Bonum Certa Men Certa

Why Cyber Resilience Act (CRA) Won't Work

posted by Roy Schestowitz on Sep 11, 2026,
updated Sep 11, 2026

American companies don't follow laws, they work around them (they even lobby to add loopholes for themselves, notably in order to exempt themselves from strict compliance needs and effective enforcement/regulatory fines/antitrust penalties)

"Cyber Resilience Act" (CRA) is about "reporting obligations" among other things that are "shaping" Europe's so-called "digital future" (quoting their silly and technically-shallow prose).

If Europe wants any future - let alone a so-called "digital future" - then it needs to rely on its own so-called "digitalisation" (buzzword that EPO management truly fancies as it is a vague misnomer like "agents"). At the EPO, everything of significant confidentiality needs/requirements was outsourced to Microsoft (US) and the EU tolerates this. It's hard not to get cynical about the whole thing. Remember what ICC in Europe was subjected to after it had foolishly outsourced to Microsoft (US). It's the same with the British legal system. We'll cover the latter in future years.

So what sort of security do we have in Europe if we do not control our own data and computer systems? Nothing. Zilch. This is not security. This is a breach, a compromise, a sellout.

Some people in Europe, sometimes but not always on the payroll of American companies or their offshoots/partners (which are deep in debt; it's a cultural thing for both people and companies in the US to always borrow as much as feasible, then tell one another this is "normal"), try to convince us and our elected officials that it's totally OK and perfectly safe to outsource and import. Of course they do not disclose their conflict of interest, a salary meant to retain foreign occupation with localised subsidiaries meant to foster a phony image of being wholly independent (see the Finnish example this week, it has sold out to Microsoft and Google, it effectively became an "outpost state").

If Europe does not invest in autonomy, it'll never have any and may lose the little it has left. See FRANCE 24's timely new report, "Europe urged to find its path, from crewed spaceflight to communications" (published yesterday).

From communications to crewed spaceflight, French President Emmanuel Macron and European Commission President Ursula von der Leyen called for Europeans to 'act' on a massive scale to find their place in the space race on Thursday – notably, against the United States and China.

Well, part of the CRA kicks in today: "Cyber Resilience Act, Article 14"

"Manufacturers of hardware and software are now obligated to report actively exploited vulnerabilities and severe incidents within 24 hours," an associate explained. "The word "severe" is doing heavy lifting there and Microsoft will avoid using it whenever possible to do so. Furthermore, the CRA conflicts with the gag and non-disparagement clauses* bound into Microsoft contracts with the public sector So there is a conflict there."

In short, Microsoft can just hide holes or deny that existing holes are "severe". That's it.

It's not just a Microsoft thing.

Google also. GAFAM and much more.

They must be having a field day today, for Europe erects a set of new regulations that are toothless upon arrival and will likely just punish small companies without lobbyists or in-house legal/compliance teams (i.e. it'll hurt the European economy with an abundance of SMEs in it).

How about European bans on companies that put back doors in things? Or companies that work for Putin? No? Is that too much to ask for?

Canonical (de facto GAFAM subsidiary based in London) has just published "What the Cyber Resilience Act (CRA) means for Android™ development" and it says:

The CRA starts now: 24 hours to respond Picture this: a critical Android vulnerability is reportedly being exploited. Based on initial analysis, the compromised component is part of your software stack. Your product runs Android, but probably not exactly the Android described in the Common Vulnerabilities and Exposures (CVE) description.

Remember the EU's upload filters (which another GAFAM front group in Europe, misleadingly named "FSFE", boosted**)? Those so-called 'filters' too punished small European companies, whereas Google and Microsoft could afford to respond within the specified time, as they have many workers dealing with notices "all around the clock" (or deploy bots to do so shoddily and sloppily, offloading liability to buzzwords).

If the CRA is toothless, it's because it was designed to fail and crafted in the usual way: bribes, lobbyists, and pressure disguised as "input" (or GAFAM proxies pretending to be European or falsely claiming to represent Europe).

____

* Suffice to say, we previously gave more consideration to the possible gag clauses which Microsoft has in public sector contracts, and the possible effects of such clauses. See for instance:

2023-10-26 Microsoft's Non-Disparagement Agreements/Clauses: Can't See, Hear, or Speak
2024-03-22 Hiding Behind Call Centre Staff and Contradictions/Lies (Lying to the Customers) to Protect Microsoft From 'Embarrassment'?
2024-04-02 The Microsoft NDAs Keep Microsoft Employees (and Former Employees) From Talking About Embarrassing (to Microsoft) Facts and Information About Crimes
2024-08-30 Microsoft is Still Hurting Badly From CrowdStrike-gate (Now It Plays Dirty to Bypass Technical People)
2025-07-20 More Microsoft Shutdowns That Mostly Slipped Under the Radar
2025-08-06 Microsoft is Apparently Sending Gag Orders or NDAs to Staff That Got Laid Off (“We were told not to post on LinkedIn. Not to say anything.”)

** It was paid by Google to promote Google-friendly legislation. We should add that despite the name, the organisation has nothing to do with the actual FSF and is sometimes at odds with it (it later started taking money from Microsoft as well, a hefty sum). Similarly, not too long after Reda lobbied to gut the FSF (remove its leader and founder) Reda went to work for Microsoft (US). Great example of a sellout. Prior to that Reda had played a pivotal role regarding upload filters.

