EU ์‚ฌ์ด๋ฒ„ ๋ณต์›๋ ฅ๋ฒ•(CRA) ์ทจ์•ฝ์  ๋ณด๊ณ  ์˜๋ฌด โ€” 2026-09-11 ์‹œํ–‰ ๋Œ€๋น„ ์กฐ์‚ฌ๋ณด๊ณ ์„œ

EU ์‚ฌ์ด๋ฒ„ ๋ณต์›๋ ฅ๋ฒ•(CRA)์€ 2026๋…„ 9์›” 11์ผ๋ถ€ํ„ฐ ์ œ14์กฐ ๋ณด๊ณ  ์˜๋ฌด๋ฅผ ์‹œํ–‰ํ•œ๋‹ค. ํ•œ๊ตญ ๊ธฐ์—…์ด 24์‹œ๊ฐ„ยท72์‹œ๊ฐ„ยท14์ผ ํ†ต์ง€ ์‹œํ•œ๊ณผ SBOMยท์ ํ•ฉ์„ฑ ํ‰๊ฐ€์— ์–ด๋–ป๊ฒŒ ๋Œ€๋น„ํ•ด์•ผ ํ•˜๋Š”์ง€ 1์ฐจ ์ถœ์ฒ˜ ์ค‘์‹ฌ์œผ๋กœ ์ •๋ฆฌํ•œ๋‹ค.

์š”์•ฝ EU ์‚ฌ์ด๋ฒ„ ๋ณต์›๋ ฅ๋ฒ•(Cyber Resilience Act, CRA โ€” Regulation (EU) 2024/2847)์€ EU ์‹œ์žฅ์— ์ถœ์‹œ๋˜๋Š” ๋ชจ๋“  “๋””์ง€ํ„ธ ์š”์†Œ๋ฅผ ๊ฐ€์ง„ ์ œํ’ˆ(product with digital elements, PDE)“์— ์ˆ˜ํ‰์  ์‚ฌ์ด๋ฒ„๋ณด์•ˆ ์˜๋ฌด๋ฅผ ๋ถ€๊ณผํ•˜๋Š”, EU ์—ญ์‚ฌ์ƒ ์ฒซ ํฌ๊ด„์  ์ œํ’ˆ ๋ณด์•ˆ ๊ทœ์ •์ด๋‹ค. 2024๋…„ 12์›” 10์ผ ๋ฐœํšจ๋œ ์ด ๊ทœ์ •์€ ๋‹จ๊ณ„์ ์œผ๋กœ ์ ์šฉ๋˜๋ฉฐ, 2026๋…„ 9์›” 11์ผ๋ถ€ํ„ฐ๋Š” ์ œ14์กฐ ๋ณด๊ณ  ์˜๋ฌด๊ฐ€ ๋ฐœํšจ๋˜์–ด ์ œ์กฐ์‚ฌยท์ˆ˜์ž…์‚ฌยท์œ ํ†ต์‚ฌ๊ฐ€ ์‹ค์ œ ์•…์šฉ ์ค‘์ธ ์ทจ์•ฝ์ ๊ณผ ์ค‘๋Œ€ํ•œ ๋ณด์•ˆ ์‚ฌ๊ณ ๋ฅผ 24์‹œ๊ฐ„ยท72์‹œ๊ฐ„ยท14์ผ ์‹œํ•œ ์•ˆ์— ENISA(์œ ๋Ÿฝ ์‚ฌ์ด๋ฒ„๋ณด์•ˆ์ฒญ)์™€ ํšŒ์›๊ตญ CSIRT์— ํ†ต์ง€ํ•ด์•ผ ํ•œ๋‹ค. ์ด ๋‚ ์งœ๊นŒ์ง€ ๋ณด๊ณ  ์›Œํฌํ”Œ๋กœ์šฐ๊ฐ€ ๊ฐ€๋™๋˜์ง€ ์•Š์œผ๋ฉด ์ตœ๋Œ€ 1,500๋งŒ ์œ ๋กœ ๋˜๋Š” ์ „ ์„ธ๊ณ„ ์—ฐ๊ฐ„ ๋งค์ถœ 2.5%์˜ ๊ณผ์ง•๊ธˆ ์œ„ํ—˜์ด ๋ฐœ์ƒํ•˜๋ฉฐ, ํ•œ๊ตญ ๊ธฐ์—…์ด๋ผ๋„ EU ์‹œ์žฅ์— ์ œํ’ˆ์„ ์ถœ์‹œํ•˜๋ฉด ์ฆ‰์‹œ ์ ์šฉ ๋Œ€์ƒ์ด ๋œ๋‹ค. A1ยทB1ยทE1


1. ์™œ 2026-09-11์ด ํ•œ๊ตญ ๊ธฐ์—…์— ์ค‘์š”ํ•œ๊ฐ€

์˜ค๋Š” 2026๋…„ 9์›” 11์ผ์€ CRA ์ œ14์กฐ ๋ณด๊ณ  ์˜๋ฌด์˜ ์ฒซ ์ ์šฉ์ผ์ด๋‹ค. ์ด๋‚  ๋™์‹œ์— ENISA์˜ ๋‹จ์ผ ๋ณด๊ณ  ํ”Œ๋žซํผ(Single Reporting Platform, SRP)๋„ ๊ฐ€๋™๋œ๋‹ค. A1ยทB4 CE ๋งˆํ‚น๊ณผ ์ ํ•ฉ์„ฑ ํ‰๊ฐ€ ๋“ฑ CRA์˜ ๋‚˜๋จธ์ง€ ๋ณธ์งˆ ์˜๋ฌด๋Š” 2027๋…„ 12์›” 11์ผ์ด ์‹œํ•œ์ด์ง€๋งŒ, ๋ณด๊ณ  ์›Œํฌํ”Œ๋กœ์šฐ๋งŒํผ์€ ๊ทธ๋ณด๋‹ค 15๊ฐœ์›” ์•ž์„œ ๊ฐ–์ถฐ์•ผ ํ•œ๋‹ค.

ํ•œ๊ตญ ๊ธฐ์—… ๊ด€์ ์—์„œ ์ด ๋‚ ์งœ๊ฐ€ ๊ฐ–๋Š” ์‹ค์งˆ์  ์˜๋ฏธ๋Š” ๋‹ค์Œ๊ณผ ๊ฐ™๋‹ค. CRA๋Š” EU ํšŒ์›๊ตญ์ด ์ œ์ •ํ•œ ์ง€์นจ(Directive)์ด ์•„๋‹ˆ๋ผ EU ์ง์ ‘ ํšจ๋ ฅ์˜ ๊ทœ์ •(Regulation)์ด๋ฏ€๋กœ, ๋ณ„๋„์˜ ๊ตญ๋‚ด ์ดํ–‰ ์ž…๋ฒ• ์—†์ด EU ์‹œ์žฅ ์ง„์ž… ์ฆ‰์‹œ ์ ์šฉ๋œ๋‹ค. A1 ํ•œ๊ตญ์— ๋ณธ์‚ฌ๋ฅผ ๋‘๊ณ  EU ๋ฒ•์ธ ์—†์ด ์ง์ˆ˜์ถœํ•˜๋”๋ผ๋„ ์ ์šฉ ๋Œ€์ƒ์—์„œ ๋ฒ—์–ด๋‚˜์ง€ ๋ชปํ•œ๋‹ค. ๋ ˆ๊ฑฐ์‹œ ์ œํ’ˆ, ์ฆ‰ ์ด๋ฏธ EU ์‹œ์žฅ์— ์ถœ์‹œ๋œ ์ œํ’ˆ๋„ ํฌํ•จ๋œ๋‹ค๋Š” ์ ๋„ ์ฃผ์˜๊ฐ€ ํ•„์š”ํ•˜๋‹ค. E1

2026๋…„ 5์›” ํ˜„์žฌ ์ „์ฒด ์‹œํ–‰๊นŒ์ง€ ์•ฝ 4๊ฐœ์›”์ด ๋‚จ์•˜๋‹ค. ENISA๋Š” ์‹œํ—˜ ๊ธฐ๊ฐ„(testing period)์„ ๋‘๊ฒ ๋‹ค๊ณ  ๋ฐํ˜”์ง€๋งŒ ๊ณต์‹ ์ผ์ •์€ ๊ณต์‹œ๋˜์ง€ ์•Š์•˜๊ณ , API ์‚ฌ์–‘๊ณผ ์ธ์ฆ ๋ฐฉ์‹๋„ ๊ณต๊ฐœ๋˜์ง€ ์•Š์€ ์ƒํƒœ๋‹ค. B4 ํ†ตํ•ฉ ์‹œํ—˜์„ ๊ฑฐ์ณ SRP์— ์—ฐ๊ฒฐํ•˜๋ ค๋ฉด ์‚ฌ์–‘ ๊ณต๊ฐœ ์ฆ‰์‹œ ์ฐฉ์ˆ˜ํ•ด์•ผ ํ•˜๋Š” ์‹œ๊ฐ„์  ์••๋ฐ•์ด ์žˆ๋‹ค.


2. CRA์˜ ๊ตฌ์กฐ

2.1 ์ž…๋ฒ• ๋ฐฐ๊ฒฝ๊ณผ ๋ฐœํšจ ์ผ์ •

CRA์˜ ๊ณต์‹ ๋ช…์นญ์€ Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements๋‹ค. 2021๋…„ 9์›” ์šฐ์–ด์ค„๋ผ ํฐ ๋ฐ์–ด ๋ผ์ด์—”(Ursula von der Leyen) ์œ„์›์žฅ์˜ ์—ฐ๋‘๊ต์„œ์—์„œ ์ฒ˜์Œ ์˜ˆ๊ณ ๋œ ๋’ค, 2022๋…„ 9์›” 15์ผ ์œ ๋Ÿฝ์œ„์›ํšŒ(European Commission)๊ฐ€ ์ž…๋ฒ•์•ˆ์„ ์ œ์•ˆํ–ˆ๋‹ค. ์œ ๋Ÿฝ์˜ํšŒ๋Š” 2024๋…„ 3์›” 12์ผ ๋ณธํšŒ์˜์—์„œ ์ฐฌ์„ฑ 517ํ‘œ, ๋ฐ˜๋Œ€ 12ํ‘œ๋กœ ์ฑ„ํƒํ–ˆ๊ณ , ์ด์‚ฌํšŒ(Council)๊ฐ€ ๊ฐ™์€ ํ•ด 10์›” 10์ผ ์ตœ์ข… ์ฑ„ํƒํ•ด 10์›” 23์ผ ์„œ๋ช… ํ›„ 11์›” 20์ผ EU ๊ด€๋ณด์— ๊ฒŒ์žฌ๋๋‹ค. ๋ฐœํšจ์ผ์€ 2024๋…„ 12์›” 10์ผ์ด๋‹ค. A1ยทB1

%%{init: {'theme':'default', 'themeVariables': {'fontSize':'18px'}, 'flowchart': {'nodeSpacing': 30, 'rankSpacing': 40}} }%%
flowchart LR
    A["<b>2021-09</b><br/>CRA ์˜ˆ๊ณ "] --> B["<b>2022-09</b><br/>์ž…๋ฒ• ์ œ์•ˆ"]
    B --> C["<b>2023-11</b><br/>์ž ์ • ํ•ฉ์˜"]
    C --> D["<b>2024-03</b><br/>์˜ํšŒ ์ฑ„ํƒ<br/>(์ฐฌ์„ฑ 517ยท๋ฐ˜๋Œ€ 12)"]
    D --> E["<b>2024-12-10</b><br/>๋ฐœํšจ"]
    E --> F["<b>2026-09-11</b><br/>๋ณด๊ณ  ์˜๋ฌด + SRP"]
    F --> G["<b>2027-12-11</b><br/>์ „๋ฉด ์ ์šฉ"]
    style F fill:#fff3e0,stroke:#ef6c00,stroke-width:2px
    style G fill:#e8f5e9,stroke:#2e7d32,stroke-width:2px

๊ทธ๋ฆผ 1. CRA ์ž…๋ฒ•ยท์‹œํ–‰ ํƒ€์ž„๋ผ์ธ (์ถœ์ฒ˜: Regulation (EU) 2024/2847, EC ์ž…๋ฒ• ํŠธ๋ ˆ์ธ) A1ยทB1

์ž…๋ฒ• ๊ณผ์ •์—์„œ ์˜คํ”ˆ์†Œ์Šค ์ปค๋ฎค๋‹ˆํ‹ฐ์˜ ์ž…์žฅ ํ‘œ๋ช…์ด ๋ˆˆ์— ๋„์—ˆ๋‹ค. 2022~2023๋…„ ์ดˆ์•ˆ ๋‹จ๊ณ„์—์„œ ์ดํด๋ฆฝ์Šค ์žฌ๋‹จ(Eclipse Foundation), ์˜คํ”ˆ์†Œ์Šค ์ด๋‹ˆ์…”ํ‹ฐ๋ธŒ(OSI), ๋„ํ๋จผํŠธ ์žฌ๋‹จ ๋“ฑ์€ “์ƒ์—… ํ™œ๋™” ์ •์˜๊ฐ€ ๋ถˆ๋ช…ํ™•ํ•ด ์ž์›๋ด‰์‚ฌ ๊ฐœ๋ฐœ์ž์—๊ฒŒ๋„ ์ปดํ”Œ๋ผ์ด์–ธ์Šค ๋ถ€๋‹ด์ด ๋Œ์•„๊ฐˆ ์ˆ˜ ์žˆ๋‹ค๋Š” ์šฐ๋ ค๋ฅผ ์ œ๊ธฐํ–ˆ๋‹ค. 2023๋…„ 12์›” ์ž ์ • ํ•ฉ์˜ ์‹œ “์˜คํ”ˆ์†Œ์Šค ์ŠคํŠœ์–ด๋“œ(open-source steward)” ๊ฐœ๋…๊ณผ ์˜ˆ์™ธ ์กฐํ•ญ์ด ๋„์ž…๋˜๋ฉด์„œ ์ผ๋ถ€ ์šฐ๋ ค๊ฐ€ ํ•ด์†Œ๋์ง€๋งŒ, ์†Œ๊ทœ๋ชจ ์žฌ๋ฐฐํฌ์ž์— ๋Œ€ํ•œ ์ ์šฉ ๋ฒ”์œ„ ๋ฌธ์ œ๋Š” ์—ฌ์ „ํžˆ ๋…ผ๋ž€ ์ค‘์ด๋‹ค. D1

2.2 ์ ์šฉ ๋ฒ”์œ„ (Art. 2~3)

CRA๋Š” “๋””์ง€ํ„ธ ์š”์†Œ๋ฅผ ๊ฐ€์ง„ ์ œํ’ˆ(product with digital elements, PDE)“์— ์ ์šฉ๋œ๋‹ค. ์žฅ์น˜๋‚˜ ๋„คํŠธ์›Œํฌ์™€ ๋…ผ๋ฆฌ์ ยท๋ฌผ๋ฆฌ์  ๋ฐ์ดํ„ฐ ์—ฐ๊ฒฐ์ด ๊ฐ€๋Šฅํ•œ ํ•˜๋“œ์›จ์–ด์™€ ์†Œํ”„ํŠธ์›จ์–ด๋ฅผ ํฌ๊ด„ํ•˜๋ฉฐ, ๋…๋ฆฝ์ ์œผ๋กœ ์‹œ์žฅ์— ์ถœ์‹œ๋œ ์†Œํ”„ํŠธ์›จ์–ด ๊ตฌ์„ฑ์š”์†Œ๋„ ํฌํ•จ๋œ๋‹ค. B3

๋‹ค์Œ ์ œํ’ˆ์€ ์ ์šฉ ๋ฒ”์œ„์—์„œ ์ œ์™ธ๋œ๋‹ค. ์ƒ์—…์  ํ™œ๋™ ์—†์ด ๊ณต๊ธ‰๋˜๋Š” ์ž์œ ยท์˜คํ”ˆ์†Œ์Šค ์†Œํ”„ํŠธ์›จ์–ด, ์˜๋ฃŒ๊ธฐ๊ธฐยท์ž๋™์ฐจ์ฒ˜๋Ÿผ ๋” ์—„๊ฒฉํ•œ ๋ถ€๋ฌธ๋ณ„ ์‚ฌ์ด๋ฒ„๋ณด์•ˆ ๊ทœ์ œ๊ฐ€ ์ด๋ฏธ ์ ์šฉ๋˜๋Š” ์ œํ’ˆ์ด ๋Œ€ํ‘œ์ ์ด๋‹ค. ๋‹จ, ๊ธฐ์กด ์‚ฌ์ด๋ฒ„๋ณด์•ˆ ๊ทœ์ œ์˜ ์ ์šฉ ๋Œ€์ƒ์ด์–ด๋„ CRA๊ฐ€ “๋ณด์™„์ "์œผ๋กœ ์ ์šฉ๋  ์—ฌ์ง€๊ฐ€ ์žˆ์–ด ๋ถ€๋ฌธ๋ณ„ ํŒ๋‹จ์ด ํ•„์š”ํ•˜๋‹ค. A1ยทE2

%%{init: {'theme':'default', 'themeVariables': {'fontSize':'18px'}, 'flowchart': {'nodeSpacing': 40, 'rankSpacing': 50}} }%%
flowchart TD
    A["EU ์‹œ์žฅ์— ์œ ํ†ต๋˜๋Š” ์ œํ’ˆ์ธ๊ฐ€?"] -->|์•„๋‹ˆ์˜ค| Z["์ ์šฉ ์™ธ"]
    A -->|์˜ˆ| B["๋””์ง€ํ„ธ ์š”์†Œ๋ฅผ ๊ฐ€์ง„ ์ œํ’ˆ์ธ๊ฐ€?"]
    B -->|์•„๋‹ˆ์˜ค| Z
    B -->|์˜ˆ| C["์ƒ์—…์  ํ™œ๋™์ด ์žˆ๋Š”๊ฐ€?<br/>(์ƒ์—…์  FOSS ํฌํ•จ)"]
    C -->|์•„๋‹ˆ์˜ค| Z2["์ ์šฉ ์™ธ (๋น„์ƒ์—… FOSS)"]
    C -->|์˜ˆ| D["๋” ์—„๊ฒฉํ•œ ๋ถ€๋ฌธ๋ณ„ ์‚ฌ์ด๋ฒ„๋ณด์•ˆ ์ž…๋ฒ•์ด<br/>์ด๋ฏธ ์ ์šฉ๋˜๋Š”๊ฐ€? (์˜ˆ: MDR ์˜๋ฃŒ๊ธฐ๊ธฐ)"]
    D -->|์˜ˆ| Z3["์ ์šฉ ์™ธ"]
    D -->|์•„๋‹ˆ์˜ค| E["CRA ์ ์šฉ ๋Œ€์ƒ"]
    E --> F["๋“ฑ๊ธ‰ ๋ถ„๋ฅ˜:<br/>๊ธฐ๋ณธ / ์ค‘์š” Class I /<br/>์ค‘์š” Class II / ์ค‘๋Œ€"]

    style E fill:#fce4ec,stroke:#c2185b
    style F fill:#fce4ec,stroke:#c2185b

๊ทธ๋ฆผ 2. CRA ์ ์šฉ ์—ฌ๋ถ€ ํŒ๋‹จ ํ๋ฆ„ (์ถœ์ฒ˜: CRA Art. 2~3, ์‹œํ–‰๊ทœ์น™ (EU) 2025/2392) A1ยทA3

2.3 ๋‹จ๊ณ„์  ์‹œํ–‰

CRA๋Š” ์ „๋ฉด ์ ์šฉ์ด ๋‹จ์ผ ์‹œ์ ์— ์ด๋ค„์ง€์ง€ ์•Š๋Š”๋‹ค.

