Cyber Resilience Act
From baby-monitors to smart watches, from apps to computer programs, connectable hardware and software are omnipresent in our daily lives. Less apparent to many users is the security risk such products may present.
The Cyber Resilience Act (CRA) aims to safeguard consumers and businesses buying software or hardware products with digital elements. The CRA addresses the inadequate level of cybersecurity in many products, and the lack of timely security updates. It also tackles the challenges consumers and businesses currently face when trying to determining which products are cybersecure and in setting them up securely, making it easier to identify hardware and software with the proper cybersecurity features.
The CRA introduces mandatory cybersecurity requirements for manufacturers, covering the planning, design, development and maintenance of such products. These obligations must be met at every stage of the value chain. The CRA also requires manufacturers to handle vulnerabilities during the lifecycle of their products. Some products of particular relevance for cybersecurity may need to undergo a third-party assessment by a notified body before they are sold on the EU market.
Via Ron Elemans:
[…] the extremely heavy future requirements that are due on December 11, 2027.
For example, free security updates must be provided for at least five years without changes regarding the operating system requirements—a period that resets every time someone purchases an app of a particular version.
Here’s the text of it, which was approved in 2024.
Previously:
17 Comments RSS · Twitter · Mastodon
> free security updates must be provided for at least five years without changes regarding the operating system requirements
Is this even possible with current App Store rules? Once you update the minimum supported OS version of your app (which you might be forced to by newer Xcode versions, which Apple requires for submission, no longer supporting old OS releases), you can no longer provide updates for your older app versions on the App Store.
@Frederik probably not, and as written this law seems overly prescriptive.
Though like many EU laws lately, it was likely written specifically with Apple in mind, intending to force policy changes.
@Frederik,
I don't know. I haven't read through the 84-page FAQ yet.
But apparently, the reporting requirements go into effect in two weeks. We have over a year for functional requirements.
Clearly, the EU wants to take Apple down a peg or two. But they absolutely want to destroy small businesses, especially those that aren't in the EU.
Well overdue for someone to take the software industry to the anvil for some quality hammer time over using "security updates" to force OS / App Version upgrades.
On the face of it, this should target Apple's refusal to provide security updates to iOS for people whose devices can run a newer generation of iOS; eg people with iOS 26 capable devices, refusing the downgrade to Liquid Ass and staying on iOS 18.
Fucking hell. The EU is trying to impose done responsibility on a sector that has caused so much harm, and you guys start whining.
> But they absolutely want to destroy small businesses
How. Any halfway-serious software company already did most of what the CRA prescribes anyway. How does this destroy small businesses.
@someone
> On the face of it, this should target Apple's refusal to provide security updates to iOS for people whose devices can run a newer generation of iOS; eg people with iOS 26 capable devices, refusing the downgrade to Liquid Ass and staying on iOS 18.
As much as I don't like Liquid Glass... why? Each iOS version has people that are upset with changes. I don't think it is realistic to ask companies to maintain security updates for every historical version. Security patching even got worse with the huge influx of LLM-detected vulnerabilities.
For devices that are not supported by newer iOS versions anymore I can see the point, especially if the device is still in the required security update period.
"I don't think it is realistic to ask companies to maintain security updates for every historical version."
...
...
...
...
...
What are you even talking about. Apple literally already does this. It just doesn't release those security updates to people on devices that support newer major versions, forcing some people to upgrade. That was made clear when a major bug started actively being exploited in iOS 18 in April, and Apple finally released the iOS 18.7.8 upgrade for every device that supported iOS 18 (not just obsolete devices stuck on iOS 18). It's clearly just a business decision, not any technical one. Apple, and any other somewhat-competent software company, could easily do this.
@Daniël
> I don't think it is realistic to ask companies to maintain security updates for every historical version.
Why? Why should software developers be allowed to release faulty products, and say "there it is". This has been a broken cultural thing about the software industry for ever, that somehow software is special, and the laws of basic consumer fitness don't apply to it.
Your product contains a flaw, you sold it to a person, you are obligated to fix it *at the specification the customer bought*. If that's difficult, cry me a river, and get out of the industry.
Or, maybe the instant a piece of software ceases to be "supported" by its developer, the state should mandate its sourcecode be released, and its IP rights turned over to public domain.
