Book

Manufacturing European Software

by Daniel Thompson-Yvetot

This book has a name for compliance that satisfies a regulator without making software any safer: cybersecurity theatre. Under the Cyber Resilience Act, following the rules could fall short of actually achieving them.

← Back to shop

Written for product leaders, engineering leaders, and non-technical stakeholders shipping software into the EU.

Manufacturing European Software walks product people, developers, and software leaders through the CRA and the revised Product Liability Directive, then names exactly where the two regimes’ good intentions collide with how software actually gets built and secured. The CRA tells you what to do; the rPLD tells you what you owe if something goes wrong.

Why it matters

The CRA asks manufacturers to report vulnerabilities. The regulation sidelines decades of established practice (CVSS, CVE, GitHub Security Advisories) and risks building a slower, parallel reporting system instead of strengthening the ones that already work. It exempts open-source stewards from the hard compliance requirements, but that exemption does nothing to help them claim a CE mark of their own. Voluntary attestation schemes meant to fill that gap are built to serve proprietary software’s needs, not to make open source itself more secure. It assumes a supply of conformity assessment bodies that will not exist in sufficient numbers for years, leaving some manufacturers waiting up to three years for a CAB contract before they can legally place software on the EU market. None of this makes the CRA wrong to exist. It makes it something to navigate deliberately rather than assume it will work exactly as written.

What is inside

  • The regulatory landscape: the CRA and rPLD in detail, with the regulatory context of GDPR, NIS2 and the AI Act.
  • The CRA’s classification of “important” and “critical” products with digital elements, and what changes once a product falls into either category.
  • A 7-step process for placing software on the market, from readiness through Declaration of Conformity to publishing.
  • A STRIDE-based playbook for cybersecurity risk assessments and a walkthrough of the new EU Software Bill of Materials (SBOM) regime.
  • “Cybersecurity Theatre”: several named failure modes in the CRA’s reporting and certification design, from its disregard for established vulnerability tools like CVSS and CVE to the multi-year bottleneck in conformity assessment capacity.
  • The “Brussels Effect”: how GDPR, the DMA, and the AI Act are already reshaping law and product design outside the EU, illustrated through Japan’s Digital Antitrust Law, California’s 2024 AI legislation, and the July 2024 CrowdStrike outage.

Who is it for

Product owners, engineering and software leaders, and other non-technical stakeholders who need to make real decisions about a product’s compliance without being a lawyer or a security engineer.

Written by Daniel Thompson-Yvetot ("Denjell"), cofounder of the Tauri project and CEO of CrabNebula and Comply.Land, and special rapporteur for CRA Standards.

If you need advice tailored to your product, reporting process or compliance obligations, our CRA experts can help you identify the appropriate next steps.

Contact a CRA expert