์‹œ์ ์ ์šฉ ์˜๋ฌด๋ฒ•์  ๊ทผ๊ฑฐ
2024-12-10๋ฐœํšจCRA Art. 71
2026-06-11์ ํ•ฉ์„ฑ ํ‰๊ฐ€๊ธฐ๊ด€ ํ†ต๋ณด ๊ด€๋ จ ์กฐํ•ญ(์ œIV์žฅ)CRA Art. 71(2)
2026-09-11์ œ14์กฐ ๋ณด๊ณ  ์˜๋ฌด + SRP ๊ฐ€๋™CRA Art. 14, 16
2027-12-11CE ๋งˆํ‚นยท์ ํ•ฉ์„ฑ ํ‰๊ฐ€ยท๋ณธ์งˆ ์š”๊ฑด ์ „๋ฉด ์ ์šฉCRA Art. 71(2)

A1ยทB3

2026๋…„ 9์›” 11์ผ๊นŒ์ง€ ๊ฐ–์ถฐ์•ผ ํ•  ๊ฒƒ์€ ์ œํ’ˆ ์ธ์ฆ์ด ์•„๋‹ˆ๋ผ ์ทจ์•ฝ์ ยท์‚ฌ๊ณ  ๋ณด๊ณ  ์›Œํฌํ”Œ๋กœ์šฐ๋‹ค. CE ๋งˆํ‚น๊ณผ ์ ํ•ฉ์„ฑ ํ‰๊ฐ€์˜ ์‹œํ•œ์€ ๊ทธ๋ณด๋‹ค 15๊ฐœ์›” ๋’ค์ธ 2027๋…„ 12์›” 11์ผ์ด๋‹ค.


3. ์ œ์กฐ์‚ฌ ์˜๋ฌด (Art. 13)

3.1 Annex I ๋ณธ์งˆ ์š”๊ฑด

์ œ13์กฐ๋Š” ์ œ์กฐ์‚ฌ๊ฐ€ CRA Annex I์˜ ๋ณธ์งˆ์  ์‚ฌ์ด๋ฒ„๋ณด์•ˆ ์š”๊ฑด(essential cybersecurity requirements)์„ ์ถฉ์กฑํ•ด์•ผ ํ•œ๋‹ค๊ณ  ๊ทœ์ •ํ•œ๋‹ค. ์š”๊ฑด์€ ํฌ๊ฒŒ ๋‘ ๊ทธ๋ฃน์œผ๋กœ ๋‚˜๋‰œ๋‹ค. A1ยทB3

Part I โ€” ์ œํ’ˆ ๋ณด์•ˆ ์š”๊ฑด: ์•Œ๋ ค์ง„ ์ทจ์•ฝ์  ์—†๋Š” ์ƒํƒœ ์ถœ์‹œ, ๊ธฐ๋ณธ ๋น„๋ฐ€๋ฒˆํ˜ธ ๊ธˆ์ง€, ๋ณด์•ˆ ์—…๋ฐ์ดํŠธ ์ œ๊ณต, ์ตœ์†Œ ๊ถŒํ•œ ์›์น™ ์ ์šฉ, ๋ฐ์ดํ„ฐ ๋ณดํ˜ธ, ๊ณต๊ฒฉ ํ‘œ๋ฉด ์ถ•์†Œ, ์‚ฌ์ด๋ฒ„ ๋ณต์›๋ ฅ ์„ค๊ณ„, ๊ฐœ์ธ ๋ฐ์ดํ„ฐ ์ ‘๊ทผยท์ˆ˜์ • ์ด๋ ฅ ์ œ๊ณต.

Part II โ€” ์ทจ์•ฝ์  ์ฒ˜๋ฆฌ ์š”๊ฑด: ์ทจ์•ฝ์  ์‹๋ณ„ยท๋ฌธ์„œํ™”, SBOM ์œ ์ง€, ์‹ ์†ํ•œ ํŒจ์น˜ ์ œ๊ณต๊ณผ ๋ฌด๋ฃŒ ๋ฐฐํฌ, ์กฐ์ •๋œ ์ทจ์•ฝ์  ๊ณต๊ฐœ(Coordinated Vulnerability Disclosure, CVD) ์ •์ฑ…, ์•…์šฉ ์ทจ์•ฝ์ ยท์‚ฌ๊ณ  ๋ณด๊ณ (Art. 14), ์ƒ์•  ์ฃผ๊ธฐ ์ „๋ฐ˜์— ๊ฑธ์นœ ์ทจ์•ฝ์  ๋ชจ๋‹ˆํ„ฐ๋ง.

์ด ์š”๊ฑด๋“ค์€ ํ˜„ ์‹œ์ ์— ํ™•์ •๋œ ์กฐํ™” ํ‘œ์ค€์ด ์—†์–ด CRA ์›๋ฌธ์˜ ๊ธฐ๋Šฅ์  ์š”๊ฑด์œผ๋กœ ์ง์ ‘ ์ดํ–‰ํ•ด์•ผ ํ•œ๋‹ค. ENISAยทJRC๊ฐ€ ๊ณต๋™ ๋ฐœ๊ฐ„ํ•œ CRA Requirements Standards Mapping(2024)์ด ๊ธฐ์กด ํ‘œ์ค€๊ณผ์˜ ๋งคํ•‘์„ ์ œ๊ณตํ•˜๋ฉฐ, ISO/IEC 30111(์ทจ์•ฝ์  ์ฒ˜๋ฆฌ)ยท29147(์ทจ์•ฝ์  ๊ณต์‹œ)ยทNIST SP 800-218(SSDF)์ด ์ฃผ์š” ์ฐธ์กฐ์ ์ด๋‹ค. B5ยทC1ยทC2ยทC6

3.2 ์ง€์› ๊ธฐ๊ฐ„

์ œ์กฐ์‚ฌ๋Š” ์‹œ์žฅ ์ถœ์‹œ ํ›„ ์˜ˆ์ƒ ์‚ฌ์šฉ ๊ธฐ๊ฐ„ ๋™์•ˆ, ์ตœ์†Œ 5๋…„ ์ด์ƒ ๋ณด์•ˆ ์ง€์›์„ ์ œ๊ณตํ•ด์•ผ ํ•œ๋‹ค. ์˜ˆ์ƒ ์‚ฌ์šฉ ๊ธฐ๊ฐ„์ด 5๋…„ ๋ฏธ๋งŒ์ธ ์ œํ’ˆ์€ ํ•ด๋‹น ๊ธฐ๊ฐ„์„ ์ง€์› ๊ธฐ๊ฐ„์œผ๋กœ ํ•  ์ˆ˜ ์žˆ๋‹ค. ์ง€์› ๊ธฐ๊ฐ„์€ ์ œํ’ˆ์— ๋ช…์‹œ์ ์œผ๋กœ ํ‘œ์‹œํ•ด์•ผ ํ•˜๋ฉฐ, ์ด ๊ธฐ๊ฐ„ ๋™์•ˆ์˜ ์ทจ์•ฝ์  ์ฒ˜๋ฆฌ์™€ ๋ณด์•ˆ ์—…๋ฐ์ดํŠธ ์ œ๊ณต์ด ์˜๋ฌด๋‹ค. A1ยทB3

3.3 SBOM ์š”๊ฑด

CRA Annex I Part II๋Š” ์†Œํ”„ํŠธ์›จ์–ด ๋ถ€ํ’ˆ ๋ช…์„ธ์„œ(Software Bill of Materials, SBOM)๋ฅผ ์˜๋ฌดํ™”ํ•œ๋‹ค. ๊ตฌ์ฒด์ ์œผ๋กœ๋Š” ์ถœ๊ณ  ๋ฒ„์ „๋งˆ๋‹ค SBOM์„ ์ƒ์„ฑํ•˜๊ณ , ์‹œ์žฅ ๊ฐ์‹œ ๋‹น๊ตญ(Market Surveillance Authority)์˜ ์š”์ฒญ์— ๋Œ€๋น„ํ•ด ๊ธฐ๊ณ„ ํŒ๋… ๊ฐ€๋Šฅํ•œ ํ˜•์‹์œผ๋กœ ๋ณด๊ด€ํ•ด์•ผ ํ•œ๋‹ค. SBOM์„ ์ œ3์ž์—๊ฒŒ ๊ณต๊ฐœํ•  ์˜๋ฌด๋Š” ์—†์œผ๋‚˜, ์‹œ์žฅ ๊ฐ์‹œ ๋‹น๊ตญ์—๋Š” ์ œ์ถœํ•ด์•ผ ํ•œ๋‹ค. A1

ํ˜•์‹์€ SPDX ๋˜๋Š” CycloneDX๊ฐ€ ์‚ฌ์‹ค์ƒ ํ‘œ์ค€์œผ๋กœ ์ž๋ฆฌ์žก๊ณ  ์žˆ๋‹ค. SPDX๋Š” ISO/IEC 5962:2021๋กœ ํ‘œ์ค€ํ™”๋๊ณ (SPDX v2.2.1 ๊ธฐ๋ฐ˜, ํ˜„ํ–‰ ์‚ฌ์–‘์€ v3.0), C3ยทC4 CycloneDX๋Š” OWASP๊ฐ€ ๊ด€๋ฆฌํ•˜๋Š” ์‚ฌ์–‘์œผ๋กœ 2025๋…„ 12์›” 10์ผ ECMA-424 2nd Edition(v1.7 ๊ธฐ๋ฐ˜)์ด ๋ฐœํ–‰๋๋‹ค. C5 CRA ์ฐจ์›์˜ ๊ณต์‹ SBOM ์Šคํ‚ค๋งˆ ์‹œํ–‰๊ทœ์น™์€ 2026๋…„ 5์›” ํ˜„์žฌ๊นŒ์ง€ ๋ฐœํ‘œ๋˜์ง€ ์•Š์•˜๋‹ค. ๋…์ผ ์—ฐ๋ฐฉ์ •๋ณด๋ณด์•ˆ์ฒญ(Bundesamt fรผr Sicherheit in der Informationstechnik, BSI)์ด 2025๋…„ 8์›” ๋ฐœ๊ฐ„ํ•œ TR-03183-2 v2.1.0์ด CRA ์ •ํ•ฉ SBOM์˜ ํ•„๋“œ ๋งคํ•‘์„ ์ œ๊ณตํ•˜๋Š” ํ˜„์‹ค์  ์ฐธ์กฐ์ ์ด๋‹ค. G1


4. ๋ณด๊ณ  ์˜๋ฌด (Art. 14) โ€” 2026-09-11 ์‹œํ–‰

4.1 ํ†ต์ง€ ํŠธ๋ฆฌ๊ฑฐ

์ œ14์กฐ๋Š” ๋‘ ๋ถ€๋ฅ˜์˜ ์‚ฌ๊ฑด ๋ฐœ์ƒ์„ ์ œ์กฐ์‚ฌ์˜ ํ†ต์ง€ ํŠธ๋ฆฌ๊ฑฐ๋กœ ๊ทœ์ •ํ•œ๋‹ค. A1ยทB2

ํ•˜๋‚˜๋Š” **์‹ค์ œ ์•…์šฉ๋˜๊ณ  ์žˆ๋Š” ์ทจ์•ฝ์ (actively exploited vulnerability)**์ด๋‹ค. ์ทจ์•ฝ์ ์ด ์ด๋ก ์ ์œผ๋กœ ์กด์žฌํ•˜๋Š” ๊ฒƒ์ด ์•„๋‹ˆ๋ผ ๊ณต๊ฒฉ์ž์— ์˜ํ•ด ์‹ค์ œ ์•…์šฉ๋˜๋Š” ๊ฒƒ์ด ํ™•์ธ๋œ ์‹œ์ ์ด ํŠธ๋ฆฌ๊ฑฐ๋‹ค. ๋‹ค๋ฅธ ํ•˜๋‚˜๋Š” **์ค‘๋Œ€ํ•œ ๋ณด์•ˆ ์‚ฌ๊ณ (severe incident)**๋กœ, ์ œํ’ˆ์˜ ๋ณด์•ˆ์— ์˜ํ–ฅ์„ ๋ฏธ์น˜๋Š” ์‹ฌ๊ฐํ•œ ์šด์˜ ์ค‘๋‹จยท์†์‹คยท์†ํ•ด๋ฅผ ์•ผ๊ธฐํ•˜๊ฑฐ๋‚˜ ์•ผ๊ธฐํ•  ๊ฐ€๋Šฅ์„ฑ์ด ์žˆ๋Š” ์‚ฌ๊ฑด์ด๋‹ค.

์ œ์กฐ์‚ฌ ์™ธ์— ์ˆ˜์ž…์‚ฌ์™€ ์œ ํ†ต์‚ฌ๋„ ๋น„์ค€์ˆ˜๋ฅผ ๋ฐœ๊ฒฌํ•˜๊ฑฐ๋‚˜ ์‚ฌ๊ณ ๋ฅผ ์ธ์ง€ํ–ˆ์„ ๋•Œ ํ•ด๋‹น ์ •๋ณด๋ฅผ ์ œ์กฐ์‚ฌ์— ํ†ต์ง€ํ•ด์•ผ ํ•œ๋‹ค.

