New compliance obligations coming soon
Quick heads-up on the EU Cyber Resilience Act (CRA), because it may become relevant for people building and selling software, plugins, apps or digital products in the EU.
This is not βanother regulation for every websiteβ.
If you use a plugin like FluentCart on your own site, you are normally not the manufacturer of that product.
But if you develop and sell your own plugin, app, SaaS, AI tool or digital product under your own brand, the situation may be different. The CRA introduces cybersecurity-by-design obligations, vulnerability management, support periods, technical documentation, a vulnerability contact point, and reporting duties for actively exploited vulnerabilities or serious security incidents.
Full application starts in December 2027, but incident/vulnerability reporting obligations begin in September 2026.
Curious if the FluentCart / WPManageNinja team is already mapping how the CRA may apply to WordPress plugins sold in the EU. It could be an interesting topic for plugin makers over the next year!
Canβt wait to see the next FC updates!
Thanks for keeping us aware π
Agree. It would be great to know if the Fluent plugins are intended to be CRA compliant.
Come to think of it, it would also great with a similar list for which Fluent plugins that are intended to be GDPR compliant (so we know if GDPR issues are classified as bugs or feature requests). Shahjahan JewelΒ
Karl Emil NikkaΒ I was under the impression they are all GDPR compliant, without certain AI functions.
Maude VuilleΒ Iβve only tried FluentCommunity and FluentCRM. FluentCommunity is far from GDPR compliant. FluentCRM is almost GDPR compliant when correctly configured, as long as you only have one list or use e.g., FluentForms for subscription management. From what I can see, FluentCommunity isnβt marketed as GDPR compliant, at least not in the WordPress repo (where FluentCRM is marketed as GDPR ready, not GDPR compliant).
