Submind YouTube summaries
Thumbnail for FrOSCon 2025 - Cybersicherheit in der Gesellschaft

FrOSCon 2025 - Cybersicherheit in der Gesellschaft

Watch on YouTube

Video summary

The presentation by representatives from the Free Software Foundation Europe and the Federal Office for Information Security focused on the Cyber Resilience Act (CRA) and its implications for digital products within the EU. This legislation mandates that networked devices must maintain security standards throughout their entire lifecycle, including mandatory vulnerability reporting and updates until end-of-life support is complete. While the act generally applies to most CE-marked devices, it includes a specific exception for free open-source software (FOSS) developers, though commercial distributors of such software are still classified as manufacturers responsible for compliance. The discussion highlighted significant ambiguities regarding the transition from project maintainers to manufacturers, particularly concerning monetary thresholds and living expenses, which has led some projects to preemptively remove code out of fear of liability when facing demands for rapid fixes from manufacturers. To address these uncertainties and undefined aspects in current guidance documents, such as Software Bill of Materials formats and resource requirements for security auditors known as "Stuarts," the speakers launched a questionnaire to gather feedback on real-world challenges. The overarching goal is to foster collaboration between manufacturers and open-source projects without overburdening developers or stifling innovation, ensuring high security standards against large-scale threats rather than targeting small entities. Regarding product lifespans, while a five-year liability period is the general rule, it is not absolute; manufacturers determine intended lifespans, and market surveillance plans to issue guidelines extending support for long-life products like trains. Furthermore, although manufacturers can choose their own risk assessment methods, courts ultimately judge compliance against the law itself, making adherence to harmonized standards crucial as proof of conformity. The operationalization of the "Stuart" role requires manufacturers to decide whether to integrate projects directly or collaborate with maintainers, a process that must be negotiated per product to ensure safe CE marking. Since operating systems like Linux are not standalone products but become so when integrated into a system, the resulting system requires a CE mark, whereas software like LibreOffice currently lacks one, forcing companies using it to manage their own cybersecurity insurance risks. Ongoing discussions with insurers, such as Zurich, aim to assess these specific risks. Looking toward the future market structure, a state-run approach is discouraged in favor of self-regulation through private funding. Proposed models include a collective society or fund where beneficiaries of free software contribute financially, ensuring that projects without direct manufacturer ties can still participate and receive funding based on ecosystem value and risk factors.
Read the full video transcript
Welcome to Talk Z: Cybersecurity in Society, presented by Alex and Michael. Alex works for the Free Software Foundation Europe and Michael for the Federal Office for Information Security. We are delighted with the presentation. Thank you very much. Yes . Um, we met here about a year ago, almost exactly a year ago, and we exchanged ideas about the Cyber ​​Resilience Act and then planned to submit a project as part of the dialogue for cybersecurity , where we would work on the Cyber Resilience Act. We will now briefly explain at the beginning how we came to this and what this dialogue is. Then we'll briefly go through the Cyber ​​Resilience Act so that we all have roughly the same level of knowledge, and then we'll look at what we've been doing in the last year and, uh, what we've been working on regarding the Cyber ​​Resilience Act , what's on our minds, and then try to discuss that with you in the last third of this event . Exactly . Thanks. So, the dialogue for cybersecurity is a platform where organized civil society, state, business, cultures, girls and science come together and are basically a platform organized by the BSI to work collaboratively on social issues that address cybersecurity and attempt to consider the whole thing holistically. For this purpose, a so-called think tank is held once a year. For this purpose, interested parties can collect and develop ideas, and I believe the period is about to begin, which can be submitted, where topics can be presented that will then be worked on for a year in a larger group. These would then be the so-called workstreams. And I first participated in the dialogue for security two years ago because I hadn't been at the BSI for very long, and Alex had been doing it for several years before, and we got talking last year at Froscon . At some point the question came up: we still have a barrel of beer here, what do we do with it? Um, the exchange became more and more intense, and then we thought, let's see if we can bring up a topic, and one topic that has been on both our minds for several years now is the Cyber ​​Resilience Act. And when you're at the Frost Conference, at the Frost Conference, you talk about things up there here and there. That means let's bring this together and see what effects, or rather , what effects the Cyber ​​Resilience Resource Community has in its various forms, which is always interesting. Exactly . What is the Cyber ​​Resilience Act? And in principle, this is legislation that was passed last December, is now in the transition phase for 3 years, before all the requirements contained in the Cyber ​​Residency Act have to be implemented from December 11, 2027 onwards; there are already reporting obligations for next year in September that have been brought forward. This means that manufacturers who actively exploit vulnerabilities, or who become aware of them, or who gain knowledge of them, must report them to the reporting platform and to the national certifying body responsible for the manufacturer, in order to track and monitor these vulnerabilities. The Cyber ​​Resilience Set is the EU's attempt to obtain CE marking for cybersecurity. This means that what already exists for safety, such as mobile phones with their CE marking indicating that you won't die immediately if you pick them up , is now being expanded to include cybersecurity. This applies to products, or almost all products, with digital elements. The robot vacuum cleaner, operating systems, mobile phones, routers – basically anything that is networked to some extent and communicates digitally with other things. There are certain exceptions, such as medical technology, aerospace, and