4.2 3๋‹จ๊ณ„ ์‹œํ•œ (24h/72h/14d)

%%{init: {'theme':'default', 'themeVariables': {'fontSize':'18px'}, 'flowchart': {'nodeSpacing': 40, 'rankSpacing': 50}} }%%
flowchart LR
    T0["์ธ์ง€ ์‹œ์ <br/>(actively exploited vuln.<br/>๋˜๋Š” severe incident)"]
    T1["24์‹œ๊ฐ„ ๋‚ด<br/>์กฐ๊ธฐ ๊ฒฝ๋ณด<br/>(Early Warning)"]
    T2["72์‹œ๊ฐ„ ๋‚ด<br/>๋ณธ ํ†ต์ง€<br/>(Notification)"]
    T3["์™„ํ™” ์กฐ์น˜ ๊ฐ€์šฉ ํ›„<br/>14์ผ ๋‚ด<br/>์ตœ์ข… ๋ณด๊ณ  (์ทจ์•ฝ์ )"]
    T4["ํ†ต์ง€ ํ›„<br/>1๊ฐœ์›” ๋‚ด<br/>์ตœ์ข… ๋ณด๊ณ  (์‚ฌ๊ณ )"]

    T0 --> T1 --> T2 --> T3
    T2 --> T4

    style T1 fill:#ffebee,stroke:#c62828
    style T2 fill:#fff3e0,stroke:#ef6c00
    style T3 fill:#e8f5e9,stroke:#2e7d32
    style T4 fill:#e8f5e9,stroke:#2e7d32

๊ทธ๋ฆผ 3. CRA Article 14 ๋ณด๊ณ  ์‹œํ•œ (์ถœ์ฒ˜: CRA Art. 14, EC “CRA โ€” Reporting obligations”) A1ยทB2

๊ฐ ๋‹จ๊ณ„์˜ ํฌํ•จ ๋‚ด์šฉ์€ ์•„๋ž˜์™€ ๊ฐ™๋‹ค. A1ยทB2

๋‹จ๊ณ„์‹œํ•œํฌํ•จ ๋‚ด์šฉ
์กฐ๊ธฐ ๊ฒฝ๋ณด (Early Warning)์ธ์ง€ ํ›„ 24์‹œ๊ฐ„์˜ํ–ฅ ๋ฐ›๋Š” ํšŒ์›๊ตญ, ์•…์˜์  ํ™œ๋™๊ณผ์˜ ์—ฐ๊ด€ ์—ฌ๋ถ€
๋ณธ ํ†ต์ง€ (Notification)72์‹œ๊ฐ„์ทจ์•ฝ์ ยท์‚ฌ๊ณ ์˜ ์ผ๋ฐ˜์  ์„ฑ๊ฒฉ, ์‚ฌ์šฉ ๊ฐ€๋Šฅํ•œ ์™„ํ™” ์กฐ์น˜, ๋ฏผ๊ฐ๋„ ํ‰๊ฐ€
์ตœ์ข… ๋ณด๊ณ  โ€” ์ทจ์•ฝ์ ์™„ํ™” ์กฐ์น˜ ๊ฐ€์šฉ ํ›„ 14์ผ์‹ฌ๊ฐ๋„ยท์˜ํ–ฅ ๋ฒ”์œ„, ์œ„ํ˜‘ ํ–‰์œ„์ž ์ •๋ณด, ๋ณด์•ˆ ์—…๋ฐ์ดํŠธ ๋‚ด์šฉ
์ตœ์ข… ๋ณด๊ณ  โ€” ์‚ฌ๊ณ ๋ณธ ํ†ต์ง€ ํ›„ 1๊ฐœ์›”์ƒ์„ธ ์‚ฌ๊ณ  ๊ธฐ์ˆ , ์œ„ํ˜‘ ์œ ํ˜• ๋ฐ ๊ทผ๋ณธ ์›์ธ, ์ ์šฉ๋œ ์™„ํ™” ์กฐ์น˜

24์‹œ๊ฐ„ ์‹œํ•œ์ด ์ทจ์•ฝ์  ๋ถ„๋ฅ˜๋‚˜ ํ•ด๊ฒฐ ์™„๋ฃŒ๋ฅผ ์š”๊ตฌํ•˜์ง€ ์•Š๋Š”๋‹ค๋Š” ์ ์„ CRA ์›๋ฌธ์€ ๋ถ„๋ช…ํžˆ ํ•œ๋‹ค. ์กฐ๊ธฐ ๊ฒฝ๋ณด๋กœ์„œ ์กด์žฌ์˜ ํ†ต์ง€๊ฐ€ ๋ชฉ์ ์ด๋‹ค. ๋งˆ์ดํฌ๋กœ๊ธฐ์—…๊ณผ ์†Œ๊ธฐ์—…์€ 24์‹œ๊ฐ„ ์‹œํ•œ ๋ฏธ์ค€์ˆ˜์— ๋”ฐ๋ฅธ ๊ณผ์ง•๊ธˆ์ด ๋ฉด์ œ๋  ์ˆ˜ ์žˆ๋‹ค. A1

4.3 ๋‹จ์ผ ๋ณด๊ณ  ํ”Œ๋žซํผ (Art. 16)

์ œ14์กฐ ํ†ต์ง€๋Š” ๋ชจ๋‘ ๋‹จ์ผ ๋ณด๊ณ  ํ”Œ๋žซํผ(Single Reporting Platform, SRP)์„ ํ†ตํ•ด ์ด๋ค„์ง„๋‹ค. ENISA๊ฐ€ ์šด์˜ํ•˜๋ฉฐ, ์ œ์กฐ์‚ฌ๊ฐ€ ํ•œ ๋ฒˆ ์ œ์ถœํ•˜๋ฉด โ‘  ์ฃผ ์‚ฌ์—…์žฅ ์†Œ์žฌ ํšŒ์›๊ตญ์˜ ์ฝ”๋””๋„ค์ดํ„ฐ CSIRT(Computer Security Incident Response Team)์™€ โ‘ก ENISA๋กœ ์ž๋™ ๋ผ์šฐํŒ…๋œ๋‹ค. B4ยทA1

ENISA๋Š” NIS2ยทDORA์˜ ์‚ฌ๊ณ ยท์ทจ์•ฝ์  ๋ณด๊ณ  ์ฒด๊ณ„์™€์˜ ํ†ตํ•ฉ์„ ๊ฐ€๋Šฅ์ผ€ ํ•˜๋Š” ๋ฏธ๋ž˜์ง€ํ–ฅ ์•„ํ‚คํ…์ฒ˜๋ฅผ ์š”๊ตฌํ•˜๋Š” ๋ฐฉ์‹์œผ๋กœ SRP๋ฅผ ์กฐ๋‹ฌํ–ˆ๋‹ค. ์„ค๊ณ„์ƒ CRA ์˜๋ฌด ์™ธ์—๋„ ์ธ์ ‘ ๊ทœ์ œ ์ฒด๊ณ„์™€์˜ ์—ฐ๋™์ด ๊ฐ€๋Šฅํ•œ ํ”Œ๋žซํผ์„ ๋ชฉํ‘œ๋กœ ํ•œ๋‹ค.

%%{init: {'theme':'default', 'themeVariables': {'fontSize':'18px'}, 'flowchart': {'nodeSpacing': 50, 'rankSpacing': 70}} }%%
flowchart LR
    M["์ œ์กฐ์‚ฌ<br/>(Manufacturer)"]
    I["์ˆ˜์ž…์‚ฌ<br/>(Importer)"]
    D["์œ ํ†ต์‚ฌ<br/>(Distributor)"]
    SRP["ENISA SRP<br/>(๋‹จ์ผ ๋ณด๊ณ  ํ”Œ๋žซํผ)"]
    CSIRT["ํšŒ์›๊ตญ ์ฝ”๋””๋„ค์ดํ„ฐ<br/>CSIRT"]
    ENISA["ENISA"]
    OTHER_CSIRT["ํƒ€ ํšŒ์›๊ตญ<br/>CSIRT"]
    MSA["์‹œ์žฅ ๊ฐ์‹œ ๋‹น๊ตญ<br/>(MSA)"]

    M -->|"Art.14 24h/72h/14d"| SRP
    I -->|"๋น„์ค€์ˆ˜ ๋ฐœ๊ฒฌ ์‹œ"| M
    D -->|"๋น„์ค€์ˆ˜ ๋ฐœ๊ฒฌ ์‹œ"| M
    SRP --> CSIRT
    SRP --> ENISA
    CSIRT -->|"์ „ํŒŒ<br/>(์ง€์—ฐ ์กฐ๊ฑด ์ ์šฉ)"| OTHER_CSIRT
    ENISA --> MSA
    MSA -->|"์‹œ์ •ยทํšŒ์ˆ˜ ๋ช…๋ น"| M

    style M fill:#e3f2fd,stroke:#1565c0
    style SRP fill:#fff3e0,stroke:#ef6c00
    style ENISA fill:#fff3e0,stroke:#ef6c00
    style CSIRT fill:#fff3e0,stroke:#ef6c00

๊ทธ๋ฆผ 4. CRA ๋ณด๊ณ  ์ฒด๊ณ„์˜ ์ดํ•ด๊ด€๊ณ„์ž ์ƒํ˜ธ์ž‘์šฉ (์ถœ์ฒ˜: CRA Art. 13~16, ์œ„์ž„๋ฒ• (EU) 2026/881) A1ยทA2

4.4 CSIRT ๊ฐ„ ์ „ํŒŒ ์ง€์—ฐ ์กฐ๊ฑด (์œ„์ž„๋ฒ• 2026/881)

2025๋…„ 12์›” 11์ผ ์ฑ„ํƒ๋œ ์œ„์ž„๋ฒ• (EU) 2026/881(๊ด€๋ณด ๊ฒŒ์žฌ 2026-04-20)์€ ํšŒ์›๊ตญ CSIRT๊ฐ€ ๋‹จ์ผ ๋ณด๊ณ  ํ”Œ๋žซํผ์„ ํ†ตํ•ด ์ˆ˜์‹ ํ•œ ํ†ต์ง€๋ฅผ ๋‹ค๋ฅธ CSIRT์—๊ฒŒ ์ฆ‰์‹œ ์ „ํŒŒํ•˜์ง€ ์•Š์„ ์ˆ˜ ์žˆ๋Š” ์กฐ๊ฑด์„ ๋ช…์‹œํ–ˆ๋‹ค. A2 ํ—ˆ์šฉ ์กฐ๊ฑด์€ ์„ธ ๊ฐ€์ง€๋‹ค.

ํ†ต์ง€๋œ ์ •๋ณด์˜ ์„ฑ๊ฒฉ์— ๋Œ€ํ•œ ํ‰๊ฐ€์— ๋น„์ถ”์–ด ์ง€์—ฐ์ด ์ •๋‹นํ™”๋˜๋Š” ๊ฒฝ์šฐ, ์ˆ˜์‹  CSIRT๊ฐ€ ํ•ด๋‹น ์ •๋ณด์˜ ๊ธฐ๋ฐ€์„ฑ์„ ๋ณด์žฅํ•  ์ˆ˜ ์—†๋Š” ๊ฒฝ์šฐ, ๋‹จ์ผ ๋ณด๊ณ  ํ”Œ๋žซํผ ์ž์ฒด๊ฐ€ ์นจํ•ด๋˜์—ˆ๊ฑฐ๋‚˜ ์ผ์‹œ์ ์œผ๋กœ ์šด์˜์ด ๋ถˆ๊ฐ€ํ•œ ๊ฒฝ์šฐ๋‹ค. ๋˜ํ•œ ํŠธ๋ž˜ํ”ฝ ๋ผ์ดํŠธ ํ”„๋กœํ† ์ฝœ(Traffic Light Protocol, TLP)ยท์ •๋ณด ์ ‘๊ทผ ํ”„๋กœํ† ์ฝœ(Permissible Actions Protocol, PAP) ๋“ฑ ์ ์ ˆํ•œ ๋„๊ตฌ๋กœ ์œ„ํ—˜์„ ์™„ํ™”ํ•  ์ˆ˜ ์—†์„ ๋•Œ, “์—„๊ฒฉํžˆ ํ•„์š”ํ•œ ๊ธฐ๊ฐ„"์— ํ•œํ•ด์„œ๋งŒ ์ง€์—ฐ์ด ํ—ˆ์šฉ๋œ๋‹ค.

์ œ์กฐ์‚ฌ โ†’ CSIRT์˜ 24์‹œ๊ฐ„ ์‹œํ•œ์€ ์ด ์œ„์ž„๋ฒ•์˜ ์˜ํ–ฅ์„ ๋ฐ›์ง€ ์•Š๋Š”๋‹ค. ์œ„์ž„๋ฒ•์€ CSIRT ๊ฐ„์˜ ์ถ”๊ฐ€ ์ „ํŒŒ ๋‹จ๊ณ„์— ๋ณด์•ˆ ์‚ฌ์œ ์˜ ์™„ํ™” ์žฅ์น˜๋ฅผ ๋งˆ๋ จํ•œ ๊ฒƒ์ด๋‹ค.

4.5 GDPRยทNIS2์™€์˜ ๋ณ‘ํ–‰ ์ ์šฉ

CRA ๋ณด๊ณ ์™€ ๋‹ค๋ฅธ ๊ทœ์ œ์˜ ๋ณด๊ณ  ์˜๋ฌด๊ฐ€ ๋™์‹œ์— ๋ฐœ์ƒํ•  ์ˆ˜ ์žˆ๋‹ค. ์ทจ์•ฝ์ ยท์‚ฌ๊ณ ๋กœ ์นจํ•ด๋œ ๋ฐ์ดํ„ฐ์— ๊ฐœ์ธ์ •๋ณด๊ฐ€ ํฌํ•จ๋œ ๊ฒฝ์šฐ, CRA ํ†ต์ง€๋Š” GDPR(General Data Protection Regulation) ์ œ33์กฐ์˜ 72์‹œ๊ฐ„ ๊ฐ๋…๊ธฐ๊ด€ ํ†ต์ง€ ์˜๋ฌด๋ฅผ ๋Œ€์ฒดํ•˜์ง€ ์•Š๋Š”๋‹ค. A5 ๋‘ ํ†ต์ง€๋Š” ์„œ๋กœ ๋‹ค๋ฅธ ์ฑ„๋„๊ณผ ์ˆ˜์‹ ์ฒ˜(๋ฐ์ดํ„ฐ๋ณดํ˜ธ๋‹น๊ตญ vs CSIRT/ENISA)๋กœ ๋ณ„๋„๋กœ ์ด๋ค„์ ธ์•ผ ํ•œ๋‹ค.

NIS2 ์ง€์นจ(Directive (EU) 2022/2555) ์ ์šฉ ๋Œ€์ƒ์ธ ํ•„์ˆ˜ ์„œ๋น„์Šคยท์ค‘์š” ์„œ๋น„์Šค ์šด์˜์ž๊ฐ€ ์ž์‚ฌ ์ œํ’ˆ์—์„œ ์ทจ์•ฝ์ ยท์‚ฌ๊ณ ๋ฅผ ์ธ์ง€ํ•œ ๊ฒฝ์šฐ์—๋„ ๋งˆ์ฐฌ๊ฐ€์ง€๋‹ค. CRA ๋ณด๊ณ ์™€ NIS2 ๋ณด๊ณ ๊ฐ€ ๋™์‹œ์— ํ•„์š”ํ•  ์ˆ˜ ์žˆ์œผ๋ฉฐ, Digital Omnibus ํŒจํ‚ค์ง€์˜ “report once, share many” ๋ชจ๋ธ์ด ๋‘ ๋ณด๊ณ  ์˜๋ฌด๋ฅผ ํ†ตํ•ฉํ•˜๋Š” ๋ฐฉํ–ฅ์œผ๋กœ ๋…ผ์˜ ์ค‘์ด๋‚˜ ์•„์ง ์ž…๋ฒ•์œผ๋กœ ํ™•์ •๋˜์ง€ ์•Š์•˜๋‹ค. A4ยทE2


5. ์ ํ•ฉ์„ฑ ํ‰๊ฐ€์™€ CE ๋งˆํ‚น (2027-12-11)

์ ํ•ฉ์„ฑ ํ‰๊ฐ€๋Š” 2027๋…„ 12์›” 11์ผ์ด ์‹œํ•œ์ด๋‹ค. ๋“ฑ๊ธ‰์— ๋”ฐ๋ผ ๊ฒฝ๋กœ๊ฐ€ ๋‹ค๋ฅด๋‹ค. ๊ธฐ๋ณธ(default) ๋“ฑ๊ธ‰ ์ œํ’ˆ์€ ์ž์ฒด ํ‰๊ฐ€(self-assessment)๋กœ EU ์ ํ•ฉ์„ฑ ์„ ์–ธ(EU Declaration of Conformity)์„ ๋ฐœํ–‰ํ•˜๊ณ  CE ๋งˆํ‚น์„ ๋ถ€์ฐฉํ•  ์ˆ˜ ์žˆ๋‹ค. ์ค‘์š” Class I ์ œํ’ˆ์€ EU ์กฐํ™” ํ‘œ์ค€์„ ์ ์šฉํ•œ ์ž์ฒด ํ‰๊ฐ€ ๋˜๋Š” ์ œ3์ž ์ ํ•ฉ์„ฑ ํ‰๊ฐ€ ๊ธฐ๊ด€(Conformity Assessment Body, CAB)์— ์˜ํ•œ ํ‰๊ฐ€๊ฐ€ ๊ฐ€๋Šฅํ•˜๋‹ค. ์ค‘์š” Class II์™€ ์ค‘๋Œ€(critical) ๋“ฑ๊ธ‰ ์ œํ’ˆ์€ CAB์— ์˜ํ•œ ๊ฐ•ํ™”๋œ ๊ฒ€์‚ฌ๊ฐ€ ํ•„์ˆ˜๋‹ค. A1ยทB3

ENISA๋Š” 2025๋…„ 2์›” CRA Implementation via EUCC and its Applicable Technical Elements๋ฅผ ๋ฐœ๊ฐ„ํ•ด, EU ๊ณตํ†ต ๊ธฐ์ค€(EU Common Criteria, EUCC) ์ธ์ฆ์ด CRA ์ ํ•ฉ์„ฑ ํ‰๊ฐ€์— ํ™œ์šฉ๋  ์ˆ˜ ์žˆ๋Š” ๊ฒฝ๋กœ๋ฅผ ๋ถ„์„ํ–ˆ๋‹ค. B6

2026๋…„ 6์›” 11์ผ๋ถ€ํ„ฐ๋Š” ๋จผ์ € ์ ํ•ฉ์„ฑ ํ‰๊ฐ€๊ธฐ๊ด€์˜ ํ†ต๋ณด(notification) ๊ด€๋ จ ์กฐํ•ญ์ด ๋ฐœํšจ๋œ๋‹ค. ๊ฐ ํšŒ์›๊ตญ์ด ์ง€์ •ํ•œ CAB๊ฐ€ ํ†ต๋ณด ์ ˆ์ฐจ๋ฅผ ํ†ตํ•ด EU ์ฐจ์›์—์„œ ๊ณต์ธ๋˜๋Š” ๊ณผ์ •์ด ์‹œ์ž‘๋˜๋Š” ์‹œ์ ์ด๋‹ค. B3

