• pirat@lemmy.world
    link
    fedilink
    English
    arrow-up
    6
    ·
    12 hours ago

    Unfortunately, I think this plays into the EU Cyber Resilience Act, and the developer verification is how Google is trying to comply with it…

    Distributors and importers must verify that products comply with CRA standards before selling them. They must review technical documentation, ensure that software does not have known vulnerabilities and comply with update obligations. They must work with vendors to report vulnerabilities and request patches. Finally, they must conduct audits to ensure continued security over time.

    […] Finally, the resilience of mobile apps must be verified through regular testing.

    Source: https://www.mobisec.com/en/regulatory-compliance/cyber-resilience-act-dispositivi-applicazioni-mobile/