automobiles, because these are already significantly regulated, at least to the same extent or more so, through other regulations . And there is an exception, for example, for free open source software. The goals of the CAA, or what the Commission and the EU intend to achieve with it , are, firstly, that products placed on the European market meet security requirements from the outset, or are generally more secure in terms of cybersecurity, and secondly, that the devices remain secure or are repeatedly returned to a secure state for the entire life cycle of the product, including the support period. This means that a manufacturer never brings the product to market and then no one cares anymore. He is obligated to provide updates and address vulnerabilities . The second point is that it should be made easier for those who use the products to use, buy, and then obtain safe products. What does all this mean for a manufacturer and for a product? The manufacturer starts developing a product and must conduct a risk analysis right at the beginning, where he looks at how strongly he needs to implement certain requirements . These are the product-related basic security requirements that are set out in Annex 1 of the Cyber ​​Resilience Act . And that means it contains requirements, e.g., it wants secure authentication to be used . It states that secure communication is essential. This means that data transferred from one device to another is transferred securely. It says inside that data is stored securely. However, it all depends on the risk. That means if I have products that are in more critical environments , then it might be interesting that when you log in or access the site , you don't just enter a username and password, but use multi-factor authentication. It might be that with certain products that exist only once in the world and were sold on the market, you could leave it somewhere in the room in the darkroom where nobody else goes because it's locked three times; then a username and password would suffice. So it always depends on the risk. As mentioned, vulnerabilities must be fixed during the support period . There must be technical documentation . Manufacturers must demonstrate compliance with the requirements before they can bring their products to market . For most products, this is simply a self-explanatory statement. These are also things that we already have under the CE marking. There are also important products in categories 1 and 2. These include, for example, operating systems, routers, and firewalls in their various versions. There, the approach to conformity is slightly different. The important products can be tested once at a designated point to prove that they meet all safety requirements. And for the important category 1, where, for example, switches or routers are included. If there are harmonized standards that have been cited by the Commission, then it is sufficient for a manufacturer to say, "I will adhere to this harmonized site and declaration." That's why location is relatively important in all legislation. Security flaws must be rectified, and the manufacturer must report any vulnerabilities for as long as the product exists. Something that comes up alongside the Cyber ​​Resilient Act, or is mentioned as a term, is the New Legis Legis Framework. And that is basically the idea of the Commission and the EU: to harmonize the entire legislation to some extent . Imagine it as a huge network of regulations, all interconnected in some way, and none of them stands alone in the forest. In general, it regulates how, for example, market surveillance should proceed, and what all the processes are. It regulates the meaning of harmonized standards and norms, what conformity assessment procedures look like, all regulations are set out in the New Legislative Framework , which is quite important because I often experience in discussions that many people always consider the CAA in relative isolation. But it belongs to this whole construct of other laws that also exist, which are somehow related to each other . This also means that things we already do for safety, and things that generally apply to safety, can also be applied to the CA to some extent . That is, for example, um, interesting. The CH itself is a product regulation. That is, what's interesting is what it means that it's a product for and when I have to comply with the things that are in the CA. And then there's the so-called Blueegide, which is basically a tool that tries to explain certain things about the NLF, the New Legislat Framework, to a certain extent. And it says, for example, that... Making a product available on the market means any supply of a product for distribution, consumption or use on the Union market in the course of a commercial activity, whether for consideration or without limit. And then we quickly reach the point where this exception for Free Open Source comes into play. These are not products that are placed on the EU market in terms of regulation, and therefore they are excluded. These are not products where someone simply sticks a CE label on . There are manufacturers, including open-source manufacturers, who earn money with their open-source products and have a commercial activity. In this case, it's considered a product under the regulations, and they are seen as manufacturers. They must meet all the requirements of the CA (Certificate of Authorisation). However, a developer who simply develops open-source software in their free time because they enjoy it, and there can be several developers working together on the project , doesn't automatically fall under the CHA (Certificate of Authorisation) exemption. Regarding consumer protection, if it's sold on the European market , it's considered a product and therefore treated as such. Exactly . Yes, we've already heard from Michael about manufacturers and that this is a product regulation. Uh, that all makes perfect sense. However, we have also heard that there are perhaps different perspectives regarding free software, and the legislator has taken this into account to some extent and has introduced different roles in the legislative process. So, obviously, we have the manufacturer, and then he also introduced Stuart, which in German is called administrator . These are the people who, um, well, um, projects, um, for example, Men or similar, and then there's the aforementioned exception: Individual Developers, uh, a bit of code somewhere on some Git or something else. So, basically we have three roles relevant to the Cyber ​​Resilience Act, but only two roles. The manufacturer and Stuart. So, Stuart is someone who provides a project, which is then taken by a manufacturer and ends up in a product . And so that these people who work on the project, who do it in their free time, who perhaps also do it for