์œ„๋ฐ˜ ์‹œ ์ œ์žฌ๋Š” ์œ„๋ฐ˜ ์œ ํ˜•์— ๋”ฐ๋ผ ๋‹ฌ๋ผ์ง„๋‹ค. ๊ฐ€์žฅ ์—„์ค‘ํ•œ ์œ„๋ฐ˜(๋ณธ์งˆ ์š”๊ฑด ๋ฏธ์ถฉ์กฑ, ๋ณด๊ณ  ์˜๋ฌด ์œ„๋ฐ˜)์—๋Š” 1,500๋งŒ ์œ ๋กœ ๋˜๋Š” ์ „ ์„ธ๊ณ„ ์—ฐ๊ฐ„ ๋งค์ถœ์•ก์˜ 2.5% ์ค‘ ํฐ ๊ธˆ์•ก์ด ๊ณผ์ง•๊ธˆ์œผ๋กœ ๋ถ€๊ณผ๋  ์ˆ˜ ์žˆ์œผ๋ฉฐ, EU ์‹œ์žฅ์—์„œ์˜ ์ œํ’ˆ ํšŒ์ˆ˜ ๋ช…๋ น๋„ ๊ฐ€๋Šฅํ•˜๋‹ค. A1ยทE1


6. ํ‘œ์ค€ยทํ”„๋ ˆ์ž„์›Œํฌ ๋งคํ•‘

CRA๋Š” ๋ณธ์งˆ ์š”๊ฑด๋งŒ ๊ทœ์ •ํ•˜๊ณ  ๊ธฐ์ˆ ์  ์„ธ๋ถ€๋Š” ์กฐํ™” ํ‘œ์ค€์— ์œ„์ž„ํ•œ๋‹ค. CEN/CENELEC JTC 13 WG 9๊ฐ€ CRA์šฉ ์œ ๋Ÿฝ ์กฐํ™” ํ‘œ์ค€(EN)์„ ์ฑ…์ • ์ค‘์ด๋ฉฐ, 2026๋…„ 8์›” 30์ผ ์ˆ˜ํ‰ ํ‘œ์ค€, 2026๋…„ 10์›” 30์ผ ์ˆ˜์ง ํ‘œ์ค€ ๋ฐœํ–‰์„ ๋ชฉํ‘œ๋กœ ํ•œ๋‹ค. ์ตœ์ข… ์ธ์šฉ ํ‘œ์ค€ ๋ชฉ๋ก์€ ํ™•์ •๋˜๊ธฐ ์ „์ด๋ฏ€๋กœ, ํ˜„ ์‹œ์ ์—๋Š” ์•„๋ž˜ ํ‘œ๋ฅผ ๋งคํ•‘ ํ›„๋ณด๋กœ ํ™œ์šฉํ•œ๋‹ค. B5

ํ‘œ์ค€ยทํ”„๋ ˆ์ž„์›Œํฌ์ฃผ๊ด€CRA ๋งคํ•‘
ISO/IEC 30111:2019ISO/IEC์ทจ์•ฝ์  ์ฒ˜๋ฆฌ ์ ˆ์ฐจ โ€” Annex I Part II “์ทจ์•ฝ์  ์ฒ˜๋ฆฌ” ์š”๊ฑด
ISO/IEC 29147:2018ISO/IEC์กฐ์ •๋œ ์ทจ์•ฝ์  ๊ณต๊ฐœ(CVD) โ€” Art. 14 ํ†ต์ง€ ์›Œํฌํ”Œ๋กœ์šฐ
SPDX v3.0 (ISO/IEC 5962)Linux Foundation / ISOSBOM ํ‘œ์ค€ ํ˜•์‹
CycloneDX v1.7 (ECMA-424)OWASP / EcmaSBOM ํ‘œ์ค€ ํ˜•์‹ โ€” VEX(Vulnerability Exploitability eXchange) ๋„ค์ดํ‹ฐ๋ธŒ ์ง€์›
NIST SP 800-218 (SSDF)NIST์„ค๊ณ„ ๋ณด์•ˆ ์‹ค๋ฌด โ€” Annex I Part I ์š”๊ฑด๊ณผ ๊ธฐ๋Šฅ์  ์ •๋ ฌ
prEN 40000-2-1 (์ดˆ์•ˆ)CEN/CENELECCRA ์กฐํ™” ์ˆ˜ํ‰ ํ‘œ์ค€ โ€” 2026-08-30 ๋ฐœํ–‰ ๋ชฉํ‘œ
BSI TR-03183-2 v2.1.0BSI (๋…์ผ)CRA ์ •ํ•ฉ SBOM ํ•„๋“œ ๋งคํ•‘ ๊ธฐ์ˆ  ๊ฐ€์ด๋“œ๋ผ์ธ

C1ยทC2ยทC3ยทC4ยทC5ยทC6ยทG1

์œ ๋Ÿฝ ์ทจ์•ฝ์  ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค(European Vulnerability Database, EUVD)๋Š” NIS2 ์ง€์นจ ์ œ12์กฐ๋ฅผ ์ดํ–‰ํ•˜๋Š” ํ˜•ํƒœ๋กœ ENISA๊ฐ€ 2025๋…„ 5์›” 13์ผ ์ •์‹ ๊ฐ€๋™ํ–ˆ๋‹ค. F1 CRA์˜ “์ทจ์•ฝ์  ๋ชจ๋‹ˆํ„ฐ๋ง” ์š”๊ฑด์—์„œ EUVD๋Š” 1์ฐจ ๋ชจ๋‹ˆํ„ฐ๋ง ์ถœ์ฒ˜๋กœ ํ™œ์šฉ ๊ฐ€๋Šฅํ•˜๋‹ค. EUVD๋Š” ๋…์ž์  ์‹๋ณ„์ž(EUVD-YYYY-NNNNNN)๋ฅผ ์‚ฌ์šฉํ•˜๋˜ CVE ID์™€ CVSS ์ ์ˆ˜๋ฅผ ํ•จ๊ป˜ ํ‘œ๊ธฐํ•œ๋‹ค. SRP์™€๋Š” ๋ณ„๊ฐœ ์‹œ์Šคํ…œ์œผ๋กœ, SRP๋Š” ์ œ์กฐ์‚ฌ โ†’ ๋‹น๊ตญ ํ†ต์ง€ ์ฑ„๋„์ด๊ณ  EUVD๋Š” ๊ณต๊ฐœ ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค๋‹ค. B4ยทF2


7. ์ตœ์‹  ๋™ํ–ฅ (2025~2026)

2024๋…„ 12์›” ๋ฐœํšจ ์ดํ›„ ๊ทœ์ œ ํ™˜๊ฒฝ์€ ์œ„์ž„๋ฒ•ยท์‹œํ–‰๊ทœ์น™ยท๊ฐ€์ด๋˜์Šค ์„ธ ๋ฐฉํ–ฅ์—์„œ ๊ตฌ์ฒดํ™”๋๋‹ค.

์‹œํ–‰๊ทœ์น™ (EU) 2025/2392๋Š” 2025๋…„ 11์›” 28์ผ ์ฑ„ํƒ๋ผ 12์›” 21์ผ ๋ฐœํšจ๋๋‹ค. CRA Annex IIIยทIV์˜ “์ค‘์š”(important)ยท์ค‘๋Œ€(critical) ์ œํ’ˆ"์„ 28๊ฐœ ๋ฒ”์ฃผ๋กœ ๊ตฌ๋ถ„ํ•ด Class IยทClass IIยท์ค‘๋Œ€ ์„ธ ๋“ฑ๊ธ‰์— ๋ฐฐ์น˜ํ•˜๋Š” ๊ธฐ์ˆ  ์ •์˜๋ฅผ ํ™•์ •ํ•œ๋‹ค. ์ œ์กฐ์‚ฌ๊ฐ€ ์ž์‚ฌ ์ œํ’ˆ์˜ ์ ํ•ฉ์„ฑ ํ‰๊ฐ€ ๊ฒฝ๋กœ๋ฅผ ํŒ๋‹จํ•  1์ฐจ ๋ฒ•์  ๊ธฐ์ค€์ด ์ด ๊ทœ์น™์ด๋‹ค. A3

์œ„์ž„๋ฒ• (EU) 2026/881์€ 2025๋…„ 12์›” 11์ผ ์ฑ„ํƒ๋ผ 2026๋…„ 4์›” 20์ผ ๊ด€๋ณด์— ์‹ค๋ ธ๋‹ค. CSIRT ๊ฐ„ ํ†ต์ง€ ์ „ํŒŒ ์ง€์—ฐ ์กฐ๊ฑด์˜ ๋ฒ•์ œํ™”๊ฐ€ ํ•ต์‹ฌ์ด๋‹ค(ยง4.4 ์ฐธ์กฐ). A2

๊ฐ€์ด๋˜์Šค ๋ฌธ์„œ๋Š” ๋‘ ๋‹จ๊ณ„๋กœ ๋‚˜์™”๋‹ค. 2025๋…„ 12์›” 3์ผ Commission ์ฒซ ๊ณต์‹ FAQ๊ฐ€ ๋ฐœํ–‰๋๊ณ (12์›” 19์ผ ์—…๋ฐ์ดํŠธ), ์œ„ํ—˜ ํ‰๊ฐ€์˜ ๋ฒ”์œ„ยท๋ฐ˜๋ณต์„ฑ๊ณผ “์˜๋„๋œ ์‚ฌ์šฉ(intended purpose)” ๊ฐœ๋…์„ ๋น„๊ตฌ์†์ ์ด์ง€๋งŒ ์ฒ˜์Œ์œผ๋กœ ํ’€์–ด๋ƒˆ๋‹ค. ์ด์–ด 2026๋…„ 3์›” 3์ผ์—๋Š” CRA ์ œ26์กฐ์— ๋”ฐ๋ฅธ ์ฒซ ๊ฐ€์ด๋˜์Šค ์ดˆ์•ˆ์ด ๊ณต๊ฐœ๋๋‹ค. ์ด 75์ชฝ ๋ถ„๋Ÿ‰ ์ค‘ ์•ฝ 4๋ถ„์˜ 1์ด ์˜คํ”ˆ์†Œ์Šค ์ŠคํŠœ์–ด๋“œ ์ •์˜์— ํ• ์• ๋œ ์ด ์ดˆ์•ˆ์€ ์›๊ฒฉ ๋ฐ์ดํ„ฐ ์ฒ˜๋ฆฌ ์†”๋ฃจ์…˜, ์ž์œ ยท์˜คํ”ˆ์†Œ์Šค ์†Œํ”„ํŠธ์›จ์–ด, ์ง€์› ๊ธฐ๊ฐ„, CRA์™€ NIS2ยทDORA ๋“ฑ ํƒ€ ๊ทœ์ •๊ณผ์˜ ์ƒํ˜ธ๊ด€๊ณ„๋ฅผ ๋‹ค๋ค˜๋‹ค. 3์›” 31์ผ ์˜๊ฒฌ์ˆ˜๋ ด์ด ๋งˆ๊ฐ๋์œผ๋‚˜ ์ตœ์ข…๋ณธ์€ 2026๋…„ 5์›” ํ˜„์žฌ๊นŒ์ง€ ๋ฏธ๊ณตํ‘œ๋‹ค. E3

์˜คํ”ˆ์†Œ์Šค ์ปค๋ฎค๋‹ˆํ‹ฐ์˜ ์ง‘๋‹จ ๋Œ€์‘์€ 2024๋…„ ์ดˆ์•ˆ ์‹ฌ์˜ ๊ณผ์ •์—์„œ ์•„ํŒŒ์น˜(Apache Software Foundation), ์ดํด๋ฆฝ์Šค(Eclipse Foundation), ํŒŒ์ด์ฌ(Python Software Foundation), ๋Ÿฌ์ŠคํŠธ(Rust Foundation) ๋“ฑ ์ฃผ์š” ์žฌ๋‹จ๋“ค์˜ ๊ณต๋™ ์„ฑ๋ช…์œผ๋กœ ๊ฐ€์‹œํ™”๋๋‹ค. ์ดํ›„ Open Regulatory Compliance Working Group(ORC WG)์ด ๋ฐœ์กฑํ•ด ์ŠคํŠœ์–ด๋“œ์˜ ์˜๋ฌด ๋ฒ”์œ„๋ฅผ ์ •๋ฆฌํ•œ ๋ฐฑ์„œ๋ฅผ ๊ณต๊ฐœํ•˜๊ณ , OpenSSF๋Š” SBOM ํ‘œ์ค€ ์ •๋ ฌ ๋ฐฉํ–ฅ์„ 2025๋…„ 10์›” 22์ผ ๊ณต๊ฐœํ–ˆ๋‹ค. D1

๊ฐ€์žฅ ์ง€์†์ ์œผ๋กœ ์ œ๊ธฐ๋˜๋Š” ์Ÿ์ ์€ 24์‹œ๊ฐ„ ํ†ต์ง€์˜ ์‹คํšจ์„ฑ์ด๋‹ค. HackerOne ๋“ฑ ๋ณด์•ˆ ์—ฐ๊ตฌ์ž ์ธก์€ “ํŒจ์น˜๊ฐ€ ์ค€๋น„๋˜๊ธฐ ์ „์— ์ทจ์•ฝ์  ์กด์žฌ ์‚ฌ์‹ค์ด ๋‹น๊ตญ์— ํ†ต์ง€๋˜๋ฉด ๋ฏธ์™„ํ™” ์ทจ์•ฝ์ ์ด ๋…ธ์ถœ๋  ์œ„ํ—˜์ด ์žˆ๋‹ค"๋Š” ์ฃผ์žฅ์„ 2024๋…„๋ถ€ํ„ฐ ์ผ๊ด€๋˜๊ฒŒ ์ œ๊ธฐํ•ด์™”๋‹ค. E4 ์œ„์ž„๋ฒ• (EU) 2026/881์€ CSIRT ๊ฐ„ ์ „ํŒŒ ์ง€์—ฐ ์กฐ๊ฑด๋งŒ ์‹ ์„คํ–ˆ์„ ๋ฟ, ์ œ์กฐ์‚ฌ โ†’ CSIRT 24์‹œ๊ฐ„ ์‹œํ•œ ์ž์ฒด์—๋Š” ์†๋Œ€์ง€ ์•Š์•˜๋‹ค.


8. ํ•œ๊ตญ ๊ธฐ์—… ๊ด€์  โ€” 4๊ฐœ์›” ์•ˆ์— ํ•ด์•ผ ํ•  ๊ฒƒ

8.1 ์ ์šฉ ์—ฌ๋ถ€ ์ง„๋‹จ

2026๋…„ 9์›” 11์ผ์ด ์‹œํ•œ์ธ ๋ณด๊ณ  ์˜๋ฌด๊ฐ€ ์ž์‚ฌ์— ์ ์šฉ๋˜๋Š”์ง€๋ฅผ ๋จผ์ € ํ™•์ •ํ•ด์•ผ ํ•œ๋‹ค. ํ™•์ธํ•  ํ•ญ๋ชฉ์€ ๋‹ค์Œ ์…‹์ด๋‹ค.

EU ์‹œ์žฅ์— ์ œํ’ˆ์ด ์œ ํ†ต๋˜๋Š”๊ฐ€ โ€” ์งํŒยท์žฌํŒ๋งคยทOEM ๊ณต๊ธ‰ ๋ชจ๋‘ ํฌํ•จ๋˜๋ฉฐ, EU ๋ฒ•์ธ์ด ์—†์–ด๋„ ํ•œ๊ตญ ๋ณธ์‚ฌ๊ฐ€ EU์— ์ง์ˆ˜์ถœํ•˜๋ฉด ์ ์šฉ๋œ๋‹ค. ์ œํ’ˆ์ด ๋””์ง€ํ„ธ ์š”์†Œ๋ฅผ ๊ฐ€์ง„ ์ œํ’ˆ์ธ๊ฐ€ โ€” ๋„คํŠธ์›Œํฌ๋‚˜ ์žฅ์น˜์™€ ๋ฐ์ดํ„ฐ ์—ฐ๊ฒฐ์ด ๊ฐ€๋Šฅํ•œ ์†Œํ”„ํŠธ์›จ์–ด๋‚˜ ํ•˜๋“œ์›จ์–ด๋ผ๋ฉด ํ•ด๋‹นํ•œ๋‹ค. ๋ถ€๋ฌธ๋ณ„ ์‚ฌ์ด๋ฒ„๋ณด์•ˆ ์ž…๋ฒ•์˜ ์ ์šฉ ์—ฌ๋ถ€ โ€” ์˜๋ฃŒ๊ธฐ๊ธฐ๋‚˜ ์ž๋™์ฐจ ์•ˆ์ „ ๋“ฑ ๋” ์—„๊ฒฉํ•œ ๊ทœ์ œ๊ฐ€ ์ด๋ฏธ ์ ์šฉ๋˜๋Š” ์˜์—ญ์ด๋ฉด CRA ์ ์šฉ์ด ๋ฐฐ์ œ๋  ์ˆ˜ ์žˆ๋‹ค.

