EU Cyber Resilience Act - planning #1330
Replies: 3 comments
-
Corrigendum 18/7/2024 https://www.europarl.europa.eu/doceo/document/TA-9-2024-0130-FNL-COR01_EN.pdf @cyclonedx/cdxgen is not permitted to affix CE marking even when compliant
This might affect commercial companies integrating cdxgen, since in paragraph 34,
|
Beta Was this translation helpful? Give feedback.
-
Some unanswered questions:
|
Beta Was this translation helpful? Give feedback.
-
Some sample questionnaires from this blog and cdxgen-specific answers. Risk Assessment Request
Yes.
Yes.
No. Any such plans will be communicated publicly via dedicated issues and discussion threads to avoid the need for any adhoc-queries.
AppThreat Ltd offers Long Term support for multiple versions of cdxgen for paying customers.
Automated application security testing is used. No specific standard is followed as of now.
Real time security information is shared with the following kinds of commercial customers.
Free users can look for issues with the label "security" to track for open and fixed vulnerabilities.
Refer to the CycloneDX security policy.
Our goal is to eventually achieve compliance. As an open-source project, any activity including compliance requires ongoing funding and resources. We have established processes and legal paperwork (for AppThreat Ltd) to work with procurement and OSPO teams in your organisations to explore funding opportunities.
cdxgen project is non-compliant at this point. We are also not sure if the proofs could be simply made available publicly or offered for free to anyone who requests them. We are happy to collaborate with the procurement and OSPO teams in your organisations to explore funding opportunities. Custom requestsMost answers and information needed must already be available in this repo or in discussions. If you need any specific responses from the core team, you can email support at appthreat dot com. Please note that all such requests are chargeable with a minimum of one hour (£100 + VAT), regardless of whether you are an existing sponsor or not. If in doubt, do not email regarding compliance. |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Based on currently available information:
Tasks
Full text from the regulation
Relevant section from https://www.europarl.europa.eu/doceo/document/TA-9-2024-0130_EN.html#def_2_1
References
Beta Was this translation helpful? Give feedback.
All reactions