Uppsats
The Cyber Resilience Act: Life Jacket or Weighted Vest? : Regulatory Uncertainties when Integrating Free and Open-Source Software and Balancing Regulatory Burdens for Manufacturers and Innovations from Free and Open-Source Software
Master-uppsats
Linköpings universitet/Affärsrätt
Publicerad: 2026
Språk: Engelska
Nyckelord
klicka för att sökaSammanfattning
The EU faces extensive cyberthreats in which products with digital elements (PDEs) constitute a weakness in the interconnected society. To face these challenges the EU has introduced the Cyber Resilience Act (CRA). The CRA holds a comprehensive regulatory approach as it applies horizontally to all PDEs and imposes various obligations on manufacturers. Simultaneously, the widespread use of Free and Open-Source Software (FOSS) presents significant challenges. FOSS refers to a specific type of software which is community driven and can be accessed, modified, and redistributed for free. The FOSS community is underfunded resulting in frequent cybersecurity vulnerabilities. This is particularly problematic considering FOSS components are often integrated into commercial PDEs, constituting weaknesses in supply chains. The widespread use of FOSS entails that a single vulnerability can be exploited simultaneously across multiple entities, potentially causing far-reaching damage. This thesis examines whether the CRA adequately addresses cybersecurity vulnerabilities originating from FOSS while balancing regulatory burdens for manufacturers and innovations from FOSS. Furthermore, the thesis examines if provisions regarding the integration of FOSS components in commercial PDEs provide sufficient regulatory certainty for manufacturers. The thesis provides both descriptive and critical analysis of the regulatory burdens imposed on manufacturers while evaluating the reasonableness of these obligations. The thesis focuses in particular on the "commercial activity criterion" and the due diligence requirement. The thesis concludes that there are regulatory uncertainties relating to these provisions, especially regarding the term "intention to monetize" within the "commercial activity criterion" which creates interpretative challenges. Similarly, the due diligence requirement lacks clarity regarding both what mandatory measures manufacturers must undertake and at what point this obligation is considered fulfilled. Furthermore, the analysis reveals that the CRA in its current form relies largely on standards that have not yet been fully formulated, creating implications which may threaten both the existence of FOSS and the implementation of the CRA.
Information
- Författare
- Sandberg, Frida
- Lärosäte / institution
- Linköpings universitet/Affärsrätt
- Publiceringsdatum
- 2026
- Uppsatstyp
- Master-uppsats
- Språk
- Engelska
- Nyckelord
- ⌕cybersecurity⌕Due diligence⌕cybersäkerhet⌕Cyber Resilience Act⌕Vulnerabilities⌕PDE⌕CRA⌕FOSS⌕Products with digital elements⌕Free and Open-Source Software⌕Commerciality⌕Commercial Activity Criterion⌕Regulatory burdens for manufacturers⌕Cyberresiliensförordningen⌕Fri- och öppen källkod⌕Digitala produkter⌕Uppkopplade produkter⌕Kommersiell aktivitet⌕Regelbördor för tillverkare
Utforska vidare
Liknande uppsatser
Uppsatser med liknande ämnen och nyckelord.
Master-uppsats, KTH/Skolan för industriell teknik och management (ITM)
Laurén, Mikaela
Publicerad: 2024
Kandidat-uppsats, Högskolan i Halmstad/Akademin för informationsteknologi
Johansson, Nathalie, Jonsson, Liam
Publicerad: 2026
Kandidat-uppsats, KTH/Skolan för elektroteknik och datavetenskap (EECS)
Löfgren, Nils
Publicerad: 2026
Kandidat-uppsats, Uppsala universitet/Institutionen för informatik och media
Kappler, Elena, Bakhtiyarova, Zamira
Publicerad: 2026
Kandidat-uppsats, Chalmers tekniska högskola / Institutionen för mekanik och maritima vetenskaper
Reljanovic, Momir, Ashrafzadeh Esfahani, Ali
Publicerad: 2025
Kandidat-uppsats
Trujillo Diaz, Emilit, Ågestedt, Adam
Publicerad: 2025