donations, in the common association or however you come together to create these projects, so that they are not confronted with the regulations of the Cyber ​​Resilience Act in the form of having to assume these obligations. Um, as someone just said, the manufacturer has to, um, always assume all the obligations at some point. So, everything that falls outside the scope of the Cyber ​​Resilience Act, he has to take over for the projects, and that means it's not simply taken and followed somewhere else, but rather, in principle, a relationship has to develop between the manufacturer and the project team, and that's the question we discussed with a consultant last year . What could this uh relationship look like? So how can we ensure that manufacturers and Stuarts communicate in a way that is good for safety, but also good for the price within the ecosystem? And, um, yes, we've essentially asked ourselves this question, and we've approached the whole thing, and perhaps we'll first look at what the obligations are for manufacturers, and then we'll see that many things simply cannot or should not be done by the ST duart, and then we'll consider how it could be done. So, the manufacturer is fundamentally responsible for the product. Yes, well, it is always the manufacturer who brings a product to market and they are responsible for everything that has to do with that product . He needs to address the weaknesses. If he is collaborating on a project, he must report the vulnerabilities to that project and he must also share the patch. This means, um, that if you're basically sitting on your project , you don't actually have to do anything except wait for a manufacturer to come along. The manufacturer then says to you, "I'm using your project, it's in my product, and uh, would you like to become Stuart for me?" And then this workflow would begin, right? So, the project would receive the patches, and they would then basically be available to everyone else as well . So, that means, um, if you have a project in a product and it gets patched there, is the patch still available for everyone else? Exactly . But as I said, all these things are the responsibility of the manufacturer, but of course the manufacturer can't do it alone. So he has to communicate with this project somehow. The patch has to actually get there somehow in the end. Yes, so there must be someone in the project who does that. And um, if you look at how manufacturers envision it, then I think you can see that clearly with KL . Um, they just received an email. That means, well, we 're manufacturers, we use CL by the way, um, we now have to become compliant. Go ahead and do it. Yes, and that's exactly what we don't want. Yes, we don't want manufacturers to approach projects and say, "This is what will be incorporated into our product, and because our product is so great, you'll help us now." Yes, but it has to happen in some way, so that the ST is keen on it, so that he is keen to work with the manufacturer and so that this exchange can take place, which we have just shown. So, in order for the manufacturer to be put in this position to do this, he needs Stuart, and therefore it makes perfect sense that they are kind to each other , yes, and not just kind in the sense that they send each other back and forth in a friendly manner , but that resources are perhaps also made available . Yes, so basically, Stuart must or can, so to speak, immediately help the manufacturer to fulfill these obligations. If he does that, then in my opinion at least he should be supported . And that's a question we've been asking ourselves, so to speak, about um, uh, questions. So, we've published questionnaires, we'll get to that in a moment, to see where this is already working in the ecosystem , where we can take blueprints and then transfer them into guidelines, because that is, um, let me just finish this thought briefly, the central point is that not everything is happening in a vacuum. We have the Cyber Resilience Act, which contains many articles and regulations, and so on and so forth, but many questions remain unanswered. Yes, and for these unanswered questions there are guides. There are these standards we've already heard about, which are particularly relevant for manufacturing. There are things like ATT, there are implementing Acts, delegated Acts, and so on and so forth. Much of the Cyber Resilience Act is still not fully fleshed out. Among other things, this relationship, how manufacturers and Stuarts are currently working together. Yes, manufacturer Stuart, as it has now been explained by me, is the issue that manufacturers now only use resources very quickly, of course, there is a risk that you yourself become the software manufacturer , because we are suddenly commercial and profitable, and that means the manufacturer offers me, so to speak, here you also get a little money for getting a bank. Now you are a manufacturer. Okay, so the question was, or rather, the comment was, what happens when the manufacturer provides resources to the project, which was previously not monetarily involved, especially monetary resources, and whether Stuart then also becomes a manufacturer, because so to speak the money game begins, and um, well, that 's not the case, because it's not a product. Yes, well, the project isn't a product in itself, but rather, nothing is actually being manufactured, right? It's just that there's code lying around somewhere, which will then be patched somehow, but nothing is actually being sold right now, right? Therefore, no product will be sold. So. Well, um, and therefore you wouldn't become a manufacturer right now, and maybe you'll even go back later . So you're always just for, well, that's also important to know, so a Stuart, um, wo n't itself be CE compliant or anything like that. Yes, so it's always about one specific product. So, for example, you could now work with Stuart and a manufacturer . The manufacturer has two products. Regarding one product, you say, "I think it's a great product, I'll work with you." With the other one you say, no, I don't feel like it , I'm not a Stuart. So, and all of this , what is still unclear is, uh, fundamentally, where the monetary threshold is. So, from what point does one become a Stuart, so to speak, up to what point can one earn money without being considered a manufacturer? This hasn't been spelled out yet, but there is, um, a discussion point, we can perhaps say, which suggests that the threshold is, um, what your living expenses are. So, if you're doing this as a private individual , the threshold is roughly what your living expenses are, and the second threshold is when you're bigger, to make the thing run. Yes, so what you need, uh, to keep the project from dying, so that it survives and fulfills these, um, things. If you start making billions