Skip to main content

New compliance obligations coming soon

Quick heads-up on the EU Cyber Resilience Act (CRA), because it may become relevant for people building and selling software, plugins, apps or digital products in the EU.

This is not β€œanother regulation for every website”.

If you use a plugin like FluentCart on your own site, you are normally not the manufacturer of that product.

But if you develop and sell your own plugin, app, SaaS, AI tool or digital product under your own brand, the situation may be different. The CRA introduces cybersecurity-by-design obligations, vulnerability management, support periods, technical documentation, a vulnerability contact point, and reporting duties for actively exploited vulnerabilities or serious security incidents.

Full application starts in December 2027, but incident/vulnerability reporting obligations begin in September 2026.

Curious if the FluentCart / WPManageNinja team is already mapping how the CRA may apply to WordPress plugins sold in the EU. It could be an interesting topic for plugin makers over the next year!

Can’t wait to see the next FC updates!

Thanks for keeping us aware πŸ™‚

Karl Emil Nikka

Agree. It would be great to know if the Fluent plugins are intended to be CRA compliant.

Karl Emil Nikka

Come to think of it, it would also great with a similar list for which Fluent plugins that are intended to be GDPR compliant (so we know if GDPR issues are classified as bugs or feature requests). Shahjahan JewelΒ 

Maude Vuille

Karl Emil NikkaΒ I was under the impression they are all GDPR compliant, without certain AI functions.

Karl Emil Nikka

Maude VuilleΒ I’ve only tried FluentCommunity and FluentCRM. FluentCommunity is far from GDPR compliant. FluentCRM is almost GDPR compliant when correctly configured, as long as you only have one list or use e.g., FluentForms for subscription management. From what I can see, FluentCommunity isn’t marketed as GDPR compliant, at least not in the WordPress repo (where FluentCRM is marketed as GDPR ready, not GDPR compliant).