{"MetaKeywords":null,"MetaDescription":"Does the EU Cyber Resilience Act apply to your online store, your plugins or the e-commerce software you sell? Dates, obligations and what to prepare now.","MetaTitle":"Cyber Resilience Act and open-source e-commerce","SeName":"cyber-resilience-act-open-source-ecommerce","Title":"The EU Cyber Resilience Act and open-source e-commerce: who has to do what","PictureModel":{"ImageUrl":null,"ThumbImageUrl":null,"FullSizeImageUrl":null,"Title":null,"AlternateText":null,"Style":null,"ExtraField":null,"Id":null,"UserFields":[]},"Body":"<p>The EU Cyber Resilience Act (CRA) sets security rules for \"products with digital elements\" sold in the European Union - hardware and software alike. It entered into force on 10 December 2024 and applies in two steps:</p>\n<ul>\n<li><strong>11 September 2026</strong>: manufacturers must report actively exploited vulnerabilities and severe security incidents in their products.</li>\n<li><strong>11 December 2027</strong>: the main obligations apply - security by design, vulnerability handling, security updates and documentation.</li>\n</ul>\n<p>If you run or build online stores, the question is not whether the CRA exists but whether it applies to <em>you</em>. The short answer: it depends on whether you <strong>sell software</strong>, not on whether you sell online.</p>\n<p><em>This article explains the regulation in plain terms. It is not legal advice; for your own case, ask a lawyer.</em></p>\n\n<h2 id=\"who\">Who is in scope in e-commerce</h2>\n<table class=\"table\">\n<thead><tr><th>You are...</th><th>Likely position under the CRA</th></tr></thead>\n<tbody>\n<tr><td>A merchant running your own online store</td><td>Generally not in scope for the store itself. A website people use in a browser is not, on its own, a product placed on the market. Your obligations come from other laws (GDPR, NIS2 if you are large enough).</td></tr>\n<tr><td>Selling plugins, themes or add-ons in the EU</td><td>A <strong>manufacturer</strong> of those products: reporting since September 2026, the full set of obligations from December 2027.</td></tr>\n<tr><td>Selling or licensing an e-commerce product built on an open-source platform</td><td>A manufacturer of that product - including the open-source components inside it, which you must check and keep updated.</td></tr>\n<tr><td>An agency building custom stores for clients</td><td>Depends on what you deliver and how. Custom development for one client and a packaged product sold to many are treated differently; this is the case to take to a lawyer.</td></tr>\n<tr><td>Contributing to an open-source project without monetising it</td><td>Not a manufacturer. The CRA explicitly avoids burdening non-commercial open-source development.</td></tr>\n<tr><td>An organisation that supports an open-source project used commercially</td><td>Possibly an <strong>open-source software steward</strong> - a lighter regime focused on a security policy and cooperation with authorities.</td></tr>\n</tbody>\n</table>\n\n<h2 id=\"reporting\">Reporting: what has applied since September 2026</h2>\n<p>A manufacturer that learns of an <strong>actively exploited vulnerability</strong> in its product, or a severe incident affecting its security, notifies it through the single reporting platform run by ENISA:</p>\n<ol>\n<li>an early warning within <strong>24 hours</strong> of becoming aware,</li>\n<li>a notification with more detail within <strong>72 hours</strong>,</li>\n<li>a final report within <strong>14 days</strong> after a fix is available (for a vulnerability) or within a month (for an incident).</li>\n</ol>\n<p>You can only meet those deadlines if you hear about problems quickly - from your own monitoring, from users, and from the upstream projects your product is built on.</p>\n\n<h2 id=\"open-source-inside\">The open-source components inside your product</h2>\n<p>If you sell a product that includes open-source code - an e-commerce platform, libraries, a database driver - the CRA expects you to exercise due diligence on those components. In practice that means:</p>\n<ul>\n<li><strong>Know what is inside</strong>: a software bill of materials (SBOM) listing components and versions.</li>\n<li><strong>Know when a component has a vulnerability</strong>: follow the projects' security advisories.</li>\n<li><strong>Ship fixes</strong> for the period you support your product - which is why the platform you build on needs a clear policy on which versions receive security fixes, and for how long.</li>\n</ul>\n\n<h2 id=\"prepare\">What to prepare now</h2>\n<ol>\n<li><strong>Decide which of the roles above is yours</strong>, product by product.</li>\n<li><strong>Publish a vulnerability disclosure policy</strong> - a page and an address where researchers can report issues.</li>\n<li><strong>Generate an SBOM</strong> for every release you ship.</li>\n<li><strong>Write down your support period</strong>: which versions receive security updates, and until when.</li>\n<li><strong>Rehearse the 24-hour warning</strong>: who decides, who writes it, who submits it.</li>\n</ol>\n\n<h2 id=\"grandnode\">How GrandNode fits in</h2>\n<p>GrandNode is open source under GPL-3.0. The project publishes a <a href=\"/security\">security policy</a> with a way to report vulnerabilities, and from the next release on, its Docker images on GitHub Container Registry are signed and carry an SBOM and build provenance. Security fixes for the latest version are published to everyone.</p>\n<p>If you build products on GrandNode and need fixes on one version for longer, <a href=\"/official\">GrandNode Official</a> adds LTS releases with a 24-month lifecycle, backported security fixes, private notice of vulnerabilities before they are disclosed publicly, and a compliance pack with the security policy and CVE history. It gives you the inputs your own CRA process needs; it does not make your product compliant on your behalf - nothing a supplier sells can.</p>","BodyOverview":"<p>Since 11 September 2026, the EU Cyber Resilience Act requires manufacturers of software to report actively exploited vulnerabilities. Here is who that means in e-commerce, and what to prepare before the main obligations apply in December 2027.</p>","AllowComments":false,"NumberOfComments":0,"CreatedOn":"2026-10-03T10:00:00","Tags":["Cyber Resilience Act","security","compliance","open source"],"Comments":[],"AddNewComment":{"CommentText":null,"DisplayCaptcha":true,"Captcha":{"ReCaptchaChallengeField":null,"ReCaptchaResponseField":null,"ReCaptchaResponseValue":null,"ReCaptchaResponse":null},"Id":null,"UserFields":[]},"Id":"6ac0dd893fddd1b1aaa3969c","UserFields":[{"Key":"gnc.blog.hash","Value":"ee30038bd278d1bef3e908113a4ecbaad88d922a","StoreId":""}]}