from this , then we might need to take another look, but overall it's fine for now , so these are the thresholds that are currently being discussed. So the project continues. There may also be an expert group convened by the Commission, and there is also a working group that deals with obsourcing, and these questions are currently being examined there as well, because you cannot have both roles, meaning no one can be both for a product at the same time. You can have both roles, but you can never be both the manufacturer and the starter for a product. And it is not intended that once the sword is paid for, he automatically becomes the manufacturer, and guidance is currently being written by the Commission on this, and that is one of the points related to the Implementing Act. Something needs to be published by the Commission this year that clarifies how the Commission views this and describes these roles more precisely . Um, if I'm now, so to speak, a project, then maybe we could briefly ask some questions to clarify things, but perhaps the discussion should be left for the end. Um, because otherwise I think we could now, well, I see so many hands, um, that I think otherwise there would be questions of understanding. Yes, unfortunately I arrived too late. Well, a product, if I offer a server or service that I can start, is already a product, or a CLI tool, or Liberoffice, or something like that. It can be used independently by anyone who downloads it from the internet. Is this already a product ? So, we had that at the beginning. Provides a definition; perhaps you should also take a look at the slides. Exactly. Now we're going to make whales. Um, exactly. So, as I said, there is what we stand at now, and what's also important is that there are things like Implementing Acts, Delegated Acts, which can come, which don't have to come, but Implementing Acts, which must come. For example, the question that is often discussed is: what should the SBOM look like? This is an Implementing Act; it will be passed, and you will get these answers then. We ca n't tell you yet; we have feelings about it , but nothing more than that. Um, Geidens is something that comes from the Commission, but perhaps also from the market surveillance authority, which then spells out, for example, where these limit values ​​are? Um, how much money can you earn? Uh, like which, um, and that's certainly something one can expect, is that this guidance will also use many examples. Yes, so in order to clearly define what is a project, what is a manufacturer, and so on and so forth, this guide will certainly include examples. And with these documents, the basic idea is that someone who has no clue reads and understands them and knows, okay, all right, I am now a manufacturer, I am now Duart, and so on. It is, so to speak, the process. Yes, well, all of this is still in the works. So this is exactly the implementation that is taking place now. We've already heard that we'll hear about these thresholds by the end of the year . Um, uh, and this will continue until 2027. Um, to get closer to this, this, this mess, so to speak, and above all, to contribute to this guidance. I think that's particularly important for us as an FSVE, because we don't really pay that much attention to what the manufacturers are doing. I believe they can usually stand up for themselves. We're looking at what's happening with the projects, what's happening with individual developers, and so on and so forth. Yes, and that's why we asked ourselves the question: how does the manufacturer communicate with Stuart? But what other questions are out there? So, what problems are there? What niches are there? What are the different types of hair removal zones? Where, where, where are things that would make any of you read the Cyber ​​Resilience Act and think, " Wow, what does that mean for me?" That's why we sat down as part of this dialogue for maritime safety and developed a questionnaire which can currently be filled out until the end of the month. We started in July and now, what comes next is primarily the feedback we've received in the last month. We want to circulate this with you all a bit and see what you think. And overall, we would of course also like to encourage you to fill out the questionnaire now in the next, um, current month , so that we can then, so to speak, continue working with your results . And our goal is basically to get these results, especially here, into this guidance. Yes, so we want to find out what your problems are and address them in this guidance so that you ultimately have a document you can look at and say, "My example is mentioned," or "I find myself reflected here in some way and know how I should act within the framework of the CA in the future ." Yes, and that's why we created questionnaires for manufacturers, projects, and potential open source Stuarts . Yes, and where you roughly find yourself, you fill out a questionnaire like this . If you're unsure, you might want to consider potential open source options. The questions are more or less similar. You do n't have to fill out the entire questionnaire . So, if you're unsure about something, if you don't know what to do at any point , just leave it blank. And what is particularly important to us is that it utilizes the free spaces. Also, write in there what, so to speak, if there are any questions that were missing or if you want to tell us anything else , use the question fields to explain to us what the problem is for you, so that we can ultimately include it in this guidance and thus solve this lack of clarity and help you understand who you are and what you have to do. Exactly . And um, another point we have at the very bottom: we are also in contact with certain or several foundations that are already actively dealing with the Cyber ​​Resilience Act . We talk to representatives of the European Commission to pass these things on to them and simply name examples and where there are questions, because these are also initial things that we are doing and also when we hold talks. With open source, there are things we've all never thought of, and there are projects that collaborate in that way . You learn something new every day. And when the law was being developed and written, the commission did indeed talk to an incredibly large number of people . But in the end, as mentioned above, it's just that small point again, and certain things have been added for that purpose, and now we have to see where everyone knows what the text looks like, how to promote it externally so that it works for everyone else, and that they know what they have to do if they have to do anything. So, as I said, a project in itself must comply with the Cyber ​​Resilience Act; if no tangible product in a monetary sense comes out of it, they don't have to do