Open source software and the CRA

The Cyber Resilience Act, Regulation (EU) 2024/2847, treats non-commercial open source software differently from commercial supply. It introduces the concept of an open source software steward, and a steward cannot be fined for any CRA infringement. That does not mean open source is untouched: manufacturers who build open source components into products they place on the market remain responsible for those products.

The open source software steward

The CRA recognises that much open source is developed outside a conventional commercial relationship, and it creates a distinct role, the open source software steward, to reflect that. The strongest signal of this lighter treatment is in the penalties: an open source software steward cannot be fined for any CRA infringement.

Under CRA Article 3(14), an open-source software steward is a legal person other than a manufacturer that systematically provides sustained support for specified free/open-source products intended for commercial use and ensures their viability; Article 24 gives stewards a tailored duty to maintain a verifiable cybersecurity and vulnerability-handling policy, cooperate with authorities and make specified reports where applicable.

Manufacturers still own their products

The steward carve-out does not flow through to a commercial manufacturer. If you place a product on the market and it incorporates open source components, you are responsible for that product under the CRA. That means the open source you ship is part of your product, and:

In short, using open source does not transfer your manufacturer obligations to anyone else.

Where the line falls

The practical question is which side of the commercial line an activity sits on. Non-commercial development, and stewardship of a project, attract the lighter treatment, including the steward fine carve-out. Non-monetised free and open-source software supplied by its manufacturer is generally not a commercial activity, and development funding, contributions or regular releases do not by themselves make it commercial. Placing a product on the market in the course of a commercial activity attracts the full manufacturer obligations, regardless of how much open source that product contains.

How CRANIS2 helps

CRANIS2 keeps the open source in your products visible and accountable: it builds and maintains the SBOM of your top-level dependencies, tracks vulnerabilities in those components against the products that ship them, and holds the evidence your manufacturer obligations require. Create an account to bring your open source components into one accountable record.

Frequently asked questions

Can an open source project maintainer be fined under the CRA?

An open source software steward cannot be fined for any CRA infringement. The steward concept is the CRA's mechanism for treating non-commercial open source stewardship differently from commercial supply.

If I use open source in my product, who is responsible?

You are, as the manufacturer placing the product on the market. The open source components form part of your product, so your SBOM, vulnerability handling and support-period duties cover them.

Does open source have to be in my SBOM?

Yes. Annex I Part II requires you to identify and document components, including an SBOM in a commonly used machine-readable format covering at least the top-level dependencies, and that includes the open source components in your product.


Related guides: Does the CRA apply to my product? and CRA compliance checklist for manufacturers.