Have you tried about new CRA (BTW, June 11th started the first phases), in your plants or software ?
No, I have not. But we only deliver software in machines, and generally for use on non internet connected networks.
The fact that the opening page (
https://digital-strategy.ec.europa.eu/en/policies/cra-msmes) seems to contain faults (MSMEs vs MSEMs) doesn't instill the feeling that this is fully cooked yet.
Anyway, I assume, like CE it will boil down to some form of self-certification for SME. In short, I expect it to be a "paper tiger" with more holes than Edam cheese, with punitive clauses (read: updates not free) giving another escape hatch.
This is my point too, but those laws were done for what ? Saftey ? Security ? Money ?
It starts with safety/security as a noble idea, but when the lobbyist get involved, it becomes about business and thus increasing the revenue per customer under security pretences.
I think Embarcadero's general history is a good example of that. Similar developments can also been seen in cloud services where cheaper alternatives disappear, making upselling the name of the game.
I don't see any basis for that, except for the manufacturer's share holders' dividend. Moreover Embarcadero is special, even in the subscription world, by asking both a one-off fee and a (considerable) subscription fee.
In this regard, maintenance isn't cheap.
My point is more that there is no incentive for the producers at all to keep security related costs under control. Crafty engineering of SKUs and Terms of Service can make a "security only" update something totally else.
Especially if you need to maintain certain "production quality levels and standards." I mean, if I have to maintain hundreds of software releases to customers and ensure everything works properly after every update... (I'm not talking about smartphone apps, but software for production plants)...
Software for production plants is what we do too. This is why I think this is mostly a paper tiger. Just add a box to your tender that customers have to tick if they plan to deploy your product in a situation where security concerns apply, and put a competitive price on that option. 19 out of 20 customers will leave it unchecked...
One of our problems is that antivirus software is severely disruptive to begin with, if your bandwidth (2x 10 GB/s with high utilisation) and realtime requirements increase. Most of the PCs we deliver have defender and firewall disabled. Purely because of support reasons, as any update might suddenly cause these (not very efficient) programs to insert themselves into datastreams where they don't belong.
P.S.: Now, nothing is changed in the plants, only for new features the sw will be updated. After those laws, YOU MUST UPDATE ALL SOFTWARE, ALWAYS.
And SBOM ....
We'll see. The devil is in the details. You know the old IT saying:
Theory is when you know everything but nothing works.
Practice is when everything works but nobody knows why.
In our lab, Theory and practice are combined: nobody knows why nothing works.