Computing covers a wide spectrum, from hardware components to regulations governing software security. Measuring the state of the sector requires comparing what has changed recently: new legal obligations, the evolution of online learning tools, and the increasing demands for cybersecurity in digital products. This article places the data side by side to identify the gaps that matter.
Cyber Resilience Act and NIS 2: Comparative Timeline of Digital Obligations
Two European texts are reshaping the rules for anyone who manufactures, distributes, or uses IT products. The Cyber Resilience Act (CRA) and the NIS 2 directive have different scopes and timelines, but their effects accumulate.
| Criterion | Cyber Resilience Act (CRA) | NIS 2 |
|---|---|---|
| Entry into force (EU) | December 2024 | October 2024 |
| Next major deadline | September 2026: reporting of exploited vulnerabilities and serious incidents | National transposition pending in France |
| Full requirements | December 2027 (CE marking, risk analysis, technical documentation) | Depends on the French transposition law |
| Main targets | Manufacturers, importers, and distributors of any product with digital elements (software, connected objects) | Essential and important entities (administrations, digital service companies, cloud providers) |
| Regulatory body (France) | Cofrac (accreditation) and ANSSI (notification) | ANSSI |
The CRA transforms cybersecurity into a prerequisite for market access. Every computer, software, and connected object sold in Europe will need to prove its compliance. For users, this means documented security updates and monitoring of vulnerabilities throughout the product’s lifecycle.
Following computing with Info Geeks allows you to keep an eye on these regulatory developments that affect both professionals and individuals.
NIS 2, on the other hand, targets organizations that operate digital services. In France, legislative transposition has been delayed. The text has not yet been voted on by Parliament, creating a gap between the European obligation and the applicable national law. The affected companies are therefore navigating a temporary legal gray area, but ANSSI is already recommending preparation.

Cybersecurity News: What the CRA Changes for Everyday Software
Most articles on computing treat cybersecurity as a topic reserved for network administrators. The CRA shifts the focus: it directly concerns consumer software publishers, including word processing tools, web browsers, and mobile applications.
Mandatory Reporting of Vulnerabilities Starting September 2026
From this date, any manufacturer or publisher will have to report actively exploited vulnerabilities and serious incidents, even for products already on the market. This is not a theoretical obligation: compliance assessment bodies accredited by Cofrac will conduct technical audits.
For users, the direct consequence is a better traceability of security flaws in the software they use daily. Publishers who do not comply risk having their products removed from the European market.
CE Marking Extended to Software in December 2027
The CE marking, previously associated only with physical devices, will also apply to software. The compliance assessment will include documented risk analysis and complete technical documentation. Small publishers of free or open-source software will also need to position themselves regarding these requirements.
Learning Computing Online: Tools and Learning Levels
The offering of online computing courses has structured itself in recent years around three distinct levels. Comparing these levels helps to choose the right entry point without wasting time on unsuitable content.
- Beginner Level: getting to grips with a computer, file management, internet browsing, using word processing. Platforms often offer these modules for free to attract new learners.
- Intermediate Level: mastery of advanced office software (spreadsheets, presentation tools), introduction to digital data, configuring the security of a workstation. Paid courses generally start at this stage.
- Advanced Level: system administration, networking, programming, applied cybersecurity. Learning at this level relies on practical environments (virtual machines, online labs) rather than just theory.
A often overlooked point: cybersecurity is no longer a topic reserved for the advanced level. With the CRA and NIS 2, concepts of updating, password management, and recognizing phishing attempts now fall under the basic foundation.

Free Software and Digital Tools: Selection Criteria in Light of New Standards
The common reflex is to look for free software for word processing, image editing, or data management. The question of cost needs to be considered alongside compliance.
A free software distributed in Europe will be subject to the same CRA obligations as a paid software starting December 2027. This means that publishers of free tools will have to provide technical documentation on the security of their product. Some small open-source projects may not have the resources to conduct these assessments, raising questions about their continued presence in the European market.
When choosing software, three criteria become more relevant:
- The frequency of security updates published by the publisher over the past twelve months
- The existence of a vulnerability disclosure policy (dedicated page on the publisher’s website)
- Compatibility with the social networks and cloud services used, without unsupported third-party extensions
Google, for example, publishes a monthly security bulletin for its products. This type of transparency will become a differentiating factor among publishers as the CRA comes fully into effect.
The computing landscape in the coming years will be shaped by these regulatory constraints as much as by technical innovation. For both individuals and professionals, the ability to read a product security policy will become as common as knowing how to browse the internet. September 2026 marks the first concrete deadline of the CRA, and it is at this date that regulatory theory will transform into verifiable obligations.