๋ ˆ๊ฑฐ์‹œ ์ œํ’ˆ๋„ ์ ์šฉ ๋Œ€์ƒ์ด๋‹ค. ์ด๋ฏธ EU ์‹œ์žฅ์— ์ถœ์‹œ๋œ ์ œํ’ˆ์—๋„ 9์›” 11์ผ๋ถ€ํ„ฐ ๋ณด๊ณ  ์˜๋ฌด๊ฐ€ ๋ฐœ์ƒํ•œ๋‹ค๋Š” ์ ์€ ๋งŽ์€ ๊ธฐ์—…์ด ๊ฐ„๊ณผํ•˜๊ธฐ ์‰ฌ์šด ๋ถ€๋ถ„์ด๋‹ค. E1

8.2 ์ค€๋น„ ๋‹จ๊ณ„

9์›” 11์ผ๊นŒ์ง€ ๊ฐ–์ถฐ์•ผ ํ•  ๊ฒƒ์€ ์ธ์ฆ์„œ๊ฐ€ ์•„๋‹ˆ๋ผ ๋ณด๊ณ  ์›Œํฌํ”Œ๋กœ์šฐ๋‹ค. ์ทจ์•ฝ์ ยท์‚ฌ๊ณ ๋ฅผ ์ธ์ง€ํ•œ ์ˆœ๊ฐ„๋ถ€ํ„ฐ 24์‹œ๊ฐ„ ์•ˆ์— ์กฐ๊ธฐ ๊ฒฝ๋ณด๋ฅผ ๋ฐœ์‹ ํ•  ์ˆ˜ ์žˆ๋Š” ์ธ์  ์ฒด๊ณ„์™€ ๊ธฐ์ˆ  ์—ฐ๊ฒฐ์ด ํ•„์š”ํ•˜๋‹ค. ์ด๋ฅผ ์œ„ํ•ด ์˜จ์ฝœ(on-call) ์ฒด๊ณ„, ์˜์‚ฌ๊ฒฐ์ • ๊ถŒํ•œ, ์™ธ๋ถ€ ์ปค๋ฎค๋‹ˆ์ผ€์ด์…˜ ๋‹ด๋‹น์ž๊ฐ€ ์‚ฌ์ „์— ์ง€์ •๋˜์–ด์•ผ ํ•œ๋‹ค.

๋ชจ๋“  ์ถœ๊ณ  ๋ฒ„์ „์— ๋Œ€ํ•œ SBOM์„ SPDX ๋˜๋Š” CycloneDX ํ˜•์‹์œผ๋กœ ์ž๋™ ์ƒ์„ฑยท๋ณด๊ด€ํ•˜๋Š” ํŒŒ์ดํ”„๋ผ์ธ๋„ 9์›” 11์ผ๊นŒ์ง€ ํ•„์š”ํ•˜๋‹ค. BSI TR-03183-2 v2.1.0์˜ ํ•„๋“œ ๋งคํ•‘์„ ํ˜„์‹ค์  ์ฐธ์กฐ์ ์œผ๋กœ ํ™œ์šฉํ•  ์ˆ˜ ์žˆ๋‹ค. G1

SRP ํ†ตํ•ฉ ์‹œํ—˜์€ ENISA๊ฐ€ API ์‚ฌ์–‘์„ ๊ณต๊ฐœํ•˜๋Š” ์ฆ‰์‹œ ์ฐฉ์ˆ˜ํ•ด์•ผ ํ•œ๋‹ค. 2026๋…„ 5์›” ํ˜„์žฌ ์‚ฌ์–‘์ด ์—†๋Š” ์ƒํƒœ์ด๋ฏ€๋กœ, ๋‹ด๋‹นํŒ€์ด ๋ฐœํ‘œ๋ฅผ ๋ชจ๋‹ˆํ„ฐ๋งํ•˜๊ณ  ์‚ฌ์–‘ ๊ณต๊ฐœ ์งํ›„ ๋ฐ”๋กœ ์ฐฉ์ˆ˜ํ•  ์ˆ˜ ์žˆ๋Š” ์ค€๋น„ ์ƒํƒœ๋ฅผ ์œ ์ง€ํ•ด์•ผ ํ•œ๋‹ค.

EUVD(https://euvd.enisa.europa.eu)๋ฅผ ์ž์‚ฌ ์ œํ’ˆ์˜ ๊ตฌ์„ฑ ์š”์†Œ์™€ ์—ฐ๊ณ„ํ•ด ๋ชจ๋‹ˆํ„ฐ๋งํ•˜๋Š” ์ ˆ์ฐจ๋„ ํ•„์š”ํ•˜๋‹ค. CVE ID์™€ EUVD-YYYY-NNNNNN ๋‘ ์‹๋ณ„์ž ์ฒด๊ณ„๋ฅผ ์ฒ˜๋ฆฌํ•  ์ˆ˜ ์žˆ์–ด์•ผ ํ•œ๋‹ค.

2027๋…„ 12์›” 11์ผ๊นŒ์ง€๋Š” ํ•œ ๋‹จ๊ณ„ ๋” ๋‚˜์•„๊ฐ€์•ผ ํ•œ๋‹ค. CE ๋งˆํ‚น๊ณผ ์ ํ•ฉ์„ฑ ํ‰๊ฐ€, ์ž์‚ฌ ์ œํ’ˆ ๋“ฑ๊ธ‰์— ๋งž๋Š” CAB ์„ ์ •(Class I ์ด์ƒ์ด๋ผ๋ฉด), ์กฐํ™” ํ‘œ์ค€ ๋ฐœํ–‰ ํ›„ ์ ํ•ฉ์„ฑ ์„ ์–ธ์ด ํ•„์š”ํ•˜๋‹ค. CEN/CENELEC์˜ ์ˆ˜ํ‰ ํ‘œ์ค€(2026-08-30 ๋ชฉํ‘œ)๊ณผ ์ˆ˜์ง ํ‘œ์ค€(2026-10-30 ๋ชฉํ‘œ) ๋ฐœํ–‰์„ ์ฃผ์‹œํ•ด์•ผ ํ•œ๋‹ค.

8.3 ํƒ€ ๊ด€ํ• ๊ถŒ ๋น„๊ต

ํ•ญ๋ชฉEU CRA๋ฏธ๊ตญ (EO 14028ยทCISA KEV)์˜๊ตญ PSTI Actํ•œ๊ตญ SW๊ณต๊ธ‰๋ง ๊ฐ€์ด๋“œ๋ผ์ธ
์ ์šฉ ๋Œ€์ƒEU ์‹œ์žฅ์˜ ๋ชจ๋“  PDE์—ฐ๋ฐฉ ์กฐ๋‹ฌ SW (๋ฏผ๊ฐ„์€ ๊ถŒ๊ณ )์†Œ๋น„์ž์šฉ ์—ฐ๊ฒฐ ์ œํ’ˆ๋ชจ๋“  SW (๋น„๊ฐ•์ œ)
๋ฒ•์  ๊ฐ•์ œ๋ ฅEU ๊ทœ์ • โ€” ์ง์ ‘ ํšจ๋ ฅํ–‰์ •๋ช…๋ นยท๊ตฌ์†์„ฑ ์šด์˜ ์ง€์นจ(BOD)๋ฒ•๋ฅ ํ–‰์ • ๊ฐ€์ด๋“œ๋ผ์ธ
๋ณด๊ณ  ์‹œํ•œ24h/72h/14dKEV๋ณ„ ๊ธฐํ•œ๋ณด๊ณ  ์ฑ„๋„ ์œ ์ง€ ์˜๋ฌด๋งŒ์—†์Œ
SBOM์˜๋ฌด (SPDX/CycloneDX)์—ฐ๋ฐฉ ์กฐ๋‹ฌ SW ๊ถŒ๊ณ  (NTIA)์—†์ŒSSDF ๊ธฐ๋ฐ˜ ๊ถŒ๊ณ 
์‹œํ–‰2026-09-11 (๋ณด๊ณ ) ยท 2027-12-11 (์ „๋ฉด)2021-052024-04-292024-05

C6ยทE2

CRA์˜ ๋‘๋“œ๋Ÿฌ์ง„ ํŠน์ง•์€ ์ˆ˜ํ‰์  ์ ์šฉ(IoTยทSWยท์ž„๋ฒ ๋””๋“œ๋ฅผ ๊ฐ€๋ฆฌ์ง€ ์•Š์Œ)๊ณผ ์ง์ ‘ ํšจ๋ ฅ์ด๋‹ค. ํ•œ๊ตญ SW๊ณต๊ธ‰๋ง ๊ฐ€์ด๋“œ๋ผ์ธ 1.0์€ NIST SSDF ๊ธฐ๋ฐ˜์œผ๋กœ 30๊ฐœ ์ ๊ฒ€ ํ•ญ๋ชฉ๊ณผ SBOM ์ ˆ์ฐจ๋ฅผ ๊ถŒ๊ณ ํ•˜๋Š”๋ฐ, CRA ๋ณธ์งˆ ์š”๊ฑด๊ณผ SSDF๊ฐ€ ๊ธฐ๋Šฅ์ ์œผ๋กœ ์ •๋ ฌ๋˜๋ฏ€๋กœ ๊ตญ๋‚ด ๊ฐ€์ด๋“œ๋ผ์ธ์„ ๋”ฐ๋ผ ๊ตฌ์ถ•ํ•œ ์ฒด๊ณ„๋Š” CRA ๋Œ€์‘์˜ ์ถœ๋ฐœ์ ์œผ๋กœ ํ™œ์šฉ ๊ฐ€๋Šฅํ•˜๋‹ค. ๋‹ค๋งŒ ํ•œ๊ตญ ๊ฐ€์ด๋“œ๋ผ์ธ์€ ๊ถŒ๊ณ ์ด๊ณ  CRA๋Š” ๊ณผ์ง•๊ธˆ ์ฒด๊ณ„๋ฅผ ๊ฐ–์ถ˜ ๋ฒ•์  ์˜๋ฌด์ด๋ฉฐ, CRA๋Š” ๊ทธ ์œ„์— ๋ณ„๋„์˜ ๋ณด๊ณ  ์˜๋ฌด๋ฅผ ์ถ”๊ฐ€ํ•œ๋‹ค.


9. ๊ฒฐ๋ก ๊ณผ ๊ถŒ๊ณ 

2026๋…„ 9์›” 11์ผ์€ CRA๊ฐ€ ์ œ์กฐ์‚ฌ์—๊ฒŒ ์ฒ˜์Œ์œผ๋กœ ์‹ค์งˆ์ ์ธ ์ดํ–‰ ์˜๋ฌด๋ฅผ ๋ถ€๊ณผํ•˜๋Š” ๋‚ ์ด๋‹ค. CE ๋งˆํ‚น๊ณผ ์ ํ•ฉ์„ฑ ํ‰๊ฐ€๋Š” 2027๋…„ 12์›” 11์ผ์ด ์‹œํ•œ์ด์ง€๋งŒ, ๋ณด๊ณ  ์›Œํฌํ”Œ๋กœ์šฐ ๊ตฌ์ถ•์€ ๊ทธ ์ „์— ์™„๋ฃŒ๋˜์–ด์•ผ ํ•œ๋‹ค.

ํ•œ๊ตญ ๊ธฐ์—…์—๊ฒŒ ๊ฐ€์žฅ ๋จผ์ € ํ•„์š”ํ•œ ์ž‘์—…์€ ์„ธ ๊ฐ€์ง€๋‹ค. ์ž์‚ฌ ์ œํ’ˆ์ด CRA ์ ์šฉ ๋Œ€์ƒ์ธ์ง€ ํ™•์ •ํ•˜๊ณ , ํ•ด๋‹นํ•œ๋‹ค๋ฉด ์ œํ’ˆ์ด ๊ธฐ๋ณธยท์ค‘์š”ยท์ค‘๋Œ€ ์–ด๋А ๋“ฑ๊ธ‰์— ํ•ด๋‹นํ•˜๋Š”์ง€ ์‹œํ–‰๊ทœ์น™ (EU) 2025/2392 ๊ธฐ์ค€์œผ๋กœ ํŒ๋‹จํ•˜๋Š” ๊ฒƒ์ด ์šฐ์„ ์ด๋‹ค. ๋“ฑ๊ธ‰์— ๋”ฐ๋ผ 2027๋…„์˜ ์ ํ•ฉ์„ฑ ํ‰๊ฐ€ ๊ฒฝ๋กœ์™€ ๊ทธ์— ์†Œ์š”๋˜๋Š” ์ค€๋น„ ๊ธฐ๊ฐ„์ด ๋‹ฌ๋ผ์ง€๊ธฐ ๋•Œ๋ฌธ์ด๋‹ค.

๋ณด๊ณ  ์ธํ”„๋ผ์™€ ๋‚ด๋ถ€ ํ”Œ๋ ˆ์ด๋ถ ๊ตฌ์„ฑ์ด ๊ทธ ๋‹ค์Œ์ด๋‹ค. SRP ์‚ฌ์–‘์ด ์•„์ง ๊ณต๊ฐœ๋˜์ง€ ์•Š์•˜์ง€๋งŒ, ์ธ์  ์ฒด๊ณ„์™€ ๋‚ด๋ถ€ ์ ˆ์ฐจ๋Š” ์‚ฌ์–‘ ๊ณต๊ฐœ์™€ ๋ฌด๊ด€ํ•˜๊ฒŒ ์ง€๊ธˆ ๋ฐ”๋กœ ์„ค๊ณ„ํ•  ์ˆ˜ ์žˆ๋‹ค. ENISA ๋ฐœํ‘œ๋ฅผ ๋ชจ๋‹ˆํ„ฐ๋งํ•˜๋ฉด์„œ API ์‚ฌ์–‘์ด ๋‚˜์˜ค๋Š” ์ฆ‰์‹œ ํ†ตํ•ฉ ์‹œํ—˜์— ์ฐฉ์ˆ˜ํ•  ์ˆ˜ ์žˆ๋„๋ก ํŒ€์„ ์ค€๋น„์‹œ์ผœ์•ผ ํ•œ๋‹ค.

SBOM ํŒŒ์ดํ”„๋ผ์ธ ์ž๋™ํ™”๋Š” 9์›” 11์ผ๊นŒ์ง€ ์™„๋ฃŒํ•ด์•ผ ํ•œ๋‹ค. ์ถœ๊ณ  ๋ฒ„์ „๋งˆ๋‹ค SPDX ๋˜๋Š” CycloneDX ํ˜•์‹์˜ SBOM์ด ์ž๋™ ์ƒ์„ฑยท๋ณด๊ด€๋˜์ง€ ์•Š์œผ๋ฉด ๋ณด๊ณ  ์˜๋ฌด๋ฅผ ์ดํ–‰ํ•  ๋•Œ ํ•„์š”ํ•œ ์†Œํ”„ํŠธ์›จ์–ด ๊ตฌ์„ฑ ์ •๋ณด ์ž์ฒด๊ฐ€ ์—†๊ฒŒ ๋œ๋‹ค. A1ยทB2ยทE2ยทE4


์ฐธ๊ณ  ์ž๋ฃŒ

A. ๋ฒ•๋ นยท๊ทœ์ œ ์›๋ฌธ (1์ฐจ)

A1. European Parliament and Council (2024). Regulation (EU) 2024/2847 of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act). Official Journal of the European Union, OJ L, 2024/2847, 20.11.2024. https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng (์ ‘์†: 2026-05-12). โ†ฉ

A2. European Commission (2025). Commission Delegated Regulation (EU) 2026/881 of 11 December 2025 supplementing Regulation (EU) 2024/2847 with regard to the conditions for delaying dissemination of notifications of actively exploited vulnerabilities and severe incidents. Published 20 April 2026. https://eur-lex.europa.eu/eli/reg_del/2026/881/oj (์ ‘์†: 2026-05-12). โ†ฉ

A3. European Commission (2025). Commission Implementing Regulation (EU) 2025/2392 of 28 November 2025 laying down technical descriptions of categories of important and critical products with digital elements. OJ L, 2025/2392. https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=OJ:L_202502392 (์ ‘์†: 2026-05-12). โ†ฉ

A4. European Parliament and Council (2022). Directive (EU) 2022/2555 of 14 December 2022 on measures for a high common level of cybersecurity across the Union (NIS2 Directive). OJ L 333, 27.12.2022. https://eur-lex.europa.eu/eli/dir/2022/2555/oj/eng (์ ‘์†: 2026-05-12). โ†ฉ

A5. European Parliament and Council (2016). Regulation (EU) 2016/679 โ€” General Data Protection Regulation (GDPR). OJ L 119, 4.5.2016. https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679 (์ ‘์†: 2026-05-12). โ†ฉ


B. ๋ฐœํ–‰ ๊ธฐ๊ด€ ๊ณต์‹ ๋ฌธ์„œ

B1. European Commission, DG CNECT (2026). Cyber Resilience Act โ€” Shaping Europe’s digital future. https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act (์ ‘์†: 2026-05-12). โ†ฉ

B2. European Commission, DG CNECT (2026). Cyber Resilience Act โ€” Reporting obligations. https://digital-strategy.ec.europa.eu/en/policies/cra-reporting (์ ‘์†: 2026-05-12). โ†ฉ

B3. European Commission, DG CNECT (2024). The Cyber Resilience Act โ€” Summary of the legislative text. https://digital-strategy.ec.europa.eu/en/policies/cra-summary (์ ‘์†: 2026-05-12). โ†ฉ

B4. ENISA (2026). Single Reporting Platform (SRP). https://www.enisa.europa.eu/topics/product-security-and-certification/single-reporting-platform-srp (์ ‘์†: 2026-05-12). โ†ฉ

B5. ENISA & Joint Research Centre (2024). Cyber Resilience Act Requirements Standards Mapping โ€” Joint Analysis. April 2024. https://www.enisa.europa.eu/publications/cyber-resilience-act-requirements-standards-mapping (์ ‘์†: 2026-05-12). โ†ฉ

