Doesn't really do anything to ensure the end-user truly has ownership over the device and the ability to control what software runs on it. 10 years of security updates is nice (assuming the company making the device doesn't go out of business in that time) but doesn't stop those devices becoming vulnerable after that (and a truly useful device will likely have more than 10 years of useful life). I don't know the specifics of the CRA, but most proposed regulatory solutions I've seen intentionally take control away from the end-user.