anything. If they don't want to become a start, they wo n't be a start. If they never want to talk to a manufacturer, then they don't have to. But what we want, or what interests us, is what happens if someone wants to do this? How can we—and this is again part of the guidance—what kind of guidance can we provide if someone wants to take on this role, if someone prepares their project in such a way that it already fulfills many things that a manufacturer would then have to fulfill? Because conversations with manufacturers that we have sometimes go like this: they use an incredibly large number of projects. They simply can't look after all of them. They don't have the resources either . They are completely responsible for it. That means they have to do something. Now you can go to someone who will take care of it . One can try to remove the open source projects from one's product and replace them with components purchased from elsewhere, products that have been bought on the market, because these products have to meet the CA requirements, then I can simply move everything a little further along, but that also costs money. So, in other words, why do n't we create some kind of collaboration where resources and funds are paid to those who are already working on their project all day anyway? If I'm going ahead with the project , there's someone there who might be able to do all that, and then that's okay too. But it is quite possible that someone will then take care of the abandoned project and do certain things correctly again. We do have weaknesses, and that happens sometimes . Why don't we support those who are originally working on it, if that's what they want? As I said, a project in itself does n't need that. If they don't feel like it, they simply don't feel like it, period. And we need to make sure that things like what happened to Körl don't help anyone. If 100 manufacturers come and say, "You have two weeks, please fill out the Excel spreadsheet." At some point, someone quickly gets fed up with the project and says, "I'm quitting , I'm not continuing at all." This is also the case, and it helps if manufacturers have guidelines on how to get in touch. And there's already a lot of it, and you just need to process it all, bring it together in such a way that you have something uniform that several people can work with. Uh, I have a question regarding STRS. Can there be multiple versions of an open-source project? No. So, the question was, can there be more "you" for an open source project? No. The answer was no. Not planned. This has opened up an unbelievable mystery. Perhaps, as I said, we should move this back to the discussion section and try to make some progress on the content first. Exactly . So, uh, as I already said, we have this questionnaire, this survey has been running for a month now, and it's important for us to give you a little preview of some initial results, to see what we've gotten so far. It is definitely, um, I think it's evident that we can see tendencies, that certain things keep recurring and, um, um, certain problems are repeatedly identified by different participants . The goal now, and this is not our position, yes, it's not irrelevant whether it's right or wrong, but it's about presenting this first and then having a little discussion afterwards and seeing what you think about it and whether you have any corresponding opinions. Exactly . So the points we recorded are simply random individual answers to the questions we have, where we now think, firstly, you can see to some extent what really interests us. So, let's start with the first question. A few Developbar members are working together on the project without any single entity or developer behind it . Those who work on the project are paid by companies, and then, as stated here, a company offers services related to this project. What does this mean in the context of the CA? Those who work on the project are then automatically considered manufacturers. And at first glance, one might say no, then one might say again, but if you as a manufacturer work on it, won't they fall down after all? I have an opinion on that, but these are the things we would like to consider in guidance , because there will be guidance from the Commission. It may be that the biggest questions have already been answered here, but it may also be that additional things will come up in the project examples, and what we have considered or where we want to go, so that we can look at how to simply go through these examples step by step with the Commission's guidance and other documents . In this case, it's simply a handful of people working together. So, no manufacturer. They're being paid now. What does that mean? No manufacturer or producer. Then you have to find something, and hopefully you can do that using the Commission's guidelines, so that you can simply work your way through these example projects to some extent and explain why they are considered manufacturers, or why they are not considered manufacturers, or why they are considered starters. That's one of the songs. And what you generally see now is with the second one. The second and third actually belong together. Someone is working on the project and then a manufacturer comes along with a deadline of z weeks. I've found a vulnerability; you need to fix it for me now. If I had a project, I probably wouldn't want that. And you can see that there are already certain fears in the Open Source Commuter community regarding the projects that these projects deal with, and that such a question or such an answer came up several times. And in the end, it also helps if there is guidance that explains whether they even need to do that. Perhaps a note on that. So I did a random sample and it was a bullseye: Kobit has taken the project off the network. Recourse. Yes, definitely . Yes . Yes, we can see that. So, the point was that projects are already ceasing to make their materials available, so to speak, out of preemptive fear of a cybersecurity crisis. And another question: did you also send the questionnaire to the manufacturers, i.e., associations? Yes, yes, yes, yes. You continue. Exactly . Then there are people asking questions of the manufacturer. There we asked questions such as, what dangers do you see if you are responsible for all Opensur-free components in the product? And what do you do with projects where you do n't know if they already meet the requirements of the Cyberilience Act, especially if you can't then step in to do that, or whatever other issues there are in general? And then, already in the first point, that manufacturers are also considering what they can do. And these are also things that we see that way. Projects are being requested. Either you can take on the support yourself, or you can support the project and then simply provide the things the manufacturer needs for the project so that they can integrate it and meet all the requirements, so that they then take it over for the project and play along with the feedback. Here too, one has to see if that can work, and scaling is another matter entirely, but there are already considerations and discussions on that, and sometimes it feels as if the discussions are being conducted in parallel without being brought together . One question, for example, was whether it would help if there was proof that projects meet this requirement. And there's another point, um, that the manufacturers can't do it themselves because they would need the resources to do it for all the products that are inside their product. And the point is, the proof would have to come from the open source manufacturers themselves . So, if we now – and we see that several have written this – if these are the fears of manufacturers, then we are back at the point where we cannot initiate things in such a way that the manufacturer pays, receives the certificate that the product is okay, and ends the matter with them. The third are the Stuarts, and then we're back to Guidance. There are also many who have answered the questions; they know relatively precisely whether they want to be Stuart or not. So, we assume that some Foundation employees also contributed to the responses, and in many places it is relatively clear that the role of the Jewers is being taken over there. Where support is needed is the question of who should pay for it if someone wants to become a Stewart and does become a Stewart, and what does it really mean? What requirements must a Stuart fulfill in accordance with the CHA in order to avoid further problems with market surveillance and nothing else? It must be said that a pilot in itself has significantly fewer requirements to meet than a manufacturer, and no penalties can or will be imposed on pilots. What? He must report weaknesses. The vulnerability reporting process for actively exploited vulnerabilities is therefore taken from the manufacturer's articles or requirements . He must have a cyber security policy and he must cooperate with market surveillance. It must always be in mind if he doesn't do it. There are no penalties, but um, he has to cooperate with the market surveillance authority so that things can be fixed. I think what also came up often, uh, is uh, tools, is definitely something that people really want to see. Um, so they want to see text, they want tools to help them, resources, money, whatever. Yes, and also to elaborate on this understanding of roles and to see if it might be useful to allow dual roles in one or more places. So these are the points that we have repeatedly seen in the questionnaires, but also generally in many discussions that we are having, especially with projects, to understand the market realities to some extent and to see how this can then be incorporated into guidance. Exactly . So, I think to reiterate what underlines the whole thing, well, um, from the questionnaires we would say that approximately 50% of people know their role and can assess it fairly well. That's nice, of course, but also bad. So fifty-fifty years, right? It's somewhere in the middle, whether that's good or bad. Um, we definitely see that, uh, especially projects, individual developers, so everything that isn't a manufacturer, feel a certain pressure to do something, and it's a bit vague for them what exactly that should be. Um, and how do you get there, and above all, where do the resources come from to do it? Um, we also hear things like, which I thought was a very apt sentence, "Like to do Software Engineering, not management, right?" So, people do n't usually start their projects because they want to deal with big management issues , uh, but rather they just want to tinker with their project, right? And that, of course, is something that needs to be preserved. So we don't want to ensure that everyone who starts a project is then busy with some strange paperwork , but rather that people can just get on with their work. Um, the problem is, as we just said, we're looking a bit at blueprints, so where is this already happening? Where are projects somehow connected to manufacturers? Where is there already resource exchange where we support this? Um, and we can definitely see across the board that this is not cost-effective in any way . So it's not like the projects are getting so much money that they have to worry about whether they're manufacturers, but rather they're thinking, can we keep the project alive with the money we're getting here? So the support currently in place is often lower than the actual costs. This is the current reality we are facing. Um, what we've also heard repeatedly is a feared loss of quality in projects. This is primarily a practice recommended by manufacturers. So, they're kind of afraid that if they collaborate on these projects, they might be able to do things like quality assurance and stuff. So, they have, um, problems there, and also a few other things that keep coming up, like what about the overall research environment ? Fear of costs. Yes, well, everyone seems to have that on their wallet . Um, the S-bomb question is something that keeps people thinking about, right? So there's another implementing act for that as well. It's still being defined, uh, there's simply nothing yet. And then, um, yes, things like supply chain attacks, licensing problems, those kinds of issues are also on people's minds. So it's not like, uh, that it has n't appeared, so to speak. Therefore, as I said, there are a few other things as well. So, if you filled out the questionnaire and do n't see yourself reflected here, we still looked at everything, but these are the relevant points for us, uh, that we have identified so far. And that's why we're appealing to you again: if you feel that your position isn't reflected here, please let us know in the questionnaire. This helps us to address this as a problem to the Commission, for example, and to get it included in these guidelines, in order to address the problem and, ideally, to solve it. And now, I think I can say this for both of us , the feeling is definitely that we are being heard and that there is a real attempt being made to clear up such problems. Yes, so nobody wants to ruin anything by over-regulating, nobody wants to ruin projects, nobody wants to ruin SMEs or micro- enterprises, that's not the goal at all . Perhaps one could take another look at it, similar to what was done with the data protection reform. It's not about somehow taking the small baker around the corner out of the market, but it's about going against Google and Facebook, that sort of thing. And this Sabe security legislation should be viewed in a similar way. It's about taking a closer look at the junk that comes onto our market, especially where a lot of junk is mass-produced, and not just some small project cobbled together by two manufacturers, right? So, perhaps at the end, there will also be a market supervisory authority. Yes, I'll just have to take a look at it. These are also people who have resources available to them . Uh, that means they'll naturally be looking at where they can get a lot of money, where they can create, um, so to speak, big examples that might then appear in the media, so that other manufacturers see, oh, oh, oh, the market surveillance system really does monitor things, maybe I should do a bit more cyburity myself. That's the thinking behind this law and what will realistically result in the end. Yes, it's not going to be the case that the BSI (Federal Office for Information Security) is going to hire 2000 people who then spend all day wearing market surveillance jackets in the media market. That's never certain; maybe someone else will do it, right? But no, these aren't realistic scenarios where the entire media market is somehow cleared out and every product is scrutinized from one day to the next. Yes, exactly. So, to reiterate the question , what happens next? For us, the next step is definitely to continue evaluating this questionnaire. Uh, we will take these results, try to bring them into play , try to talk to the Commission , try to get in touch with other market regulators. Uh, here's another request: please fill out this questionnaire. Find it at dialog-cyicherheit.de/aktuelles, because it's current, it 's definitely current. Uh, and like I said, tell us about your project, tell us about it, tell me about it, tell me about it, send us an email, I don't know, write about it on social media. So, we just showed you this K project, right? Things like that help. If you're doing something like that , if you're a project and a manufacturer approaches you in a really strange way, publish it. Then we can go to the commission and say, look, this is reality. This cannot continue. These people will never become Stuarts . And so to speak, there is a great interest on the part of the people who made the law that as many people as possible become Duarts, otherwise the whole concept doesn't really work. Um, and that is of course a positive situation for us, in which we can ensure that this Duarts, that the projects ultimately benefit from it. Yes, so that is our goal here, what we are pursuing. And um, finally, as I said, if you have any direct contacts, use them. So, if you happen to meet people from the BSI (Federal Office for Information Security), tell them. Um, if you happen to meet commission officials or anything like that, talk about it, try to make it tangible and understandable somehow, and like I said, show us your niches, okay? Um, that helps us to understand them and, if necessary, illustrate them with examples . In that sense, I think we can all have a nice beer today and then meet up again next year. Until then, we'll definitely answer a few more questions, discuss things with you a bit, and we probably won't be quite so early today and tomorrow, but we'll still be there. Um, uh, talk to us, talk to us, and otherwise all the best. [Applause] Exactly. And I think, uh, you'll help us with the moderation. Yes. Uh, exactly. So there are people walking around with microphones. Please wait until it's available for the stream. um, so that the questions are clear for the people who are joining online, so that they understand what it's all about. So, uh, we now have just under 10 minutes for the Q&A session and uh, can we get started right away? So, the important thing is that the questions are also included in the stream, and if, for example, the microphone is difficult to reach, then please repeat the questions again. Now I would say I'll first go a bit by topic, or that the people who raise their hands have a suitable connection to the question, and otherwise I would go by seating position. Good. Um, who has questions? So, from here on out, we already said earlier that we are allowed to... We have a question about what you had on the slides at the beginning, regarding the deadlines, so there is this wording in the CA with 5 years or so to speak the lifetime, the intended lifetime of the product. Um, the manufacturer determines that; the intended lifespan is determined by a roll of the dice . Um, can he always do 5 years or how does that work? So, if I buy an airplane, how long is the 5-year liability period? The idea is that the 5 years are a general rule for now, unless there are compelling reasons why it is shorter. So, yes, there are products that simply don't last as long as insulin, but there are certain products that aren't even around for 5 years. There are already products where the life cycle and support period are longer because other regulations stipulate different timeframes. The plan is for market surveillance to look over the years at what the expected support period should be, and then issue guidelines on when these periods should be extended. So, 5 years is now the final term. This may change over the years for certain product categories. So a train will certainly be looked at for longer than 5 years. Yes, but we have another question for you, which might be quite good: as a manufacturer, can I choose my own risk assessment methodology and the standard or whatever I use for it? People from Herrneller have already told me, "I want to take this, I want to take this." Complete overgrowth. What does everyone know about this? Basically , you can do whatever you want if you believe you are following the law. I would rather make sure that I follow Geiden's standards, because then I can always say that it came from the Commission and the BSI and they wrote down how it's done, and if you stick to it, you're not on the safe side either, a court can still say, yes, the standard is nice, what you wrote down there, but it's not in accordance with the law. So, in the end, the court looks at the law, and if you can prove that you abide by the law and the court believes you. So, this is partly why standardization is currently so important, because if there is a harmonized reference site, then manufacturers producing products in important Class 1 can declare themselves compliant with this standard . And when he was quoted, the Commission said that, from our point of view, what is written there is sufficient to demonstrate conformity if it is followed . And the more uniform or harmonized the standards are, the better, then the manufacturers or many manufacturers will follow them, in the Commission's view; they don't have to. Harmonised standard cites harmonised standard. Yes, it's my turn. Do you have a question? Yes . Yes, I have a simple question. So now you basically have four roles in your game. This is the user, this is the manufacturer. I would prefer to call them the integrator; then it's the project, they're the ones who write the software. And now the fourth new role is added, that is Stuart. How can the role of the tax officer be operationalized? That is the question. Yes, because it seems relatively new to me. So, to reiterate, it's not a free software law, right? It 's a product regulation, and then at some point it was discovered that products also contain free software, and so this law specifically addresses the issue of what happens to free software. There are also manufacturers who never have anything to do with a project and yet still make free software. Yes, so maybe that's a basic understanding, so to speak. And then, at the end of the day, if I 'm a manufacturer and I access projects that end up in my product, the first question I have to ask myself as a manufacturer is: should it stay that way? So, basically, do I need this, do I have to do this, do I want this? And then I can ask myself, for example, if I follow this, then I have nothing to do with the project, I take care of it myself , um, I do n't have to integrate or rationalize or anything else. And at the moment I, as the manufacturer, decide to collaborate on the project, I have to find a way with the project so that in the end I, as the manufacturer, can say that I can safely put a CE marking on it, and for that I have to put Stuart in a position to help me so that I can do that. And that's how you operationalize it. So, for each product, a manufacturer will come along and say, "For this product I need a Celebel; I'm using the one from your project. How do we get there?" And then this one product gets a CE label for this one specific process. And how that looks in each case, that's something to be negotiated, I would say. OK. We have about 5 minutes left, right? I see three or four messages right now. I don't really know. Um, I can't really commit to anything right now . You can then ask questions in the hallway, for information, and I don't know how they respond so cheerfully. The other one was also short. Yes, a good example is that system integrators often use Linux in their systems. Um, that would have to have a CE mark , that Linux. Uh, where is a CE- certified Linux distribution supposed to come from? Linux itself is not a product, but as you said, operating systems are within the scope of Cass. Yes, but it's not a product in itself. So it only becomes a product when you do something with it, anything at all. Okay, then we'll use the word processor LibreOffice. If I want to use this in my company because I want to save on licensing costs . However, it doesn't yet have a CE mark, and my Cyburity insurance company requires me to only use C-marked products. Then you need to consider what to do with your cybersecurity insurance. So I would say the probability of Lebro Office simply having a C license plate slapped on it is relatively low, and if you want to use the software , nobody is stopping you from using it. Just because they want to use them with Census symbols does n't mean the software has to put a Census symbol on them. If someone requests this and makes it available in a commercial context , then that person can become a manufacturer and then they can say, "This is a modified Libraoffice with trademarks." Dramatic. I don't think this product is really safe. Uh yeah, just one comment on this matter. So, there are already a few talks underway with insurance companies . So I personally had talks with the reinsurance company in Zurich, and the people from the Open Chain process are discussing things with the people in London. So I believe the problem will eventually resolve itself outside of this area. So, yes, it's a well-known problem, that can be insured. So the insurance people want to know what the risks are, and they can't assess that yet. So that's due to us, for example, not you. So, to roughly demonstrate these risks. If we behave properly, the costs will be low; if not, they will be high. Also, bring the traffic category sign. Yes . Yes, you have to multiply that by two messages. We hardly have any time left. I don't really know. Okay, I'd like to make a brief comment. So, work is underway and currently in progress . That means if you 're a manufacturer and you say, "I distribute my browser" or "I distribute my operating system" and you're worried that there's nonsense in there," then find out more. They're working on this, they're looking for employees with expertise who really know what's going on, and you should make sure you can exert influence, because now's your chance to help shape these standards . So, anyone who is worried that a business model will go under, in two years the train will have left the station. And it's really not terribly difficult, uh, if you want to get involved, to be able to get involved . So, the doors are definitely open. This relationship between Stuart and the companies that bring products to market could, to make a very, very unpopular parallel, be handled through a kind of collecting society. In other words, companies buy a kind of insurance for a specific open source project, which can then rise or fall with the product's value to the company and with the risk factor of the respective project, and the company then receives money, or the project receives money to bring this product, or rather the sub-product, to market and make it usable for the companies. So, my personal opinion on this is, I don't think we should build some kind of state-run structure there . I think the market can regulate this to some extent on its own. I also think it's important that private money is involved in this game. Um, and then I could definitely imagine something like this: there's a fund into which people pay, and then there's something like a Nutrcore on the other side, and then you can see whether a company is financing into the ecosystem or not. And these funds are primarily channeled into projects that don't have a particularly good relationship with the manufacturer, but still want to participate in the process. But, uh, so to speak, this, as I said, this: how does money get to whom, when, and where? Um, that's a problem that I think many people see, uh, how it's solved. There are few concrete proposals. As I said, I personally find it important that this is primarily about private money , meaning that those who benefit from free software should support those who make it available . So, this principle should generally be adhered to . That's how the law came about . Of course, there are also state actors who benefit from free software, and they must also contribute, but overall I see the market participants as being responsible for providing the resources . Okay, that's the end of it. Many thanks again to Alex and Michael. Yes, thanks.