B6. ENISA (2025). Cyber Resilience Act implementation via EUCC and its applicable technical elements. 26 February 2025. https://certification.enisa.europa.eu/publications/cyber-resilience-act-implementation-eucc-and-its-applicable-technical-elements_en (์ ‘์†: 2026-05-12). โ†ฉ


C. ํ‘œ์ค€ยทํ”„๋ ˆ์ž„์›Œํฌ

C1. ISO/IEC (2019). ISO/IEC 30111:2019 โ€” Information technology โ€” Security techniques โ€” Vulnerability handling processes. Edition 2. https://www.iso.org/standard/69725.html (์ ‘์†: 2026-05-12). โ†ฉ

C2. ISO/IEC (2018). ISO/IEC 29147:2018 โ€” Information technology โ€” Security techniques โ€” Vulnerability disclosure. Edition 2. https://www.iso.org/standard/72311.html (์ ‘์†: 2026-05-12). โ†ฉ

C3. ISO/IEC (2021). ISO/IEC 5962:2021 โ€” Information technology โ€” SPDXยฎ Specification V2.2.1. https://www.iso.org/standard/81870.html (์ ‘์†: 2026-05-12). โ†ฉ

C4. The Linux Foundation / SPDX Project (2024). SPDX Specifications (current: v3.0). https://spdx.dev/specifications/ (์ ‘์†: 2026-05-12). โ†ฉ

C5. OWASP Foundation / Ecma International (2025). CycloneDX Specification v1.7 / ECMA-424, 2nd Edition. ECMA-424 published 2025-12-10. https://cyclonedx.org/specification/overview/ (์ ‘์†: 2026-05-12). โ†ฉ

C6. Souppaya, M., Scarfone, K., Dodson, D. โ€” NIST (2022). Secure Software Development Framework (SSDF) Version 1.1: Recommendations for Mitigating the Risk of Software Vulnerabilities. NIST SP 800-218. DOI: 10.6028/NIST.SP.800-218. https://csrc.nist.gov/publications/detail/sp/800-218/final (์ ‘์†: 2026-05-12). โ†ฉ


D. ํ•™์ˆ ยท์ •์ฑ… ์—ฐ๊ตฌ

D1. OpenSSF Best Practices WG / Global Cyber Policy WG (2025). Cyber Resilience Act (CRA) Brief Guide for Open Source Software (OSS) Developers. Lead author: David A. Wheeler. https://best.openssf.org/CRA-Brief-Guide-for-OSS-Developers.html (์ ‘์†: 2026-05-12). โ†ฉ


E. ์—…๊ณ„ยท๋ฒ•๋ฌด๋ฒ•์ธ ๋ถ„์„

E1. Bird & Bird LLP (2026). CRA’s phased entry into application starts in September 2026. Bird & Bird Insights. https://www.twobirds.com/en/insights/2026/cra%E2%80%99s-phased-entry-into-application-starts-in-september-2026 (์ ‘์†: 2026-05-12). โ†ฉ

E2. DLA Piper โ€” Blum, L. & Moylan Burke, L. (2026). Cyber Resilience Act: What you need to know and what you need to be doing. 19 February 2026. https://www.dlapiper.com/en/insights/publications/2026/02/cyber-resilience-act-what-you-need-to-know-and-what-you-need-to-be-doing (์ ‘์†: 2026-05-12). โ†ฉ

E3. DLA Piper (2026). Cyber Resilience Act: Commission unveils draft implementation guidance. Law in Tech. https://www.dlapiper.com/en-us/insights/publications/law-in-tech/2026/cyber-resilience-act (์ ‘์†: 2026-05-12). โ†ฉ

E4. HackerOne โ€” Eldering, B. (2026). EU Cyber Resilience Act: Preparing Your VDP for 2026 Reporting Requirements. https://www.hackerone.com/blog/cyber-resilience-act-vdp-2026-reporting-readiness (์ ‘์†: 2026-05-12). โ†ฉ


F. ์–ธ๋ก ยท๊ณต์‹ ๋ฐœํ‘œ (๋ณด์กฐ)

F1. ENISA (2025). Consult the European Vulnerability Database to enhance your digital security! News release, 13 May 2025. https://www.enisa.europa.eu/news/consult-the-european-vulnerability-database-to-enhance-your-digital-security (์ ‘์†: 2026-05-12). โ†ฉ

F2. European Commission (2025). EU launches a European vulnerability database to boost its digital security. https://digital-strategy.ec.europa.eu/en/news/eu-launches-european-vulnerability-database-boost-its-digital-security (์ ‘์†: 2026-05-12). โ†ฉ


G. ํšŒ์›๊ตญ ๊ธฐ๊ด€ ๊ธฐ์ˆ  ๊ฐ€์ด๋“œ

G1. Bundesamt fรผr Sicherheit in der Informationstechnik (BSI) (2025). Technical Guideline TR-03183-2 v2.1.0 โ€” Cyber Resilience Requirements for Manufacturers and Products, Part 2: Software Bill of Materials (SBOM). August 2025. ์š”์ง€ ์ •๋ฆฌ: Sbomify, EU Cyber Resilience Act (CRA) SBOM Requirements. https://sbomify.com/compliance/eu-cra/ (์ ‘์†: 2026-05-12). โ†ฉ



์กฐ์‚ฌ ๊ธฐ์ค€์ผ: 2026-05-12 ยท ๊ฒ€์ฆ: 2026-05-17 (CONDITIONAL PASS, ๊ถŒ์žฅ ์ˆ˜์ • 2๊ฑด ๋ฐ˜์˜) 1์ฐจ ์ถœ์ฒ˜: Regulation (EU) 2024/2847 (EUR-Lex), ์œ ๋Ÿฝ์œ„์›ํšŒ ๊ณต์‹ ํŽ˜์ด์ง€, ENISA, ISO/IEC ํ‘œ์ค€, BSI TR-03183-2

Rockchip๊ณผ FFmpeg์˜ ๋ผ์ด์„ ์Šค ๋ถ„์Ÿ ์‚ฌ๋ก€

์•ˆ๋…•ํ•˜์„ธ์š”.

์ตœ๊ทผ ์ž„๋ฒ ๋””๋“œ ๋ฆฌ๋ˆ…์Šค ์—…๊ณ„์—์„œ ํ™”์ œ๊ฐ€ ๋œ Rockchip๊ณผ FFmpeg์˜ ๋ผ์ด์„ ์Šค ๋ถ„์Ÿ(2025-2026) ์‚ฌ๋ก€๋ฅผ ์ •๋ฆฌํ•ด ๋ณด์•˜์Šต๋‹ˆ๋‹ค. ์ด ์‚ฌ๋ก€๋Š” ๋‹จ์ˆœํžˆ ํ•œ ๊ธฐ์—…์˜ ์‹ค์ˆ˜๊ฐ€ ์•„๋‹ˆ๋ผ, ํ•˜๋“œ์›จ์–ด ๋ฒค๋”(SoC Vendor)๊ฐ€ ์ œ๊ณตํ•˜๋Š” SDK/BSP๋ฅผ ๊ทธ๋Œ€๋กœ ์‚ฌ์šฉํ•  ๋•Œ ๋ฐœ์ƒํ•  ์ˆ˜ ์žˆ๋Š” ๊ณต๊ธ‰๋ง ๋ฆฌ์Šคํฌ๋ฅผ ๋ณด์—ฌ์ค๋‹ˆ๋‹ค.

1. ์‚ฌ๊ฑด ๊ฐœ์š”: 2025๋…„ GitHub ๋ฆฌํฌ์ง€ํ† ๋ฆฌ ๊ฐ•์ œ ์ค‘๋‹จ

2025๋…„ 12์›”, ์ค‘๊ตญ์˜ ๋Œ€ํ‘œ์ ์ธ ๋ฐ˜๋„์ฒด ๊ธฐ์—… Rockchip์˜ GitHub ๋ฆฌํฌ์ง€ํ† ๋ฆฌ ์ค‘ ํ•˜๋‚˜์ธ rockchip-linux/mpp (Media Process Platform)๊ฐ€ GitHub์— ์˜ํ•ด ๋น„ํ™œ์„ฑํ™”(disabled)๋˜๋Š” ์‚ฌ๊ฑด์ด ๋ฐœ์ƒํ–ˆ์Šต๋‹ˆ๋‹ค. ์ด๋Š” FFmpeg ๊ฐœ๋ฐœ์ž๊ฐ€ ์ œ์ถœํ•œ DMCA(Digital Millennium Copyright Act) Takedown ์š”์ฒญ์— ๋”ฐ๋ฅธ ์กฐ์น˜์˜€์Šต๋‹ˆ๋‹ค.

๊ตฌ๋ถ„๋‚ด์šฉ
๋ฐœ์ƒ ์‹œ๊ธฐ2025๋…„ 12์›” 18์ผ(DMCA ๊ณต์ง€ ๊ฒŒ์‹œ) โ†’ 2025๋…„ 12์›” 26์ผ(GitHub ๋ฆฌํฌ์ง€ํ† ๋ฆฌ ๋น„ํ™œ์„ฑํ™”)
๋Œ€์ƒ ํ”„๋กœ์ ํŠธRockchip Linux MPP (Media Process Platform)
๋ฌธ์ œ ์ œ๊ธฐ์žFFmpeg ๊ฐœ๋ฐœ์ž ๋ฐ ์ปค๋ฎค๋‹ˆํ‹ฐ
ํ•ต์‹ฌ ์œ„๋ฐ˜ ์‚ฌํ•ญLGPL ์ฝ”๋“œ ๋ฌด๋‹จ ๋„์šฉ ๋ฐ ๋ผ์ด์„ ์Šค ์„ธํƒ (LGPL 2.1 โ†’ Apache-2.0)

๋ฌด์—‡์ด ๋ฌธ์ œ์˜€๋‚˜?

Rockchip์€ ์ž์‚ฌ ์นฉ์…‹(RK3588 ๋“ฑ)์˜ ํ•˜๋“œ์›จ์–ด ์˜์ƒ ๊ฐ€์†์„ ์œ„ํ•ด mpp๋ผ๋Š” ๋ฏธ๋“ค์›จ์–ด ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ๋ฅผ ์ œ๊ณตํ•ด ์™”์Šต๋‹ˆ๋‹ค. ๋ฌธ์ œ๋Š” ์ด ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ์˜ ์†Œ์Šค ์ฝ”๋“œ ์ค‘ ์ƒ๋‹น ๋ถ€๋ถ„์ด FFmpeg์˜ libavcodec (ํŠนํžˆ H.265, AV1, VP9 ๋””์ฝ”๋” ๊ด€๋ จ ์ฝ”๋“œ ์ˆ˜์ฒœ ์ค„)์„ ๊ทธ๋Œ€๋กœ ๋ณต์‚ฌํ•œ ๊ฒƒ์œผ๋กœ FFmpeg ์ธก์€ ์ฃผ์žฅํ–ˆ์Šต๋‹ˆ๋‹ค.

๋‹จ์ˆœ ๋ณต์‚ฌ๊ฐ€ ๋ฌธ์ œ๊ฐ€ ๋œ ๊ฒƒ์ด ์•„๋‹ˆ๋ผ, ๋‹ค์Œ ์„ธ ๊ฐ€์ง€ ํ–‰์œ„๊ฐ€ ๊ฒฐํ•ฉ๋˜์–ด ์น˜๋ช…์ ์ธ ์ปดํ”Œ๋ผ์ด์–ธ์Šค ์œ„๋ฐ˜์ด ๋˜์—ˆ์Šต๋‹ˆ๋‹ค.

  1. ์ €์ž‘๊ถŒ ๊ณ ์ง€ ์‚ญ์ œ: ์›๋ณธ ์ฝ”๋“œ(FFmpeg)์— ์žˆ๋˜ ์ €์ž‘๊ถŒ์žยท์ €์ž‘๊ถŒ ํ‘œ์‹œ๋ฅผ ์ œ๊ฑฐํ•จ.
  2. ์ €์ž‘์ž ํ—ˆ์œ„ ์ฃผ์žฅ: Rockchip์ด ํ•ด๋‹น ์ฝ”๋“œ์˜ ์ €์ž‘์ž์ธ ๊ฒƒ์ฒ˜๋Ÿผ ์ฝ”๋ฉ˜ํŠธยทํ—ค๋”๋ฅผ ๋ณ€๊ฒฝํ•จ.
  3. ๋ผ์ด์„ ์Šค ๋ณ€๊ฒฝ: ์›๋ž˜ LGPL 2.1์ธ ์ฝ”๋“œ๋ฅผ Apache 2.0 ๋ผ์ด์„ ์Šค๋กœ ์žฌ๋ฐฐํฌํ•จ.

FFmpeg ์ปค๋ฎค๋‹ˆํ‹ฐ๋Š” 2024๋…„ 2์›” 23์ผ GitHub Issue #530์„ ํ†ตํ•ด ์ด ๋ฌธ์ œ๋ฅผ ๊ณต๊ฐœ์ ์œผ๋กœ ์ œ๊ธฐํ•˜๋ฉฐ ์ธก๋ฉด-by-์ธก๋ฉด(Side-by-Side) ์ฝ”๋“œ ๋น„๊ต ์ฆ๊ฑฐ๊นŒ์ง€ ์ฒจ๋ถ€ํ–ˆ์Šต๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ Rockchip์€ 22๊ฐœ์›”๊ฐ„ ์‚ฌ์‹ค์ƒ ๋ฌต๋ฌต๋ถ€๋‹ต์ด์—ˆ๊ณ , ๊ฒฐ๊ตญ ๋ฒ•์  ์ˆ˜๋‹จ์ธ DMCA Takedown์œผ๋กœ ์ด์–ด์กŒ์Šต๋‹ˆ๋‹ค.

์ฐธ๊ณ : DMCA Takedown์ด๋ž€?
DMCA Takedown์˜ ํŠน์„ฑ์ƒ, ์‹ค์ œ ์นจํ•ด ์—ฌ๋ถ€๊ฐ€ ๋ฒ•์›์—์„œ ํ™•์ •๋˜๊ธฐ ์ „์ด๋ผ๋„, ํ˜ธ์ŠคํŒ… ํ”Œ๋žซํผ(GitHub)์€ ์š”์ฒญ ์ ‘์ˆ˜ ํ›„ 24~72์‹œ๊ฐ„ ๋‚ด์— ์ฝ˜ํ…์ธ ๋ฅผ ์ฐจ๋‹จํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. Rockchip MPP ๋ฆฌํฌ์ง€ํ† ๋ฆฌ๋Š” ํ˜„์žฌ๋„ ๋น„ํ™œ์„ฑํ™” ์ƒํƒœ๋กœ ๋‚จ์•„ ์žˆ์Šต๋‹ˆ๋‹ค.

2. ์ฝ”๋“œ ๋ ˆ๋ฒจ ์นจํ•ด ๋ถ„์„: ๋ฌด์—‡์ด ๋ณต์‚ฌ๋˜์—ˆ๋‚˜?

์นจํ•ด ๋Œ€์ƒ ํŒŒ์ผ ๋ชฉ๋ก

DMCA ๊ณต์ง€(2025-12-18)์—๋Š” ์นจํ•ด๋œ ํŒŒ์ผ์ด ๋ช…์‹œ๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค. ์•„๋ž˜๋Š” ๋ณด๊ณ ๋œ ์ฃผ์š” ์นจํ•ด ํŒŒ์ผ๊ณผ FFmpeg ์›๋ณธ ํŒŒ์ผ์˜ ๋Œ€์‘ ๊ด€๊ณ„์ž…๋‹ˆ๋‹ค.

์ฝ”๋ฑRockchip MPP ์นจํ•ด ํŒŒ์ผ์›๋ณธ FFmpeg ํŒŒ์ผ
AV1mpp/codec/dec/av1/av1d_codec.hlibavcodec/av1dec.h
AV1mpp/codec/dec/av1/av1d_cbs.clibavcodec/cbs_av1.c
AV1mpp/codec/dec/av1/av1d_cbs.hlibavcodec/cbs_av1.h
AV1mpp/codec/dec/av1/av1d_parser2_syntax.clibavcodec/av1_parse.c
H.265mpp/codec/dec/h265/h265d_codec.hlibavcodec/hevcdec.h
H.265mpp/codec/dec/h265/h265d_parser.clibavcodec/hevc_parser.c
H.265mpp/codec/dec/h265/h265d_ps.clibavcodec/hevc_ps.c
VP9mpp/codec/dec/vp9/vp9d_codec.hlibavcodec/vp9.h
VP9mpp/codec/dec/vp9/vp9d_parser.clibavcodec/vp9_parser.c
VP9mpp/codec/dec/vp9/vp9data.hlibavcodec/vp9data.h
VP9mpp/codec/dec/vp9/vpx_rac.clibavcodec/vpx_rac.c
VP9mpp/codec/dec/vp9/vpx_rac.hlibavcodec/vpx_rac.h

์นจํ•ด ํŒจํ„ด 1: ์ €์ž‘๊ถŒ ํ—ค๋” ๊ต์ฒด

๊ฐ€์žฅ ์ง์ ‘์ ์ธ ์ฆ๊ฑฐ๋Š” ํŒŒ์ผ ์ƒ๋‹จ์˜ ์ €์ž‘๊ถŒ ํ—ค๋”(Copyright Header)์ž…๋‹ˆ๋‹ค.
FFmpeg์˜ ์›๋ณธ ํ—ค๋”๋ฅผ ์‚ญ์ œํ•˜๊ณ  Rockchip ๋ช…์˜๋กœ ๊ต์ฒดํ•˜๋Š” ๋ฐฉ์‹์œผ๋กœ ์ด๋ฃจ์–ด์กŒ์Šต๋‹ˆ๋‹ค.

