Why Cyber Resilience Act (CRA) Won't Work
American companies don't follow laws, they work around them (they even lobby to add loopholes for themselves, notably in order to exempt themselves from strict compliance needs and effective enforcement/regulatory fines/antitrust penalties)
"Cyber Resilience Act" (CRA) is about "reporting obligations" among other things that are "shaping" Europe's so-called "digital future" (quoting their silly and technically-shallow prose).
If Europe wants any future - let alone a so-called "digital future" - then it needs to rely on its own so-called "digitalisation" (buzzword that EPO management truly fancies as it is a vague misnomer like "agents"). At the EPO, everything of significant confidentiality needs/requirements was outsourced to Microsoft (US) and the EU tolerates this. It's hard not to get cynical about the whole thing. Remember what ICC in Europe was subjected to after it had foolishly outsourced to Microsoft (US). It's the same with the British legal system. We'll cover the latter in future years.
So what sort of security do we have in Europe if we do not control our own data and computer systems? Nothing. Zilch. This is not security. This is a breach, a compromise, a sellout.
Some people in Europe, sometimes but not always on the payroll of American companies or their offshoots/partners (which are deep in debt; it's a cultural thing for both people and companies in the US to always borrow as much as feasible, then tell one another this is "normal"), try to convince us and our elected officials that it's totally OK and perfectly safe to outsource and import. Of course they do not disclose their conflict of interest, a salary meant to retain foreign occupation with localised subsidiaries meant to foster a phony image of being wholly independent (see the Finnish example this week, it has sold out to Microsoft and Google, it effectively became an "outpost state").
If Europe does not invest in autonomy, it'll never have any and may lose the little it has left. See FRANCE 24's timely new report, "Europe urged to find its path, from crewed spaceflight to communications" (published yesterday).

Well, part of the CRA kicks in today: "Cyber Resilience Act, Article 14"
"Manufacturers of hardware and software are now obligated to report actively exploited vulnerabilities and severe incidents within 24 hours," an associate explained. "The word "severe" is doing heavy lifting there and Microsoft will avoid using it whenever possible to do so. Furthermore, the CRA conflicts with the gag and non-disparagement clauses* bound into Microsoft contracts with the public sector So there is a conflict there."
In short, Microsoft can just hide holes or deny that existing holes are "severe". That's it.
It's not just a Microsoft thing.
Google also. GAFAM and much more.
They must be having a field day today, for Europe erects a set of new regulations that are toothless upon arrival and will likely just punish small companies without lobbyists or in-house legal/compliance teams (i.e. it'll hurt the European economy with an abundance of SMEs in it).
How about European bans on companies that put back doors in things? Or companies that work for Putin? No? Is that too much to ask for?
Canonical (de facto GAFAM subsidiary based in London) has just published "What the Cyber Resilience Act (CRA) means for Android™ development" and it says:
The CRA starts now: 24 hours to respond Picture this: a critical Android vulnerability is reportedly being exploited. Based on initial analysis, the compromised component is part of your software stack. Your product runs Android, but probably not exactly the Android described in the Common Vulnerabilities and Exposures (CVE) description.
Remember the EU's upload filters (which another GAFAM front group in Europe, misleadingly named "FSFE", boosted**)? Those so-called 'filters' too punished small European companies, whereas Google and Microsoft could afford to respond within the specified time, as they have many workers dealing with notices "all around the clock" (or deploy bots to do so shoddily and sloppily, offloading liability to buzzwords).
If the CRA is toothless, it's because it was designed to fail and crafted in the usual way: bribes, lobbyists, and pressure disguised as "input" (or GAFAM proxies pretending to be European or falsely claiming to represent Europe). █
____
* Suffice to say, we previously gave more consideration to the possible gag clauses which Microsoft has in public sector contracts, and the possible effects of such clauses. See for instance:
** It was paid by Google to promote Google-friendly legislation. We should add that despite the name, the organisation has nothing to do with the actual FSF and is sometimes at odds with it (it later started taking money from Microsoft as well, a hefty sum). Similarly, not too long after Reda lobbied to gut the FSF (remove its leader and founder) Reda went to work for Microsoft (US). Great example of a sellout. Prior to that Reda had played a pivotal role regarding upload filters.
