Hi there,
Thanks for asking. We’re aware of the EU Cyber Resilience Act and are actively preparing for it. GeneratePress is actively maintained and we already run a coordinated vulnerability disclosure and patching process, which covers much of what the CRA is concerned with. We’ll take the necessary steps to meet any applicable requirements ahead of the relevant deadlines.
We don’t have a CE conformity declaration published yet, as the obligations that would require one aren’t yet in application. If one is required for GeneratePress, we’ll make the appropriate documentation available in due course.