CRA: mandatory reporting of actively exploited vulnerabilities and severe incidents to ENISA/CSIRT
Any manufacturer that sells software or connected hardware in the EU, including small software vendors and open-source projects run commercially. Non-commercial open source is largely exempt.