I'm a sculptor, as an artist; the lowest paid profession in the developed world. I carry $20 million in public liability insurance. I have to pay for for that every year. Do I get to say "sorry, you stood next to the assemblage of steel at your own risk". No, I don't. But every software EULA "we are not responsible for losses resulting from the use of this product malfunctioning", well F that.
It's time for software developers, and software in general to be as strictly insured, licenced and regulated as architects and buildings.
@Simone Manganelli
> What are you even talking about. Apple literally already does this.
This is hyperbole and provably wrong. They are currently only actively maintaining 26.x plus 18.x for the iPhone XS/XR.
They occasionally do a patch release for 15.x and 16.x, but only for extremely severe issues. For instance, in 2026, they only fixed one known WebKit vulnerability and the issue where deleted notifications were still stored. They haven't gotten fixes for the over 100 CVEs that were fixed on 26.x and 18.x
iOS 14 not been touched since 2021.
@Daniël
> This is hyperbole and provably wrong. They are currently only actively maintaining 26.x plus 18.x for the iPhone XS/XR.
iOS 18 had a security update for *every* device still running it, only a couple of months ago, including those supported by iOS 26. To be clear, Apple can release updates to old operating systems for devices that support newer ones, however they choose not to.
It would appear the EU's intention is to take that choice away from Apple.
@Someone: I was more arguing that in general it's a slippery slope, because there will be people that want to stay with iOS 17 or 16, so where does it stop? I do agree that there is somewhat of a stronger argument for iOS 18 due to Apple still supporting it for a bunch of devices that don't get iOS 26.
But would you argue the same if we were on iOS 27 and those devices were stuck on iOS 26? Probably not? So, it's more about people hating Liquid Glass than necessarily wanting to run older versions. I don't think it's tenable to stay on an old version forever, so either Apple is going to make iOS acceptable again, people just have to accept it, or it is time to move somewhere else.
IMO this is the problem of the iOS ecosystem. In the end you have to go wherever Apple wants to go. If Samsung had made the equivalent of Liquid Glass in OneUI, you could just go to Pixel UI, something close to stock AOSP, or one of the gazillion other options.
Call me crazy, but I don’t think a requirement to support software with security updates for five years after the sale is that onerous.
Nothing I’m seeing would require updates for as long as someone is sticking on an old version.
> This is hyperbole and provably wrong. They are currently only actively maintaining 26.x plus 18.x for the iPhone XS/XR.
As has already been pointed out, *your* statement is hyperbole and provably wrong. On my iPhone 12 mini, I am literally staring at my screen, seeing a blaring "18.7.8" "18.7.8" "18.7.8" stare back at me, even though I am one major version behind for almost a year now. They issued this update for all devices that ever supported iOS 18.
> But would you argue the same if we were on iOS 27 and those devices were stuck on iOS 26?
Yes. Yes I would argue that, and it is not even that controversial, nor onerous. There should be security updates for every major version of all Apple platforms for every device that ever supported that major version, for five years. Full stop. Good for the EU. BECAUSE APPLE ALREADY DOES THIS. Apple issued a security update for iOS 15! This year!!! They are already doing it! They are supporting iOS 15, 16, 17, 18, 26, and beta 27! Calendar year 2026! They can spend a little more effort testing and releasing them for every device that ever supported them. And that would probably improve their toolset and fix a ton of bugs along the way, helping everyone on the platform. They rake in billions of dollars in profit for year and burn it by doing stock buybacks and issuing share dividends!! They have the money and the time, they can pay a few extra engineers to do this work! They can do it! Literally the biggest company in the world can do it! Heck, I will do it, I'm looking for a job!
*bangs head on desk repeatedly*
Oh, I forgot to point out that Apple does this in a better way on macOS. They're supporting beta Golden Gate, Tahoe, Sequoia, and Sonoma, and issuing security updates for all of them. And you can choose to stay on whichever version you want. Extending that support to two more major versions would not be onerous at all.
@SimoneManganelli
> Oh, I forgot to point out that Apple does this in a better way on macOS.
You can bet that prior to this mandate, the plan for macOS was to adopt the iOS paradigm, and only provide security updates for the most recent version of macOS your hardware supports.