Standard Reader
cio

CIOs are put to the test as security regulations across borders recalibrate

CIO.com

Mary Writes
May 14, 2026 · 1 min read
1

've had people call me naive, but I'm really quite enthusiastic about the CRA.

I spent quite a while asking people about the CRA this year and, outside security and supply chain conversations, getting blank looks, so I was delighted to see it come up in the #Kubecon keynote.

And after having spent so long saying that I know I sound naive but that I still think the CRA is an opportunity to give organizations an incentive to fund and contribute to open source better, I'm glad to know I'm not the only one - even if we're cynical about how well it survives contact with capitalism. Maybe like GDPR, the CRA will get mirrored by similar legislation around the world, although there's little sign of that yet.

  • cybersecurity
  • vulnerability
  • SBOMs
  • open source
  • EU
  • regulation
Mary Writes
Mary Writes
@marypcbuk.bsky.social
BlueskyDiscussion