Other Recent Techrights' Posts

Why Cyber Resilience Act (CRA) Won't Work
American companies don't follow laws, they work around them
Net Gain of 50 Gemini Capsules in Just One Month
a big jump in just one month
Keeping Linux Reliable
If Linux becomes a lot more reliable in the future, it'll be an "hey hi" miracle. If Linux becomes a lot less reliable in the future, we'll know why and who is responsible for it.
Cyber Show on the Fallacy of Salary/Ego as a Function of Wisdom in the Era of Pyramid Schemes (Cheating People Using Buzzwords and Complicit Media)
"the remuneration fallacy and the role of reluctance as a negative feedback force."
EPO's Local Staff Committee Munich Organises General Assembly Next Week, the Goal is to Oust the Corrupt President and Derail His Unlawful Agenda
They're aiming to show Campinos the door
 
Earlier This Year Microsoft's Chief Liar Frank Shaw Lied About the Layoffs. Now He's Leaving.
he's nowhere near retirement age
Gemini Links 11/09/2026: Small Things and "Hitching Your Wagon"
Links for the day
Links 11/09/2026: Tristan Buckmaster Ripped Off by Slop, Social Control Media Spreads Hatred for Profit
Links for the day
Animals Smarter Than Chatbots
Quack quack goes the chatbot
IBM Isn't Reporting Layoffs, But It Removes Tens of Thousands of People From Its Workforce
Red Hat and IBM already mark people for removal
"A Tale of Two Antónios" Will Resume Soon
In November the site turns 20
Links 11/09/2026: Cyberattack in Berlin (Windows/Microsoft TCO) and Hype About Slop as 'Existential' Something; Scam Altman et al Caught Stealing/Plagiarising "Mathematical Breakthrough"
Links for the day
Microsoft/GNOME 9/11
Garrett and Graveley (Microsoft/GNOME) will have a lot to explain
9/11 Was a National Event, Not an International Event
They insist that back doors will "save lives"
Very Sloppy PR From a Dying IBM, Company in Disarray and in Need of Distractions
IBM could really use distractions right now
What a Price-Fixing Cartel Can Look Like
If your prices increase five-fold or ten-fold and so do your revenues/income, what does that tell us?
SLAPP Censorship - Part 178 Out of 200: Explaining to Your American Clients That Spending 130,000+ United States Dollars on a Single Hearing in Another Continent Means the UK's National Archives Will Retain in Perpetuity What Your Spouse or Girlfriend Said
Balabhadra (Alex) Graveley should ask Garrett how much money he has lost so far
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, September 10, 2026
IRC logs for Thursday, September 10, 2026
Latest IBM Gossip is, Over 25,000 People to be PIPed (by Year's End)
That figure, 10%, is different from 15% (what we saw a lot). 10% is over 25,000 staff.
Solidarity at EPO
"Many colleagues have made personal and professional sacrifices by participating in the ongoing strike and work-to-rule action"
Gemini Links 11/09/2026: Culture Stuck, Robot Symphony, and Back to Geminispace
Links for the day
Links 10/09/2026: Facebook Unsafe for Kids, Fake Songs (Against Right of Publicity, CG Forgeries Basically) a Growing Problem
Links for the day
Rust is Financially and Technically Controlled by Microsoft. Rust Foundation is a Front for Microsoft's Proprietary Software.
Rust is not and has never been about security
Gemini Links 10/09/2026: "I Don’t Want to Interact With Stochastic Parrots" and "ROOPHLOCH 2026!"
Links for the day
What the British School Closure (BSN Senior School Leidschenveen) Means to EPO Staff
The only European thing about the EPO is the staff
Standing in Solidarity With Matt Mullenweg
I don't trust the people and companies that want Mullenweg out. Neither should you.
Links 10/09/2026: "Smear Campaign Says Anti-Flock Movement Is Chinese Propaganda" and "Flock Employee Calls Cops on Reporter Filming Them"
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, September 09, 2026
IRC logs for Wednesday, September 09, 2026
IBM's Senior VP of Infrastructure is Out, Silent Layoffs Still Going On
Some people imagine the CEO will also "retire" very soon (and "ahead of time")
Gemini Links 09/09/2026: Mechanical Cameras, "Super App", and Prusa Issues
Links for the day
SLAPP Censorship - Part 177 Out of 200: Manosphere Without Financial Transparency
It has moreover replaced a female worker with a male
Deadline Tomorrow (10th of September) to Appeal the EPO's Fleecing of Staff (Union to Make Legal Challenges)
Join them. Fight the good fight.
linuxstans.com Died, Then Came Back as Slop (LLM Junk)
Don't make the mistake or the assumption that merely 'dabbling in' or 'experimenting with' LLMs can be forgivable as it is a trust destroyer
Links 09/09/2026: GAFAM Fatalities in Miami International Airport, "Britain’s Health Crisis Is Becoming a Political Crisis"
Links for the day
Gemini Links 09/09/2026: "Adjective Is Subjective" and Walled Gardens
Links for the day
Plagiarism is Hardly a New Problem, It Predates Mainstream Media Getting Paid to Whitewash It as "Training" or "Hey Hi", Then Conflate Plagiarism With "Intelligence" or Deferred "Value"
"Quantum" isn't new either; it's a 'circle-jerk' for companies without direction, only hype
Links 09/09/2026: Airport 'Down' (Glasgow and Edinburgh), 'Open' 'AI' Losses Rise to Pace of 50 Billion Dollars in Losses Per Year
Links for the day
Unsafe at Any Speed, "Modern" Appliances
Appliances have gotten worse
SLAPP Censorship - Part 176 Out of 200: The Sex-Obsessed Non-Experts
We heard some sexual stories
European Patent Office (EPO): No Transparency and No Paper Trail
The incompetence is that of the management, i.e. sheer incompetence of people who never examined a patent in their entire lifetime
Gemini Links 09/09/2026: Going Out, Smartphone Addiction, Mapping the Geminispace
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, September 08, 2026
IRC logs for Tuesday, September 08, 2026