Lately I've been digging into what the EU Cyber Resilience Act means for one-person software vendors, and building tools for it: cra-scan (open source, SBOM + exploited-vuln checks for SwiftPM/CocoaPods) and pinwatch.dev.
Happy to talk CRA, Swift tooling or EU research projects