Kilde › Guides › CRA › Open source under the CRA: where the c…

Open source under the CRA: where the commercial line runs, and what stewards get

Current to 26 August 2026 · updates land in the changelog.

The CRA drew the open-source boundary at commerce, not at licence text. Free and open-source software supplied outside a commercial activity is out of scope; supply it in the course of a commercial activity and the CRA applies like any product. The licence being OSI-approved settles nothing — the monetisation pattern does.

The middle category: the steward

Between hobbyist and vendor sits the open-source software steward (Article 3(14)): foundations and entities that support the development of qualifying open-source products intended for commercial activities — think foundation-hosted infrastructure projects. Stewards get a light-touch regime rather than full manufacturer duties, and the regulation's sharpest kindness: exemption from administrative fines (Article 64(10)(b)). The structure is deliberate — the EU wanted the maintainer ecosystem inside the security conversation without pricing it out of existence.

Where commercial actually starts

The patterns that pull FOSS into scope are the familiar ones: selling support or dual licences around the code, shipping it inside a paid product, offering it as the paid tier of an open-core model. The pattern that doesn't: accepting donations for a project you maintain in the open. In between, the analysis deserves a written position — and manufacturers consuming open source carry their own duty either way: component due diligence and reporting vulnerabilities upstream (Article 13(5)–(6)), with the SBOM as the instrument.

The same logic is spreading

The open-source carve-out is becoming EU boilerplate: the new Product Liability Directive — which from 9 December 2026 treats software expressly as a product — carves out free and open-source software supplied outside a commercial activity in the same breath (verified verbatim at EUR-Lex; tracked on our deadline radar). For anyone building on or shipping open source, the two regimes now ask the same first question: is the supply commercial?

Related guides

Quick answers

Is open-source software covered by the CRA?
Supplied outside a commercial activity, no. Supplied commercially — support contracts, paid products, open-core — yes, like any product with digital elements.
What is an open-source software steward under the CRA?
An entity (Article 3(14)) supporting qualifying open-source development intended for commercial use — subject to a light-touch regime and exempt from administrative fines under Article 64(10)(b).
Do manufacturers using open-source components have CRA duties toward them?
Yes — component due diligence, and reporting vulnerabilities found in a component to its maintainer (Article 13(5)–(6)), with the SBOM as the working instrument.
Be reporting-ready before 11 September 2026.

The CRA Reporting-Ready Pack: the staged 24h / 72h / final-report runbook and templates, vulnerability-vs-incident triage worksheet, CSIRT-routing and main-establishment worksheet, platform registration runbook, CVD policy and evidence log — built from the regulation and the ENISA platform guides, with pinpoint citations.

Get the pack — US$390 Free 4-page sample (PDF)

Instant download · 14-day unconditional refund · single-organisation licence · full product page

General information only — not legal advice, and never a conformity assessment. Whether a specific product falls in a listed category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392, and reporting-platform mechanics are ENISA-published material marked subject to change. Sources are Regulation (EU) 2024/2847 (CELEX 32024R2847; Annex III/IV item texts read verbatim from EUR-Lex) and our audited kit research. © 2026 Kilde.

Built by Kilde's founder, a practising attorney admitted to a US state bar (not an EU or Hong Kong admission). About · Verification log · Refunds · Terms · Privacy · esau@trykilde.com