here<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cybersecurity incidents and attacks have been on the rise in the past years. Enhancing security and trust is more relevant than ever to protect users online. Legislators worldwide have been &hellip; <a class=\"go\" href=\"https:\/\/blog.mozilla.org\/netpolicy\/2023\/05\/15\/mozilla-weighs-in-on-the-eu-cyber-resilience-act\/\">Read more<\/a><\/p>\n","protected":false},"author":1924,"featured_media":1675,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[283198],"tags":[],"coauthors":[452999],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v22.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Mozilla weighs in on the EU Cyber Resilience Act - Open Policy &amp; Advocacy<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/blog.mozilla.org\/netpolicy\/2023\/05\/15\/mozilla-weighs-in-on-the-eu-cyber-resilience-act\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Tasos Stampelos\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/2023\/05\/15\/mozilla-weighs-in-on-the-eu-cyber-resilience-act\/\",\"url\":\"https:\/\/blog.mozilla.org\/netpolicy\/2023\/05\/15\/mozilla-weighs-in-on-the-eu-cyber-resilience-act\/\",\"name\":\"Mozilla weighs in on the EU Cyber Resilience Act - Open Policy &amp; Advocacy\",\"isPartOf\":{\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/2023\/05\/15\/mozilla-weighs-in-on-the-eu-cyber-resilience-act\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/2023\/05\/15\/mozilla-weighs-in-on-the-eu-cyber-resilience-act\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/blog.mozilla.org\/netpolicy\/files\/2019\/12\/privacy-image.png\",\"datePublished\":\"2023-05-15T15:21:12+00:00\",\"dateModified\":\"2023-06-09T09:35:22+00:00\",\"author\":{\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/#\/schema\/person\/caba12532672da33022261024cc9cf63\"},\"breadcrumb\":{\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/2023\/05\/15\/mozilla-weighs-in-on-the-eu-cyber-resilience-act\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/blog.mozilla.org\/netpolicy\/2023\/05\/15\/mozilla-weighs-in-on-the-eu-cyber-resilience-act\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/2023\/05\/15\/mozilla-weighs-in-on-the-eu-cyber-resilience-act\/#primaryimage\",\"url\":\"https:\/\/blog.mozilla.org\/netpolicy\/files\/2019\/12\/privacy-image.png\",\"contentUrl\":\"https:\/\/blog.mozilla.org\/netpolicy\/files\/2019\/12\/privacy-image.png\",\"width\":818,\"height\":458},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/2023\/05\/15\/mozilla-weighs-in-on-the-eu-cyber-resilience-act\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/blog.mozilla.org\/netpolicy\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Mozilla weighs in on the EU Cyber Resilience Act\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/#website\",\"url\":\"https:\/\/blog.mozilla.org\/netpolicy\/\",\"name\":\"Open Policy &amp; Advocacy\",\"description\":\"Mozilla&#039;s official blog on open Internet policy initiatives and developments\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/blog.mozilla.org\/netpolicy\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/#\/schema\/person\/caba12532672da33022261024cc9cf63\",\"name\":\"Tasos Stampelos\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/#\/schema\/person\/image\/5e3cb964f7eb226bbb5e3b0f02410ed3\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/36878ab9519e3d11e2cdd28bc854c8ab?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/36878ab9519e3d11e2cdd28bc854c8ab?s=96&d=mm&r=g\",\"caption\":\"Tasos Stampelos\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Mozilla weighs in on the EU Cyber Resilience Act - Open Policy &amp; Advocacy","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/blog.mozilla.org\/netpolicy\/2023\/05\/15\/mozilla-weighs-in-on-the-eu-cyber-resilience-act\/","twitter_misc":{"Written by":"Tasos Stampelos","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/blog.mozilla.org\/netpolicy\/2023\/05\/15\/mozilla-weighs-in-on-the-eu-cyber-resilience-act\/","url":"https:\/\/blog.mozilla.org\/netpolicy\/2023\/05\/15\/mozilla-weighs-in-on-the-eu-cyber-resilience-act\/","name":"Mozilla weighs in on the EU Cyber Resilience Act - Open Policy &amp; Advocacy","isPartOf":{"@id":"https:\/\/blog.mozilla.org\/netpolicy\/#website"},"primaryImageOfPage":{"@id":"https:\/\/blog.mozilla.org\/netpolicy\/2023\/05\/15\/mozilla-weighs-in-on-the-eu-cyber-resilience-act\/#primaryimage"},"image":{"@id":"https:\/\/blog.mozilla.org\/netpolicy\/2023\/05\/15\/mozilla-weighs-in-on-the-eu-cyber-resilience-act\/#primaryimage"},"thumbnailUrl":"https:\/\/blog.mozilla.org\/netpolicy\/files\/2019\/12\/privacy-image.png","datePublished":"2023-05-15T15:21:12+00:00","dateModified":"2023-06-09T09:35:22+00:00","author":{"@id":"https:\/\/blog.mozilla.org\/netpolicy\/#\/schema\/person\/caba12532672da33022261024cc9cf63"},"breadcrumb":{"@id":"https:\/\/blog.mozilla.org\/netpolicy\/2023\/05\/15\/mozilla-weighs-in-on-the-eu-cyber-resilience-act\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/blog.mozilla.org\/netpolicy\/2023\/05\/15\/mozilla-weighs-in-on-the-eu-cyber-resilience-act\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog.mozilla.org\/netpolicy\/2023\/05\/15\/mozilla-weighs-in-on-the-eu-cyber-resilience-act\/#primaryimage","url":"https:\/\/blog.mozilla.org\/netpolicy\/files\/2019\/12\/privacy-image.png","contentUrl":"https:\/\/blog.mozilla.org\/netpolicy\/files\/2019\/12\/privacy-image.png","width":818,"height":458},{"@type":"BreadcrumbList","@id":"https:\/\/blog.mozilla.org\/netpolicy\/2023\/05\/15\/mozilla-weighs-in-on-the-eu-cyber-resilience-act\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/blog.mozilla.org\/netpolicy\/"},{"@type":"ListItem","position":2,"name":"Mozilla weighs in on the EU Cyber Resilience Act"}]},{"@type":"WebSite","@id":"https:\/\/blog.mozilla.org\/netpolicy\/#website","url":"https:\/\/blog.mozilla.org\/netpolicy\/","name":"Open Policy &amp; Advocacy","description":"Mozilla&#039;s official blog on open Internet policy initiatives and developments","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/blog.mozilla.org\/netpolicy\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/blog.mozilla.org\/netpolicy\/#\/schema\/person\/caba12532672da33022261024cc9cf63","name":"Tasos Stampelos","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog.mozilla.org\/netpolicy\/#\/schema\/person\/image\/5e3cb964f7eb226bbb5e3b0f02410ed3","url":"https:\/\/secure.gravatar.com\/avatar\/36878ab9519e3d11e2cdd28bc854c8ab?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/36878ab9519e3d11e2cdd28bc854c8ab?s=96&d=mm&r=g","caption":"Tasos Stampelos"}}]}},"_links":{"self":[{"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/posts\/2230"}],"collection":[{"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/users\/1924"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/comments?post=2230"}],"version-history":[{"count":0,"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/posts\/2230\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/media\/1675"}],"wp:attachment":[{"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/media?parent=2230"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/categories?post=2230"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/tags?post=2230"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/coauthors?post=2230"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}