FFmpeg ์›๋ณธ (libavcodec/vpx_rac.h):

/*
 * Copyright (C) 2006  Aurelien Jacobs <aurel@gnuage.org>
 *
 * This file is part of FFmpeg.
 *
 * FFmpeg is free software; you can redistribute it and/or
 * modify it under the terms of the GNU Lesser General Public
 * License as published by the Free Software Foundation; either
 * version 2.1 of the License, or (at your option) any later version.
 */

Rockchip MPP (mpp/codec/dec/vp9/vpx_rac.h) โ€” ๊ต์ฒด ํ›„:

/*
 * Copyright 2022 Rockchip Electronics Co. LTD
 *
 * Licensed under the Apache License, Version 2.0 (the "License");
 * you may not use this file except in compliance with the License.
 * You may obtain a copy of the License at
 *
 *      http://www.apache.org/licenses/LICENSE-2.0
 */

์ €์ž‘๊ถŒ์ž ์ด๋ฆ„(Aurelien Jacobs), LGPL 2.1 ์กฐํ•ญ, FFmpeg ์–ธ๊ธ‰์ด ์‚ฌ๋ผ์ง€๊ณ  Rockchip ๋ช…์˜์˜ Apache-2.0 ํ—ค๋”๋กœ ๋Œ€์ฒด๋˜์—ˆ์Šต๋‹ˆ๋‹ค.

์นจํ•ด ํŒจํ„ด 2: ์ฝ”๋“œ ๋‚ด๋ถ€์— ๋‚จ๊ฒจ์ง„ FFmpeg ํ”์ 

ํ—ค๋”๋งŒ ๋ฐ”๊พธ์—ˆ์„ ๋ฟ, ์ฝ”๋“œ ๋‚ด๋ถ€ ๋กœ์ง์—๋Š” FFmpeg ํ•จ์ˆ˜๋ช…์ด ์ฃผ์„์ด๋‚˜ ์ฐธ์กฐ ํ˜•ํƒœ๋กœ ๊ทธ๋Œ€๋กœ ๋‚จ์•„ ์žˆ์—ˆ์Šต๋‹ˆ๋‹ค. DMCA ๊ณต์ง€๋Š” ์ด ์ ์„ ๋‹ค์Œ๊ณผ ๊ฐ™์ด ๋ช…์‹œํ•ฉ๋‹ˆ๋‹ค.

“the code’s origin is evident from identical structures, comments, and even commented-out calls referencing FFmpeg functions by their original names.”

// Rockchip MPP ์ฝ”๋“œ ๋‚ด๋ถ€์—์„œ ๋ฐœ๊ฒฌ๋œ FFmpeg ํ”์  ํŒจํ„ด (๋ณด๊ณ ๋œ ๋‚ด์šฉ ๊ธฐ๋ฐ˜)

// ff_hevc_decode_nal_vps ์™€ ๋™์ผ ๊ตฌ์กฐ ์ฐธ์กฐ
static int h265d_decode_nal_vps(H265dContext *s, ...) {
    // ff_get_buffer ๋Œ€์‹  mpp_buffer_get ์‚ฌ์šฉ
    // av_log โ†’ mpp_log ๋กœ ๊ต์ฒด
    ...
}
  • ff_๋กœ ์‹œ์ž‘ํ•˜๋Š” FFmpeg ๊ณ ์œ  ํ•จ์ˆ˜๋ช…์ด ์ฃผ์„์— ์ž”๋ฅ˜
  • av_log, av_malloc, AVCodecContext ๋“ฑ FFmpeg ์ „์šฉ ํƒ€์ž…ยทํ•จ์ˆ˜๊ฐ€
    Rockchip ์ž์ฒด API๋กœ ๊ต์ฒด๋˜์—ˆ์ง€๋งŒ, ๊ต์ฒด ํ”์ (์ฃผ์„)์ด ์ฝ”๋“œ์— ๋‚จ์•„ ์žˆ์Œ

์นจํ•ด ํŒจํ„ด 3: ๊ตฌ์กฐยท์•Œ๊ณ ๋ฆฌ์ฆ˜์˜ ์™„์ „ ์ผ์น˜

์•„๋ž˜๋Š” vpx_rac.c (VP9 Range Arithmetic Coder)์˜ ํ•ต์‹ฌ ํ•จ์ˆ˜ ๊ตฌ์กฐ ๋น„๊ต์ž…๋‹ˆ๋‹ค.
์ด ์ˆ˜์ค€์˜ ์ผ์น˜๋Š” ์ˆ˜๋™ ์žฌ๊ตฌํ˜„(๋…๋ฆฝ ์ €์ž‘)์œผ๋กœ๋Š” ๋‚˜์˜ค๊ธฐ ์–ด๋ ต๋‹ค๋Š” ๊ฒƒ์ด ์ปค๋ฎค๋‹ˆํ‹ฐ์˜ ๊ณตํ†ต๋œ ํ‰๊ฐ€์ž…๋‹ˆ๋‹ค.

FFmpeg libavcodec/vpx_rac.c:

static av_always_inline int vpx_rac_get_prob(VPXRangeCoder *c, uint8_t prob)
{
    unsigned int split = (c->range * prob + (256 - prob)) >> 8;
    if (c->value < split) {
        c->range = split;
        return 0;
    } else {
        c->value -= split;
        c->range -= split;
        return 1;
    }
}

Rockchip MPP mpp/codec/dec/vp9/vpx_rac.c (๋ณด๊ณ ๋œ ๊ตฌ์กฐ ๊ธฐ๋ฐ˜):

static MPP_INLINE RK_S32 vpx_rac_get_prob(VPXRangeCoder *c, RK_U8 prob)
{
    RK_U32 split = (c->range * prob + (256 - prob)) >> 8;
    if (c->value < split) {
        c->range = split;
        return 0;
    } else {
        c->value -= split;
        c->range -= split;
        return 1;
    }
}

๋ณ€๊ฒฝ๋œ ๊ฒƒ์€ ๋”ฑ ๋‘ ๊ฐ€์ง€์ž…๋‹ˆ๋‹ค.

  • av_always_inline โ†’ MPP_INLINE (Rockchip ์ž์ฒด ๋งคํฌ๋กœ)
  • uint8_t, unsigned int โ†’ RK_U8, RK_U32 (Rockchip ์ž์ฒด ํƒ€์ž… ์ •์˜)

์•Œ๊ณ ๋ฆฌ์ฆ˜ ๋กœ์ง, ๋ณ€์ˆ˜๋ช…, ์—ฐ์‚ฐ ์ˆœ์„œ, ๋น„ํŠธ ์—ฐ์‚ฐ ๋ฐฉ์‹์€ ์™„์ „ํžˆ ๋™์ผํ•ฉ๋‹ˆ๋‹ค.

๋ฒ•์  ์‹œ์‚ฌ์ : “ํƒ€์ž…์„ ๋ฐ”๊พผ๋‹ค๊ณ  ์ƒˆ ์ฝ”๋“œ๋กœ ์ธ์ •๋˜์ง€๋Š” ์•Š๋Š”๋‹ค”
์ด ์ˆ˜์ค€์˜ ์ˆ˜์ •์€ ์ €์ž‘๊ถŒ๋ฒ•์˜ “์‹ค์งˆ์  ์œ ์‚ฌ์„ฑ(Substantial Similarity)” ํ‰๊ฐ€๋ฅผ ํ†ต๊ณผํ•˜์ง€ ๋ชปํ•ฉ๋‹ˆ๋‹ค. ์•Œ๊ณ ๋ฆฌ์ฆ˜ ๊ตฌ์กฐ์™€ ํ‘œํ˜„์ด ๋™์ผํ•œ ๊ฒฝ์šฐ, ํƒ€์ž…๋ช…ยท๋งคํฌ๋กœ ์น˜ํ™˜๋งŒ์œผ๋กœ๋Š” ๋…๋ฆฝ ์ €์ž‘๋ฌผ๋กœ ์ธ์ •๋ฐ›์„ ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค. ์‚ฌ๋‚ด ์ฝ”๋“œ๋ฒ ์ด์Šค์— ์™ธ๋ถ€ ์˜คํ”ˆ์†Œ์Šค๋ฅผ “๋‚ด์žฌํ™”"ํ•  ๋•Œ ์ด์™€ ๊ฐ™์€ ๋ฐฉ์‹์„ ์‚ฌ์šฉํ•˜๋Š” ๊ฒฝ์šฐ๊ฐ€ ์žˆ๋Š”๋ฐ, ์ด๋ฒˆ ์‚ฌ๋ก€๋Š” ๊ทธ ์œ„ํ—˜์„ฑ์„ ๋ช…ํ™•ํžˆ ๋ณด์—ฌ์ค๋‹ˆ๋‹ค.

3๊ฐ€์ง€ ์นจํ•ด ํ–‰์œ„ ์š”์•ฝ

flowchart TD
    A["FFmpeg libavcodec(LGPL 2.1)"] -->|"1. ๋ณต์‚ฌ(Copy-paste)"| B["Rockchip MPP ๋‚ด๋ถ€ ํŒŒ์ผ"]
    B -->|"2. ํ—ค๋” ๊ต์ฒด"| C["์ €์ž‘๊ถŒ ๊ณ ์ง€ ์‚ญ์ œโ†’ Rockchip ๋ช…์˜๋กœ ๋ณ€๊ฒฝ"]
    B -->|"3. ์žฌ๋ผ์ด์„ ์‹ฑ"| D["LGPL 2.1 ์ œ๊ฑฐโ†’ Apache-2.0 ์ ์šฉ"]
    C --> E["GitHub์— ๊ณต๊ฐœ ๋ฐฐํฌ"]
    D --> E
    style A fill:#ccffcc,stroke:#333
    style E fill:#ffcccc,stroke:#333
์นจํ•ด ํ–‰์œ„์œ„๋ฐ˜ ์กฐํ•ญ
์ €์ž‘๊ถŒ ๊ณ ์ง€ ์‚ญ์ œLGPL 4์กฐ โ€” ์ €์ž‘๊ถŒ ๊ณ ์ง€ ์œ ์ง€ ์˜๋ฌด
์ €์ž‘์ž ํ—ˆ์œ„ ํ‘œ๊ธฐ์ €์ž‘๊ถŒ๋ฒ•์ƒ ์„ฑ๋ช…ํ‘œ์‹œ๊ถŒ(์ €์ž‘์ธ๊ฒฉ๊ถŒ) ์นจํ•ด
LGPL โ†’ Apache-2.0 ์žฌ๋ผ์ด์„ ์‹ฑLGPL 2์กฐ โ€” ๋™์ผ ๋ผ์ด์„ ์Šค ๋ฐฐํฌ ์˜๋ฌด
์ˆ˜์ • ์‚ฌ์‹ค ๋ฏธ๊ณ ์ง€LGPL 2์กฐ โ€” ์ˆ˜์ • ์—ฌ๋ถ€ ๋ช…์‹œ ์˜๋ฌด

3. ์™œ ‘๋ผ์ด์„ ์Šค ์„ธํƒ’์ด ์œ„ํ—˜ํ•œ๊ฐ€?

๋งŽ์€ ๊ธฐ์—… ๋‹ด๋‹น์ž๋“ค์ด “Apache 2.0์œผ๋กœ ๊ณต๊ฐœ๋œ ์ฝ”๋“œ๋Š” ์•ˆ์ „ํ•˜๋‹ค"๊ณ  ์ƒ๊ฐํ•˜๊ธฐ ์‰ฝ์Šต๋‹ˆ๋‹ค.
ํ•˜์ง€๋งŒ ์ด๋ฒˆ ์‚ฌ๋ก€๋Š” ์ €์ž‘๊ถŒ ์ถœ์ฒ˜๊ฐ€ ๋ถˆํˆฌ๋ช…ํ•œ Apache 2.0 ์ฝ”๋“œ๊ฐ€ ์˜คํžˆ๋ ค ํฐ ๋ฒ•์  ๋ฆฌ์Šคํฌ๊ฐ€ ๋  ์ˆ˜ ์žˆ์Œ์„ ๋ณด์—ฌ์ค๋‹ˆ๋‹ค.

Rockchip์˜ ์ž˜๋ชป๋œ ์ ‘๊ทผ ๋ฐฉ์‹

flowchart TD
    UserApp[User Application] --> FFmpeg_Fork
    FFmpeg_Fork[Modified FFmpeg - Non-compliant] -- Static Link / Direct Copy --> Rockchip_MPP[Rockchip MPP Library]
    Rockchip_MPP --> Hardware[Rockchip VPU Hardware]
    
    subgraph "License Violation Area"
        FFmpeg_Fork
        Rockchip_MPP
    end

    style FFmpeg_Fork fill:#ffcccc,stroke:#333,stroke-width:2px
    style Rockchip_MPP fill:#ffcccc,stroke:#333,stroke-width:2px
  • LGPL ์ฝ”๋“œ๋ฅผ ๊ฐ€์ ธ์™€ ์ˆ˜์ •ํ•œ ๊ฒฝ์šฐ, ํ•ด๋‹น ํŒŒ์ƒ ์ €์ž‘๋ฌผ์€ LGPL(๋˜๋Š” ์–‘๋ฆฝ ๊ฐ€๋Šฅํ•œ GPL)๋กœ ๋ฐฐํฌํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.
  • ์›์ €์ž‘์ž์˜ ์ €์ž‘๊ถŒ ๊ณ ์ง€์™€ ๋ผ์ด์„ ์Šค๋ฅผ ์‚ญ์ œํ•˜๊ฑฐ๋‚˜, ์ž์‹  ๋ช…์˜๋กœ ๋ฐ”๊พธ์–ด์„œ๋Š” ์•ˆ ๋ฉ๋‹ˆ๋‹ค.

์˜ฌ๋ฐ”๋ฅธ ์ ‘๊ทผ ๋ฐฉ์‹: V4L2 ํ‘œ์ค€ ์ค€์ˆ˜

๋ฆฌ๋ˆ…์Šค ์ปค๋„์€ ํ•˜๋“œ์›จ์–ด ๊ฐ€์†์„ ์œ„ํ•ด V4L2 (Video for Linux 2) ๋ผ๋Š” ํ‘œ์ค€ ์ธํ„ฐํŽ˜์ด์Šค๋ฅผ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค. ์ด์ƒ์ ์ธ ๊ตฌ์กฐ๋Š” FFmpeg๋Š” ์‚ฌ์šฉ์ž ๊ณต๊ฐ„์— ๊ทธ๋Œ€๋กœ ๋‘๊ณ , ํ•˜๋“œ์›จ์–ด ์˜์กด ์ฝ”๋“œ๋Š” ์ปค๋„ ๋“œ๋ผ์ด๋ฒ„(V4L2)๋กœ ๋ถ„๋ฆฌํ•˜๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค.

flowchart TD
    UserApp[User Application] --> Upstream_FFmpeg
    Upstream_FFmpeg[Upstream FFmpeg - LGPL] -- Standard IOCTL --> V4L2_API[Linux Kernel V4L2 API]
    V4L2_API --> Kernel_Driver[Rockchip Kernel Driver - GPL]
    Kernel_Driver --> Hardware[Rockchip VPU Hardware]

    subgraph "License Compliant Area"
        Upstream_FFmpeg
        Kernel_Driver
    end

    style Upstream_FFmpeg fill:#ccffcc,stroke:#333,stroke-width:2px
    style Kernel_Driver fill:#ccffcc,stroke:#333,stroke-width:2px
  • FFmpeg๋ฅผ ์ˆ˜์ • ์—†์ด ์‚ฌ์šฉํ•˜๊ณ , ํ•˜๋“œ์›จ์–ด ๊ฐ€์†์€ ์ปค๋„์˜ ํ‘œ์ค€ ์ธํ„ฐํŽ˜์ด์Šค(V4L2 M2M)๋ฅผ ํ†ตํ•ด ํ˜ธ์ถœํ•ฉ๋‹ˆ๋‹ค.
  • FFmpeg์™€ ์ปค๋„ ๋“œ๋ผ์ด๋ฒ„๊ฐ€ ๋ช…ํ™•ํ•œ User/Kernel ๊ฒฝ๊ณ„๋กœ ๋ถ„๋ฆฌ๋˜๋ฏ€๋กœ, FFmpeg ์ฝ”๋“œ ์ž์ฒด๋ฅผ ๋ฒค๋”๊ฐ€ ๋œฏ์–ด๊ณ ์ณ ๋ฐฐํฌํ•  ํ•„์š”๊ฐ€ ์‚ฌ๋ผ์ง‘๋‹ˆ๋‹ค.

