Whenproof

Guides · EU Cyber Resilience Act

Open-source stewards vs manufacturers under the CRA

Publishing code is not placing a product on the market. Selling a product built on it is. Where the CRA draws the lines for open source.

Checked against the sources below on . Not legal advice.

In short: If you market a product under your own name in the course of a commercial activity, you are a manufacturer, even if the code is open source. A foundation or other legal person that sustainably supports open-source software intended for commercial use may be an open-source software steward, with a much lighter regime. Open source developed and shared without monetisation is generally outside the CRA.

Manufacturer: the main role

A manufacturer is “a natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under its name or trademark, whether for payment, monetisation or free of charge” (Article 3(13)).

What matters is making the product available on the market, which means supplying it “in the course of a commercial activity, whether in return for payment or free of charge” (Article 3(22)). A company that sells software built on open-source components is a manufacturer of that software, whatever the licence of its code.

Open source outside the CRA

The recitals explain the intent. Only free and open-source software made available on the market, “and therefore supplied for distribution or use in the course of a commercial activity”, is in scope, and open source that is not monetised by its manufacturer should not be considered a commercial activity (recital 18). Simply providing software on open repositories or package managers is not making it available on the market (recital 20).

Where exactly the commercial line falls in edge cases (donations, paid support, a company that also maintains the project) is the subject of the Commission's guidance C(2026) 5252, which works through examples. Read it before deciding.

Open-source software steward: the light-touch role

The CRA adds a third role for organisations that look after open source without selling it:

“a legal person, other than a manufacturer, that has the purpose or objective of systematically providing support on a sustained basis for the development of specific products with digital elements, qualifying as free and open-source software and intended for commercial activities, and that ensures the viability of those products”

Article 3(14)

Think foundations and similar bodies. An individual maintainer is not a steward: it has to be a legal person. Stewards must (Article 24):

  • put in place and document “in a verifiable manner” a cybersecurity policy that fosters secure development and effective vulnerability handling by the project's developers;
  • cooperate with market surveillance authorities on request;
  • report actively exploited vulnerabilities under Article 14(1) “to the extent that they are involved in the development of the products”, and severe incidents (and inform users) only where the incident affects the network and information systems they provide for development (Article 24(3)).

According to the Commission and ENISA, stewards' reporting obligations apply from 11 December 2027, not September 2026. And the regulation's administrative fines do not apply to any infringement by an open-source software steward (Article 64(10)(b)).

If you are a manufacturer using open source

  • Due diligence. You must exercise due diligence when integrating third-party components “so that those components do not compromise the cybersecurity of the product”, including open source that was never made available on the market (Article 13(5)).
  • Report upstream. If you find a vulnerability in a component, including open source, you report it to whoever manufactures or maintains the component (Article 13(6)).
  • Your reporting still applies. An actively exploited vulnerability in an open-source dependency of your product can be an actively exploited vulnerability in your product. See what “actively exploited” means.

Sources

  1. Regulation (EU) 2024/2847 (Cyber Resilience Act), OJ L, 20 November 2024EUR-Lex
  2. Cyber Resilience Act: reporting obligationsEuropean Commission, updated 11 September 2026
  3. Single Reporting Platform: frequently asked questionsENISA, updated 3 October 2026
  4. Commission publishes new guidance to support timely Cyber Resilience Act implementation, C(2026) 5252European Commission, 27 July 2026

This guide explains the regulation in plain English for small software makers. It is not legal advice; check your own situation with counsel. Whenproof is a tool, not a law firm, and does not make a product compliant.