liu.seSearch for publications in DiVA
3839404142434441 of 105
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • oxford
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
The Cyber Resilience Act: Life Jacket or Weighted Vest?: Regulatory Uncertainties when Integrating Free and Open-Source Software and Balancing Regulatory Burdens for Manufacturers and Innovations from Free and Open-Source Software  
Linköping University, Department of Management and Engineering, Commercial and Business Law. Linköping University, Faculty of Arts and Sciences.
2026 (English)Independent thesis Advanced level (degree of Master (Two Years)), 20 credits / 30 HE creditsStudent thesisAlternative title
Cyberresiliensförordningen: Flytväst eller viktväst? : Regulatorisk förutsebarhet vid integrering av fri- och öppen källkod samt balansering av regelbördor för tillverkare med innovationer från fri- och öppen källkod (Swedish)
Abstract [en]

The EU faces extensive cyberthreats in which products with digital elements (PDEs) constitute a weakness in the interconnected society. To face these challenges the EU has introduced the Cyber Resilience Act (CRA). The CRA holds a comprehensive regulatory approach as it applies horizontally to all PDEs and imposes various obligations on manufacturers. Simultaneously, the widespread use of Free and Open-Source Software (FOSS) presents significant challenges. FOSS refers to a specific type of software which is community driven and can be accessed, modified, and redistributed for free. The FOSS community is underfunded resulting in frequent cybersecurity vulnerabilities. This is particularly problematic considering FOSS components are often integrated into commercial PDEs, constituting weaknesses in supply chains. The widespread use of FOSS entails that a single vulnerability can be exploited simultaneously across multiple entities, potentially causing far-reaching damage. This thesis examines whether the CRA adequately addresses cybersecurity vulnerabilities originating from FOSS while balancing regulatory burdens for manufacturers and innovations from FOSS.  

Furthermore, the thesis examines if provisions regarding the integration of FOSS components in commercial PDEs provide sufficient regulatory certainty for manufacturers. The thesis provides both descriptive and critical analysis of the regulatory burdens imposed on manufacturers while evaluating the reasonableness of these obligations. The thesis focuses in particular on the "commercial activity criterion" and the due diligence requirement. The thesis concludes that there are regulatory uncertainties relating to these provisions, especially regarding the term "intention to monetize" within the "commercial activity criterion" which creates interpretative challenges. Similarly, the due diligence requirement lacks clarity regarding both what mandatory measures manufacturers must undertake and at what point this obligation is considered fulfilled. Furthermore, the analysis reveals that the CRA in its current form relies largely on standards that have not yet been fully formulated, creating implications which may threaten both the existence of FOSS and the implementation of the CRA. 

Place, publisher, year, edition, pages
2026. , p. 56
Keywords [en]
CRA, FOSS, Cyber Resilience Act, Cybersecurity, PDE, Products with digital elements, Free and Open-Source Software, Commerciality, Due diligence, Commercial Activity Criterion, Vulnerabilities, Regulatory burdens for manufacturers
Keywords [sv]
Cyberresiliensförordningen, Fri- och öppen källkod, Digitala produkter, Cybersäkerhet, Uppkopplade produkter, Kommersiell aktivitet, Regelbördor för tillverkare
National Category
Law
Identifiers
URN: urn:nbn:se:liu:diva-223259ISRN: LIU-IEI-FIL-A--26/05191--SEOAI: oai:DiVA.org:liu-223259DiVA, id: diva2:2055432
Subject / course
Master Thesis in Commercial and Business Law
Supervisors
Examiners
Available from: 2026-05-04 Created: 2026-04-24 Last updated: 2026-05-04Bibliographically approved

Open Access in DiVA

The Cyber Resilience Act: Life Jacket or Weighted Vest?(601 kB)5 downloads
File information
File name FULLTEXT01.pdfFile size 601 kBChecksum SHA-512
bbbc31c829c344be0d79b9c9971f22f6aaa242dfd90a47a6e18b946995535f4c3e31978f44c8cbfb41c44e63e2bef0ae94b6fb9aa6108812a327000b13ee01c7
Type fulltextMimetype application/pdf

By organisation
Commercial and Business LawFaculty of Arts and Sciences
Law

Search outside of DiVA

GoogleGoogle Scholar
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 55 hits
3839404142434441 of 105
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • oxford
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf