What does the EU Cyber Resilience Act mean for PostgreSQL and its users?

Peter Eisentraut

April 2026

peter@eisentraut.org
https://peter.eisentraut.org/
@petereisentraut@mastodon.social

peter.eisentraut@enterprisedb.com
https://www.enterprisedb.com/
@edbpostgres@mastodon.social

Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act)

Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act)

Applies to

products with digital elements made available on the market, the intended purpose or reasonably foreseeable use of which includes a direct or indirect logical or physical data connection to a device or network

(CRA Art. 2)

Exceptions

Further exceptions

“important” and “critical” products

⇒ does not affect PostgreSQL

Important dates

Agencies and institutions

“Manufacturer”?

a natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under its name or trademark, whether for payment, monetisation or free of charge

(CRA Art. 3)

“Open-source software steward”

a legal person, other than a manufacturer, that has the purpose or objective of systematically providing support on a sustained basis for the development of specific products with digital elements, qualifying as free and open-source software and intended for commercial activities, and that ensures the viability of those products

(CRA Art. 3)

(Source: Draft Commission guidance on the Cyber Resilience Act)

Manufacturer/steward examples

company that sells PostgreSQL or variants with support manufacturer
company that sells (only) training or consulting for PostgreSQL neither
company that sells PostgreSQL DBaaS neither
company that does not sell any services around PostgreSQL but develops an open source software for internal use and also offers it for download steward
Cloud Native Computing Foundation → Linux Foundation steward
PostgreSQL Europe association steward (?!?)
Software in the Public Interest (SPI) steward
PostgreSQL Core Team neither
PostgreSQL Security Team neither
individual PostgreSQL hacker neither

Obligations of manufacturers

(excerpt; CRA Art. 13)

Essential cybersecurity requirements

(excerpt; CRA Annex I Part I)

Vulnerability handling requirements

(excerpt; CRA Annex I Part II)

Conformity assessment and declaration

Reporting obligations of manufacturers

(excerpt; CRA Art. 14)

(24h)

from 11 September 2026!

Obligations of users

Voluntary reporting

(CRA Art. 15)

Obligations of open-source software stewards

(CRA Art. 24)

Security attestation of free and open-source software

In order to facilitate the due diligence obligation set out in Article 13(5), in particular as regards manufacturers that integrate free and open-source software components in their products with digital elements, the Commission is empowered to adopt delegated acts in accordance with Article 61 to supplement this Regulation by establishing voluntary security attestation programmes allowing the developers or users of products with digital elements qualifying as free and open-source software as well as other third parties to assess the conformity of such products with all or certain essential cybersecurity requirements or other obligations laid down in this Regulation.

(CRA Art. 25)

Software bill of materials (SBOM)

Homework for manufacturers

(for next 6 months)

Homework for PostgreSQL project

(support for manufacturers)

Links

Bye / Questions / Contact

peter@eisentraut.org
https://peter.eisentraut.org/
@petereisentraut@mastodon.social

peter.eisentraut@enterprisedb.com
https://www.enterprisedb.com/
@edbpostgres@mastodon.social