From what I gather, the cyber resilience act applies to all products placed on the EU market, regardless of whether the manufacturer is based inside or outside of the EU. So European hardware vendors will be competing on the same terms as American and Chinese ones when it comes to the CRA.
A significant percentage of HN readership are those working in US Adtech, who's very salaries are dependent on abusing peoples privacy. Hardly surprising a hefty part of the HN demographic slants towards opposing privacy laws (for software and hardware).