Kilde › Guides › CRA › Open source under the CRA: where the c…
Current to 26 August 2026 · updates land in the changelog.
The CRA drew the open-source boundary at commerce, not at licence text. Free and open-source software supplied outside a commercial activity is out of scope; supply it in the course of a commercial activity and the CRA applies like any product. The licence being OSI-approved settles nothing — the monetisation pattern does.
Between hobbyist and vendor sits the open-source software steward (Article 3(14)): foundations and entities that support the development of qualifying open-source products intended for commercial activities — think foundation-hosted infrastructure projects. Stewards get a light-touch regime rather than full manufacturer duties, and the regulation's sharpest kindness: exemption from administrative fines (Article 64(10)(b)). The structure is deliberate — the EU wanted the maintainer ecosystem inside the security conversation without pricing it out of existence.
The patterns that pull FOSS into scope are the familiar ones: selling support or dual licences around the code, shipping it inside a paid product, offering it as the paid tier of an open-core model. The pattern that doesn't: accepting donations for a project you maintain in the open. In between, the analysis deserves a written position — and manufacturers consuming open source carry their own duty either way: component due diligence and reporting vulnerabilities upstream (Article 13(5)–(6)), with the SBOM as the instrument.
The open-source carve-out is becoming EU boilerplate: the new Product Liability Directive — which from 9 December 2026 treats software expressly as a product — carves out free and open-source software supplied outside a commercial activity in the same breath (verified verbatim at EUR-Lex; tracked on our deadline radar). For anyone building on or shipping open source, the two regimes now ask the same first question: is the supply commercial?
The CRA Reporting-Ready Pack: the staged 24h / 72h / final-report runbook and templates, vulnerability-vs-incident triage worksheet, CSIRT-routing and main-establishment worksheet, platform registration runbook, CVD policy and evidence log — built from the regulation and the ENISA platform guides, with pinpoint citations.
Get the pack — US$390 Free 4-page sample (PDF)Instant download · 14-day unconditional refund · single-organisation licence · full product page
General information only — not legal advice, and never a conformity assessment. Whether a specific product falls in a listed category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392, and reporting-platform mechanics are ENISA-published material marked subject to change. Sources are Regulation (EU) 2024/2847 (CELEX 32024R2847; Annex III/IV item texts read verbatim from EUR-Lex) and our audited kit research. © 2026 Kilde.
Built by Kilde's founder, a practising attorney admitted to a US state bar (not an EU or Hong Kong admission). About · Verification log · Refunds · Terms · Privacy · esau@trykilde.com