OSS Guide

CRA for Open Source Stewards

What foundations and maintainers need to know about the Cyber Resilience Act

Are you an Open Source Steward?

The CRA creates a special category for organizations that support open source projects. If you're a foundation, consortium, or organization that helps maintain open source software — this applies to you.

Examples: Linux Foundation, Apache Software Foundation, Eclipse Foundation, CNCF

What is an Open Source Software Steward?

In Simple Terms:

An organization (not an individual) that helps maintain and support open source projects that businesses use commercially.

Key Points:

  • Must be a legal entity (not individual contributors)
  • Provides sustained support for open source development
  • Projects must be intended for commercial use
  • Ensures long-term viability of projects

Does CRA Apply to Your Open Source Work?

Quick Decision Flow

Is the software used commercially?
YES → CRA may apply NO → Generally exempt
Is the software monetized by the developer?
YES → Developer is a Manufacturer NO → Continue to next question
Is there a legal entity providing sustained support?
YES → Entity may be an OSS Steward NO → Generally exempt

Who is NOT covered:

  • Individual open source contributors
  • Volunteer maintainers with no commercial activity
  • Educational or research projects
  • Internal-use only development

OSS Steward Obligations

What you MUST do under the CRA

Article 24.1 Easy

Establish Cybersecurity Policy

Create a security.md file and vulnerability handling process

View Details

Document and make available a cybersecurity policy to facilitate secure development

Actions:
  • Create SECURITY.md in project repositories
  • Define vulnerability disclosure process
  • Document secure development practices

⏰ Deadline: By Dec 11, 2027

Articles 14, 15 Medium

Report Vulnerabilities

Report actively exploited vulnerabilities to ENISA and national CSIRTs

View Details

Notify authorities of actively exploited vulnerabilities through the EU Single Reporting Platform

⏱️ Timeline:
  • 24 hours - Initial notification
  • 72 hours - Detailed information
  • 14 days - Corrective measures
Actions:
  • Prepare EU Login and reporting roles; register with the SRP when a report is needed
  • Set up monitoring for exploit reports
  • Create internal escalation procedures

⏰ Deadline: By Sept 11, 2026

Article 24.2 Easy

Cooperate with Authorities

Work with Market Surveillance Authorities when asked

View Details

Cooperate with market surveillance authorities and provide documentation upon request

Actions:
  • Designate a contact person for authority requests
  • Maintain compliance documentation
  • Respond to requests within reasonable timeframes

⏰ Deadline: Ongoing

Best practice (not a specific CRA obligation) Medium

Due Diligence Process

Take reasonable care about security of supported projects

View Details

Recommended practice, not a distinct legal duty under Article 24 (which has only 3 paragraphs: cybersecurity policy, cooperation with authorities, and limited Article 14 reporting) — exercising general due diligence on supported projects still supports the cybersecurity-policy obligation above

Actions:
  • Regular security audits of key projects
  • Track dependencies and known vulnerabilities
  • Support security improvements in projects

⏰ Deadline: Ongoing

What Stewards Don't Have to Do

Unlike manufacturers, OSS Stewards have lighter obligations

CE Marking

Stewards cannot and do not need to apply CE marking to projects

Full Annex I Compliance

Stewards don't need to ensure products meet all security requirements

Conformity Assessment

No third-party audits required for stewards

Product Liability

Stewards are not liable for products like manufacturers are

Steward vs Manufacturer: Liability Shield

Article 24 gives stewards lighter obligations than manufacturers. This comparison clarifies what is and is not required.

Steward: What you still must do

  • Maintain a documented cybersecurity policy for stewardship activities.
  • Run a coordinated vulnerability disclosure intake and triage process.
  • Cooperate with market surveillance authorities and ENISA where required.
  • Report severe incidents affecting steward-operated development infrastructure.

Steward: What you do not need to do

  • No CE marking for open-source components you steward.
  • No Annex VII technical documentation package as a manufacturer.
  • No conformity assessment module execution (A, B+C, H) as product manufacturer.
  • No manufacturer Declaration of Conformity obligations for third-party products.

Manufacturer obligations (for contrast)

  • Meet all Annex I essential cybersecurity requirements.
  • Complete applicable conformity assessment pathway.
  • Issue Declaration of Conformity and affix CE marking.
  • Maintain post-market vulnerability handling and mandatory reporting obligations.

Liability shield conditions

The lighter-touch regime is tied to your steward role. If you commercially place products with digital elements on the EU market, manufacturer obligations apply for those products.

Top 10 Actions for Stewards

Based on Linux Foundation guidance

1

Confirm Legal Entity

Ensure your foundation's legal entity status is clearly documented on website

2

Identify Projects

List which projects under your stewardship are intended for commercial use

3

Establish Security Policy

Create or update SECURITY.md with vulnerability handling process

4

Set Up Exploit Detection

Monitor for reports of actively exploited vulnerabilities in your projects

5

Prepare SRP Access

Set up EU Login and reporting roles; ENISA advises registering when a specific notification is needed

6

Leverage Security Tools

Use foundation security tools (OpenSSF Scorecard, Dependabot, etc.)

7

Enable SBOM Generation

Offer SBOM generation capabilities to downstream users

8

Perform Component Diligence

Document due diligence on major dependencies

9

Support Critical Upstreams

Help secure critical upstream dependencies your projects rely on

10

Stay Informed

Follow CRA implementation updates and guidance

Penalties for Stewards

Good news: OSS Stewards face no administrative fines under the CRA

  • • Article 64(10)(b) exempts OSS stewards from administrative fines for any infringement of the Regulation — with no exception
  • • Focus is on cooperation and correction, not punishment
  • • Market surveillance authorities can still require corrective action

Reference: Article 64(10)(b); Recital 120

Frequently Asked Questions

I'm a solo maintainer. Does CRA apply to me?

Probably not. CRA targets commercial activities and legal entities, not individual volunteer contributors.

Our foundation hosts many projects. Are all of them covered?

Only projects intended for commercial activities and where the foundation provides sustained support for viability.

What counts as 'commercial activity'?

Charging for the software, providing paid support, monetizing through services, or integration into commercial products by downstream users.

Can we still use 'as-is' disclaimers?

Yes, but for projects under stewardship, you still have the lighter obligations even with disclaimers.

Resources

Ready to Start Your Compliance Journey?

Use our free assessment tool to understand your CRA obligations.