ํ˜„์žฌ ์ปค๋ฎค๋‹ˆํ‹ฐ๋Š” Rockchip์˜ mpp ์‚ฌ์šฉ์ž ๊ณต๊ฐ„ ์Šคํƒ์„ ๊ฑท์–ด๋‚ด๊ณ , ๋ฉ”์ธ๋ผ์ธ ๋ฆฌ๋ˆ…์Šค ์ปค๋„์˜ V4L2 ๋“œ๋ผ์ด๋ฒ„ ๊ธฐ๋ฐ˜์œผ๋กœ ์ „ํ™˜ํ•˜๋ ค๋Š” ์›€์ง์ž„์„ ๋ณด์ด๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค. ๋‹น์žฅ Rockchip ํ•˜๋“œ์›จ์–ด๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ๊ฐœ๋ฐœ์ž๋ผ๋ฉด, ์˜ฌ๋ฐ”๋ฅธ ๋ผ์ด์„ ์Šค๋กœ ๋ฐฐํฌ๋˜๋Š” nyanmisaka/ffmpeg-rockchip ํฌํฌ๋ฅผ ๋Œ€์•ˆ์œผ๋กœ ๊ณ ๋ คํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

4. ๊ณผ๊ฑฐ ์‚ฌ๋ก€์™€์˜ ๋น„๊ต: Allwinner CedarX (2015)

์ด๋ฒˆ ์‚ฌ๊ฑด์€ 10๋…„ ์ „ Allwinner ์‚ฌํƒœ์™€๋„ ๋งค์šฐ ์œ ์‚ฌํ•ฉ๋‹ˆ๋‹ค. ์—ญ์‚ฌ์ ์œผ๋กœ ์—ฌ๋Ÿฌ ์ž„๋ฒ ๋””๋“œ ์นฉ ๋ฒค๋”๋“ค์ด ๋ฉ€ํ‹ฐ๋ฏธ๋””์–ด ์ฝ”๋ฑ ๋ผ์ด์„ ์Šค ๋ฌธ์ œ์—์„œ ๋ฐ˜๋ณตํ•ด์„œ ๊ฐ™์€ ์‹ค์ˆ˜๋ฅผ ์ €์งˆ๋Ÿฌ ์™”์Šต๋‹ˆ๋‹ค.

๋น„๊ต ํ•ญ๋ชฉAllwinner (CedarX, 2015)Rockchip (MPP, 2025-2026)
๋ฌธ์ œ ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌCedarX (๋ฐ”์ด๋„ˆ๋ฆฌ ๋ธ”๋กญ ํ˜•ํƒœ)MPP (์†Œ์Šค์ฝ”๋“œ ๊ณต๊ฐœ ํ˜•ํƒœ)
์œ„๋ฐ˜ ๋‚ด์šฉ์ปค๋„ ํŠธ๋ฆฌ์— ๋ฐ”์ด๋„ˆ๋ฆฌ ๋ธ”๋กญ ํฌํ•จ์œผ๋กœ GPL ์œ„๋ฐ˜, ์‚ฌ์šฉ์ž ๊ณต๊ฐ„ CedarX ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ์— FFmpeg libavcodec ์ฝ”๋“œ๋ฅผ ๋ฌด๋‹จ ํฌํ•จํ•˜๊ณ  LGPL ์˜๋ฌด ๋ถˆ์ดํ–‰FFmpeg libavcodec ์ฝ”๋“œ๋ฅผ ์ง์ ‘ ๋ณต์‚ฌ, ์ €์ž‘๊ถŒ ๊ณ ์ง€ ์ œ๊ฑฐ, Rockchip ๋ช…์˜๋กœ ๋ณ€๊ฒฝ, LGPL ์ฝ”๋“œ๋ฅผ Apache-2.0์œผ๋กœ ์žฌ๋ผ์ด์„ ์‹ฑ
์ปค๋ฎค๋‹ˆํ‹ฐ ๋Œ€์‘๋ฆฌ๋ฒ„์Šค ์—”์ง€๋‹ˆ์–ด๋ง์„ ํ†ตํ•œ ์˜คํ”ˆ์†Œ์Šค ๋“œ๋ผ์ด๋ฒ„(Cedrus) ๊ฐœ๋ฐœ, GPL ์œ„๋ฐ˜ ๊ณต๊ฐœ ์ง€์ DMCA Takedown, ๋ฆฌํฌ์ง€ํ† ๋ฆฌ ๋น„ํ™œ์„ฑํ™”, V4L2 ๊ธฐ๋ฐ˜ ์˜คํ”ˆ ๋“œ๋ผ์ด๋ฒ„ ๊ฐœ๋ฐœ ๊ฐ€์†ํ™”
๊ตํ›ˆ๋ฐ”์ด๋„ˆ๋ฆฌ ๋ฐฐํฌ๋Š” GPLยทLGPL ์œ„๋ฐ˜์„ ๊ฐ์ถ”๊ธฐ ์‰ฝ์ง€๋งŒ, ๊ฒฐ๊ตญ ์ปค๋ฎค๋‹ˆํ‹ฐ์— ์˜ํ•ด ๋“œ๋Ÿฌ๋‚จ์†Œ์Šค ๊ณต๊ฐœ๋ผ๋„ ‘๋ผ์ด์„ ์Šค ์„ธํƒ’(์ถœ์ฒ˜ ์€ํ, ์žฌ๋ผ์ด์„ ์‹ฑ)์€ ๋ช…๋ฐฑํ•œ ์œ„๋ฐ˜์ด๋ฉฐ, ์˜คํžˆ๋ ค ์ฆ๊ฑฐ๊ฐ€ ๋‚จ๊ธฐ ๋•Œ๋ฌธ์— ๋” ๋น ๋ฅด๊ฒŒ ๋ฌธ์ œํ™”๋จ

Allwinner ์‚ฌ๋ก€์—์„œ๋„ CedarX ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ ๋‚ด๋ถ€์— FFmpeg libavcodec ์ฝ”๋“œ๊ฐ€ ์„ž์—ฌ ์žˆ๋Š” ๊ฒƒ์ด ํ™•์ธ๋˜์—ˆ๊ณ , LGPL ์˜๋ฌด์— ๋”ฐ๋ผ ์†Œ์Šค๋ฅผ ๊ณต๊ฐœํ•ด์•ผ ํ•œ๋‹ค๋Š” ์ง€์ ์ด ์žˆ์—ˆ์Šต๋‹ˆ๋‹ค. Rockchip MPP๋Š” “๋ฐ”์ด๋„ˆ๋ฆฌ ๋ธ”๋กญ"์ด ์•„๋‹Œ “๊ณต๊ฐœ ์†Œ์Šค” ํ˜•ํƒœ์˜€์ง€๋งŒ, ๊ณต๊ฐœ๋œ ์ฝ”๋“œ ์•ˆ์—์„œ ๊ทธ๋Œ€๋กœ ๋“œ๋Ÿฌ๋‚œ ์œ„๋ฐ˜์ด๋ผ๋Š” ์ ์—์„œ ์˜คํžˆ๋ ค ๋” ๋ช…ํ™•ํ•˜๊ฒŒ ๋ฌธ์ œ๊ฐ€ ๋˜์—ˆ์Šต๋‹ˆ๋‹ค.

์ง‘ํ–‰ ์‚ฌ๋ก€ ์„ ๋ก€: 2024๋…„ 2์›”, ํŒŒ๋ฆฌ ๋ฒ•์›์€ Orange์˜ GPL ์œ„๋ฐ˜์œผ๋กœ ์ธํ•ด Entr’ouvert์‚ฌ์— ์•ฝ 86๋งŒ ์œ ๋กœ(์•ฝ 10์–ต ์›)๋ฅผ ๋ฐฐ์ƒํ•˜๋ผ๊ณ  ํŒ๊ฒฐํ–ˆ์Šต๋‹ˆ๋‹ค. ์ด๋Š” GPL/LGPL ์œ„๋ฐ˜์ด ์‹ค์ œ ๋ฒ•์ ยท์žฌ์ •์  ๊ฒฐ๊ณผ๋กœ ์ด์–ด์ง„๋‹ค๋Š” ๊ฒƒ์„ ๋ณด์—ฌ์ฃผ๋Š” ์ค‘์š”ํ•œ ์„ ๋ก€์ž…๋‹ˆ๋‹ค.

5. ๊ธฐ์—…์„ ์œ„ํ•œ Action Item

์—ฌ๋Ÿฌ๋ถ„์ด ์‚ฌ์šฉํ•˜๋Š” SoC ๋ฒค๋”์˜ SDK๋‚˜ BSP๊ฐ€ ์ด์™€ ๊ฐ™์€ ๋ฌธ์ œ๋ฅผ ์•ˆ๊ณ  ์žˆ์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
๋‹ค์Œ ์„ธ ๊ฐ€์ง€ ํ•ญ๋ชฉ์„ ๋ฐ˜๋“œ์‹œ ์ ๊ฒ€ํ•˜์‹ญ์‹œ์˜ค.

1) ๊ณต๊ธ‰๋ง(Supply Chain) ๋ผ์ด์„ ์Šค ๊ฐ์‚ฌ

  • ๋ฒค๋”๊ฐ€ ์ œ๊ณตํ•œ “์˜คํ”ˆ์†Œ์Šค” ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ(ํŠนํžˆ ๋ฉ€ํ‹ฐ๋ฏธ๋””์–ด, ๊ทธ๋ž˜ํ”ฝ, AI ๊ฐ€์† ๊ด€๋ จ)๊ฐ€ ์‹ค์ œ ์›์ €์ž‘์ž์˜ ๋ผ์ด์„ ์Šค๋ฅผ ๊ทธ๋Œ€๋กœ ์œ ์ง€ํ•˜๊ณ  ์žˆ๋Š”์ง€ ํ™•์ธํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.
  • ๋ฒค๋”๊ฐ€ Apache 2.0์ด๋‚˜ MIT ๋“ฑ “์•ˆ์ „ํ•ด ๋ณด์ด๋Š”” ๋ผ์ด์„ ์Šค๋ฅผ ์ฃผ์žฅํ•˜๋”๋ผ๋„, ๋‚ด๋ถ€ ์ฝ”๋“œ๊ฐ€ FFmpeg์ด๋‚˜ ๋‹ค๋ฅธ GPL/LGPL ํ”„๋กœ์ ํŠธ์—์„œ ๋ณต์‚ฌ๋œ ๊ฒƒ์ด๋ผ๋ฉด, ์ œํ’ˆ ์ „์ฒด๊ฐ€ ๋ฒ•์  ์œ„ํ—˜์— ๋…ธ์ถœ๋ฉ๋‹ˆ๋‹ค.
  • Black Duck, FOSSID ๋“ฑ์˜ ์†Œ์Šค ์ฝ”๋“œ ๋ถ„์„ ๋„๊ตฌ๋กœ ๋ฒค๋” ์ œ๊ณต ์ฝ”๋“œ๋ฅผ ์Šค์บ”ํ•˜๋ฉด, ๋‚ด๋ถ€์— ๋‚จ์•„ ์žˆ๋Š” ์›๋ณธ ๋ผ์ด์„ ์Šค ๊ณ ์ง€๋‚˜ ์ €์ž‘๊ถŒ ํ‘œ์‹œ๋ฅผ ์ฐพ์•„๋‚ผ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

2) ‘Upstream First’ ์ •์ฑ… ํ™•์ธ

  • ๋ฒค๋”๊ฐ€ ์ œ๊ณตํ•˜๋Š” ๋“œ๋ผ์ด๋ฒ„๊ฐ€ ๋ฆฌ๋ˆ…์Šค ๋ฉ”์ธ๋ผ์ธ ์ปค๋„(Upstream)์— ๋ณ‘ํ•ฉ๋˜์–ด ์žˆ๋Š”์ง€ ํ™•์ธํ•˜์‹ญ์‹œ์˜ค.
  • ๋ฉ”์ธ๋ผ์ธ์— ๋ณ‘ํ•ฉ๋œ ์ฝ”๋“œ๋Š” ์ „ ์„ธ๊ณ„ ๊ฐœ๋ฐœ์ž๋“ค์— ์˜ํ•ด ์ฝ”๋“œ ๋ฆฌ๋ทฐ์™€ ๋ผ์ด์„ ์Šค ๊ฒ€ํ† ๋ฅผ ๊ฑฐ์นœ ๊ฒƒ์ด๋ฏ€๋กœ, ๋ฒค๋”๊ฐ€ ์ž์ฒด์ ์œผ๋กœ ์šด์˜ํ•˜๋Š” GitHub ๋ฆฌํฌ์ง€ํ† ๋ฆฌ๋ณด๋‹ค ์ƒ๋Œ€์ ์œผ๋กœ ์‹ ๋ขฐ๋„๊ฐ€ ๋†’์Šต๋‹ˆ๋‹ค.

3) ๋‚ด๋ถ€ ๊ฐœ๋ฐœํŒ€ ๊ฐ€์ด๋“œ: “๋ณต์‚ฌ ๋ถ™์—ฌ๋„ฃ๊ธฐ” ๊ธˆ์ง€

  • ์‚ฌ๋‚ด ๊ฐœ๋ฐœ์ž๊ฐ€ ์™ธ๋ถ€ ์˜คํ”ˆ์†Œ์Šค ์ฝ”๋“œ๋ฅผ ๊ฐ€์ ธ์˜ฌ ๋•Œ, ํŒŒ์ผ ์ƒ๋‹จ์˜ ์ €์ž‘๊ถŒ ํ—ค๋”๋ฅผ ์‚ญ์ œํ•˜๊ฑฐ๋‚˜ ํšŒ์‚ฌ ๋ช…์˜๋กœ ๋ฐ”๊ฟ”์„œ ์ปค๋ฐ‹ํ•˜๋Š” ํ–‰์œ„๋Š” ์ ˆ๋Œ€ ํ—ˆ์šฉํ•ด์„œ๋Š” ์•ˆ ๋ฉ๋‹ˆ๋‹ค. ์ด๋Š” ๊ณ ์˜์ ์ธ ์ €์ž‘๊ถŒ ์นจํ•ด๋กœ ๊ฐ„์ฃผ๋  ์ˆ˜ ์žˆ์œผ๋ฉฐ, ์ดํ›„ ๋ถ„์Ÿ์—์„œ ์น˜๋ช…์ ์ธ ์ฆ๊ฑฐ๊ฐ€ ๋ฉ๋‹ˆ๋‹ค.
  • ์ฝ”๋“œ ํ†ตํ•ฉ์ด ํ•„์š”ํ•œ ๊ฒฝ์šฐ, ๊ฐ€๋Šฅํ•œ ํ•œ ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ ๋งํฌ ๋ฐฉ์‹์œผ๋กœ ์‚ฌ์šฉํ•˜๊ณ , ์›์ €์ž‘์ž์˜ ๋ผ์ด์„ ์Šค์™€ ์ €์ž‘๊ถŒ ํ‘œ์‹œ๋Š” ๋ฐ˜๋“œ์‹œ ์œ ์ง€ํ•˜๋Š” ๊ฒƒ์„ ํ‘œ์ค€์œผ๋กœ ์‚ผ์œผ์‹ญ์‹œ์˜ค.

์š”์•ฝ

Rockchip ์‚ฌ๋ก€๋Š” “์†Œ์Šค ์ฝ”๋“œ๋ฅผ ๊ณต๊ฐœํ•˜๋Š” ๊ฒƒ"๊ณผ “์˜คํ”ˆ์†Œ์Šค ๋ผ์ด์„ ์Šค๋ฅผ ์ค€์ˆ˜ํ•˜๋Š” ๊ฒƒ"์ด ์ „ํ˜€ ๋‹ค๋ฅธ ๋ฌธ์ œ์ž„์„ ๋ช…ํ™•ํžˆ ๋ณด์—ฌ์ค๋‹ˆ๋‹ค. LGPL ์ฝ”๋“œ๋Š” ์ €์ž‘๊ถŒ์ž ๋™์˜ ์—†์ด Apache 2.0 ๋“ฑ ๋‹ค๋ฅธ ๋ผ์ด์„ ์Šค๋กœ ์žฌ๋ผ์ด์„ ์‹ฑํ•  ์ˆ˜ ์—†์œผ๋ฉฐ, ์ €์ž‘๊ถŒ ๊ณ ์ง€ ์‚ญ์ œ์™€ ์ €์ž‘์ž ์œ„์กฐ๋Š” ๊ทธ ์ž์ฒด๋กœ ์‹ฌ๊ฐํ•œ ์นจํ•ด ํ–‰์œ„์ž…๋‹ˆ๋‹ค.

SoC ๋ฒค๋”๊ฐ€ ์ œ๊ณตํ•˜๋Š” ์†Œํ”„ํŠธ์›จ์–ด๋ฅผ ๊ทธ๋Œ€๋กœ ์‹ ๋ขฐํ•˜๊ธฐ๋ณด๋‹ค๋Š”, Black Duck, FOSSID ๋“ฑ์˜ ์†Œ์Šค ์ฝ”๋“œ ๋ถ„์„ ๋„๊ตฌ๋ฅผ ํ™œ์šฉํ•ด ๋ฒค๋” ์ œ๊ณต ์ฝ”๋“œ ์•ˆ์— ์–ด๋–ค ๋ผ์ด์„ ์Šค์™€ ์ €์ž‘๊ถŒ ๊ณ ์ง€๊ฐ€ ํฌํ•จ๋˜์–ด ์žˆ๋Š”์ง€๋ฅผ ์ฃผ๊ธฐ์ ์œผ๋กœ ์Šค์บ”ํ•˜๊ณ , ๊ฒฐ๊ณผ๋ฅผ ๋ฐ”ํƒ•์œผ๋กœ ๋ฒค๋”์™€ ์ฑ…์ž„ ๋ฒ”์œ„๋ฅผ ๋ช…ํ™•ํžˆ ํ•˜๋Š” ํ”„๋กœ์„ธ์Šค๋ฅผ ๊ตฌ์ถ•ํ•˜๋Š” ๊ฒƒ์ด ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค.

์ฐธ๊ณ  ์ž๋ฃŒ