Introduction
The Cyber Resilience Act (CRA) has sparked debate around free patches and whether it signals the end of enterprise subscriptions. In reality, the regulation focuses on how manufacturers charge for required security updates, not on eliminating commercial support models. This post breaks down what the CRA actually requires versus common interpretations.
What Happened
Author Sebastian Martinez Torregrosa clarifies that CRA's free of charge mandate applies specifically to security updates, not to the broader product or subscription framework. The article identifies three widespread misconceptions: the support period isn't always five years, the regulation extends beyond European vendors, and tailor-made software has specific exceptions. Each point is grounded in the regulation's text and the European Commission's guidance.
Why This Matters
For enterprises and open-source vendors, the distinction is practical. The CRA doesn't prevent selling subscriptions, support plans, or implementation services. It simply prohibits turning a mandatory security fix into a separate paid product. This affects how companies structure entitlement, pricing, and customer communication especially for enterprise Linux and other commercially supported open-source platforms.
Key Takeaways
- Security updates required by the CRA must be disseminated without delay and generally free of charge.
- Vendors may still charge for subscriptions, support, consulting, and other commercial services.
- The five-year minimum support period applies only if the product is expected to be used that long; shorter expected use cases warrant shorter periods.
- The CRA applies to any in-scope product made available on the EU market, regardless of the vendor's location.
- Tailor-made software and non-commercial open source receive distinct legal treatment, but neither automatically escapes CRA obligations.
Conclusion
The CRA is product cybersecurity law, not a mandate to give away software. It ensures users get timely fixes without extra fees, while preserving vendors' rights to commercialize their offerings. Understanding the boundary between product entitlement and security-update obligation helps businesses stay compliant and keep their models sustainable.




Discussion
Join the conversation
Thoughtful reactions, questions, and follow-up ideas help shape the next story.