我们发现了什么
我在德国经营一家一人 GmbH。一人公司承担的义务与大型公司相同。
- 来源:Hacker News(发现于 2026-09-02)
- 证据等级:D · 发现产品或需求信号,暂未获得可核验的商业证据。
- 商业模式:Marketplace / 佣金
- 主题:独立产品
- 初筛评分:17.2/100 · 收录 1 次
证据,比故事更重要。
规则清洗与初筛,未经人工商业核验。原文语境、实际客户和付费情况仍需自行验证。
引用与数字披露
来源类型(原作者自述/第三方测算/媒体转引)需采集端标注,本版尚未落字段。
- 作者
- 未标注
- 抓取日期
- 来源类型
- 未标注
- 币种
- 未标注
- 口径
- 未标注
- 披露主体
- 未标注
- 披露日期
- 未标注
中文辅助译文(全文)
我在德国经营一家一人有限责任公司(GmbH)。我正在考虑为一款现成的掌上设备销售固件——离线、没有 WiFi、没有编译进任何网络栈、通过 USB 重新刷写来更新。我不卖硬件,只卖软件。结果发现,欧盟《网络韧性法案》(Cyber Resilience Act, CRA)适用于我。欧盟开始把软件产品按与硬件产品类似的方式来处理,CRA 对此进行了规范(从客户的角度来看——这是理所应当的!)。报告义务从今年 9 月开始生效;其他所有条款则从 2027 年 12 月起执行。因此我花了些时间阅读原始资料而非各种评论文章:法规本身 ,以及欧盟委员会 2026 年 7 月 27 日发布的指南 (C(2026) 5252,约 80 页,包含 67 个示例,明确面向中小企业)。以下是我目前了解到的情况,也是我希望得到指正的地方:1. 销售软件现在等同于销售硬件。同样的制度——技术文档、符合性声明、软件上的 CE 标志。我原本以为 CE 是针对硬件的;在 CRA 下不再如此。2. 我无法通过免费赠送软件来规避它。豁免适用于在商业活动之外提供的开源——免费与非商业并不相同。我为支持我所售产品而发布的固件,无论我是否为此收费,都显然属于商业活动。3. 没有规模门槛。一人公司与大公司承担相同的义务。第 33 条的标题是"对微型企业和中小型企业的支持措施",其每一条规定都是帮助,而不是豁免。4. 但实际工作量并不大。我的产品不在附件 III 中,所以是自我评估:无需公告机构、无费用、无需提交任何文件、没有任何人审批。工作似乎就是一次写好的一小批文档。基本上就是自己贴上 CE 标签。
5. 但存在第 13(9) 条。每发布一次安全更新,必须在你发布后 10 年内或剩余支持期(以较长者为准)保持可下载。对于一款 2027 年发布、可能只卖一次的产品来说,这意味着要一直维护到 2040 年代,是相当长的一段时间。6. 报告义务不会随支持期结束而终止。指南中明确说明(第 210 段):漏洞处理在支持期结束时停止,但报告义务在此后仍然继续。我先写到这里,但还有另外几层含义。啊,在你问之前:重要的不是你住在哪里,重要的是你向欧盟销售。简而言之:我没有找到任何处理这些事务的"独立开发者"来源,所以我主要的问题是——还有其他人正在为此做准备吗?如果有,你们是怎么处理的?尤其希望听到那些在小规模下实际经历过这种情况的人,或者任何来自市场监管机构的人的声音。https://eur-lex.europa.eu/eli/reg/2024/2847/oj https://digital-strategy.ec.europa.eu/en/library/commission-publishes-new-guidance-support-timely-cyber-resilience-act-implementation
译文由上游机器翻译生成,可能有误;判断请以英文原文为准。
英文原文(来源本站未改写)
I run a one-person GmbH in Germany.I am thinking about selling firmware for an off-the-shelf handheld - offline, no WiFi, no network stack compiled in at all, updates by reflashing over USB.I don't sell hardware, just software.Turns out that the EU Cyber Resilience Act applies to me.The EU starts to handle software products similar to hardware products and the CRA regulates that (and from a customer's standpoint - rightfully so!).Reporting duties start this September;everything else in December 2027.
So I spent some time reading the sources rather than the commentary: the Regulation itself , and the Commission's guidance of 27 July 2026 (C(2026) 5252, around 80 pages with 67 worked examples, explicitly aimed at SMEs).This is what I found out so far, and this is where I'd like to be corrected: 1.Selling software now works like selling hardware.Same regime - technical file, declaration of conformity, CE marking on a piece of software.I'd assumed CE was a hardware thing;with the CRA not anymore. 2.I can't escape it by giving the software away.The exemption is for open source supplied outside commercial activity - free isn't the same as non-commercial.
Firmware I publish to support a product I sell is plainly commercial, whatever I charge for it. 3.There's no size threshold.A one-person company carries the same obligations as a large one.Article 33 is titled "Support measures for microenterprises and small and medium-sized enterprises" and every provision in it is help, not exemption. 4.But the actual work is small.My product isn't in Annex III, so it's self-assessment: no notified body, no fee, nothing filed, nobody approves anything.The work seems to be a handful of documents I write once.You basically stick the CE label on by yourself. 5.But there is Art. 13(9).
Every security update you ship has to stay available for 10 years after you issue it, or the rest of the support period, whichever is longer.That's a serious amount of time into the 2040s for a product launched in 2027, maybe sold only once. 6.Reporting obligations don't end when support does.The guidance is explicit (para 210): vulnerability handling stops with the support period, reporting continues afterwards.I'll stop here, but there's a couple more implications.Ah, and before you ask: it doesn't matter where you live, it matters that you sell to the EU.
In a nutshell: I didn't find any 'indie' sources dealing with these matters, so my main question is - is anyone else preparing for this scenario?If so, how do you handle it?Especially interested in anyone who has actually been through this at a small scale, or anyone from a market surveillance authority. https://eur-lex.europa.eu/eli/reg/2024/2847/oj https://digital-strategy.ec.europa.eu/en/library/commission-publishes-new-guidance-support-timely-cyber-resilience-act-implementation
这条还缺什么证据?
下面每条都由本条已有字段推出(等级、理由、商业模式、来源次数、是否演示), 本站不生成推测性结论;通用验证方法放在方法论页。
- 可核验的收入或付费证据查官网定价页与付费口径;第三方数据源(如 GetLatka)只作旁证,需标注来源与时点。
- 只有单一来源找一手站点或其他渠道是否重复出现同一产品;社区热帖数量不等于商业进展。
通用验证清单(谁有这个问题/谁愿意付费/一个人能交付哪一小步)见我们的筛选方法。