CRA for Open Source Stewards
What foundations and maintainers need to know about the Cyber Resilience Act
Are you an Open Source Steward?
The CRA creates a special category for organizations that support open source projects. If you're a foundation, consortium, or organization that helps maintain open source software — this applies to you.
Examples: Linux Foundation, Apache Software Foundation, Eclipse Foundation, CNCF
What is an Open Source Software Steward?
In Simple Terms:
An organization (not an individual) that helps maintain and support open source projects that businesses use commercially.
Key Points:
- Must be a legal entity (not individual contributors)
- Provides sustained support for open source development
- Projects must be intended for commercial use
- Ensures long-term viability of projects
View Legal Definition (Article 3(14))
"'open-source software steward' means a legal person, other than a manufacturer, that has the purpose or objective of systematically providing support on a sustained basis for the development of specific products with digital elements qualifying as free and open-source software that are intended for commercial activities, and that ensures the viability of those products"
Does CRA Apply to Your Open Source Work?
Quick Decision Flow
Who is NOT covered:
- Individual open source contributors
- Volunteer maintainers with no commercial activity
- Educational or research projects
- Internal-use only development
OSS Steward Obligations
What you MUST do under the CRA
Establish Cybersecurity Policy
Create a security.md file and vulnerability handling process
View Details
Document and make available a cybersecurity policy to facilitate secure development
- Create SECURITY.md in project repositories
- Define vulnerability disclosure process
- Document secure development practices
⏰ Deadline: By Dec 11, 2027
Report Vulnerabilities
Report actively exploited vulnerabilities to ENISA and national CSIRTs
View Details
Notify authorities of actively exploited vulnerabilities through the EU Single Reporting Platform
- 24 hours - Initial notification
- 72 hours - Detailed information
- 14 days - Corrective measures
- Prepare EU Login and reporting roles; register with the SRP when a report is needed
- Set up monitoring for exploit reports
- Create internal escalation procedures
⏰ Deadline: By Sept 11, 2026
Cooperate with Authorities
Work with Market Surveillance Authorities when asked
View Details
Cooperate with market surveillance authorities and provide documentation upon request
- Designate a contact person for authority requests
- Maintain compliance documentation
- Respond to requests within reasonable timeframes
⏰ Deadline: Ongoing
Due Diligence Process
Take reasonable care about security of supported projects
View Details
Recommended practice, not a distinct legal duty under Article 24 (which has only 3 paragraphs: cybersecurity policy, cooperation with authorities, and limited Article 14 reporting) — exercising general due diligence on supported projects still supports the cybersecurity-policy obligation above
- Regular security audits of key projects
- Track dependencies and known vulnerabilities
- Support security improvements in projects
⏰ Deadline: Ongoing
What Stewards Don't Have to Do
Unlike manufacturers, OSS Stewards have lighter obligations
CE Marking
Stewards cannot and do not need to apply CE marking to projects
Full Annex I Compliance
Stewards don't need to ensure products meet all security requirements
Conformity Assessment
No third-party audits required for stewards
Product Liability
Stewards are not liable for products like manufacturers are
Steward vs Manufacturer: Liability Shield
Article 24 gives stewards lighter obligations than manufacturers. This comparison clarifies what is and is not required.
Steward: What you still must do
- Maintain a documented cybersecurity policy for stewardship activities.
- Run a coordinated vulnerability disclosure intake and triage process.
- Cooperate with market surveillance authorities and ENISA where required.
- Report severe incidents affecting steward-operated development infrastructure.
Steward: What you do not need to do
- No CE marking for open-source components you steward.
- No Annex VII technical documentation package as a manufacturer.
- No conformity assessment module execution (A, B+C, H) as product manufacturer.
- No manufacturer Declaration of Conformity obligations for third-party products.
Manufacturer obligations (for contrast)
- Meet all Annex I essential cybersecurity requirements.
- Complete applicable conformity assessment pathway.
- Issue Declaration of Conformity and affix CE marking.
- Maintain post-market vulnerability handling and mandatory reporting obligations.
Liability shield conditions
The lighter-touch regime is tied to your steward role. If you commercially place products with digital elements on the EU market, manufacturer obligations apply for those products.
Top 10 Actions for Stewards
Based on Linux Foundation guidance
Confirm Legal Entity
Ensure your foundation's legal entity status is clearly documented on website
Identify Projects
List which projects under your stewardship are intended for commercial use
Establish Security Policy
Create or update SECURITY.md with vulnerability handling process
Set Up Exploit Detection
Monitor for reports of actively exploited vulnerabilities in your projects
Prepare SRP Access
Set up EU Login and reporting roles; ENISA advises registering when a specific notification is needed
Leverage Security Tools
Use foundation security tools (OpenSSF Scorecard, Dependabot, etc.)
Enable SBOM Generation
Offer SBOM generation capabilities to downstream users
Perform Component Diligence
Document due diligence on major dependencies
Support Critical Upstreams
Help secure critical upstream dependencies your projects rely on
Stay Informed
Follow CRA implementation updates and guidance
Penalties for Stewards
Good news: OSS Stewards face no administrative fines under the CRA
- • Article 64(10)(b) exempts OSS stewards from administrative fines for any infringement of the Regulation — with no exception
- • Focus is on cooperation and correction, not punishment
- • Market surveillance authorities can still require corrective action
Reference: Article 64(10)(b); Recital 120
Frequently Asked Questions
I'm a solo maintainer. Does CRA apply to me?
Probably not. CRA targets commercial activities and legal entities, not individual volunteer contributors.
Our foundation hosts many projects. Are all of them covered?
Only projects intended for commercial activities and where the foundation provides sustained support for viability.
What counts as 'commercial activity'?
Charging for the software, providing paid support, monetizing through services, or integration into commercial products by downstream users.
Can we still use 'as-is' disclaimers?
Yes, but for projects under stewardship, you still have the lighter obligations even with disclaimers.
Resources
Ready to Start Your Compliance Journey?
Use our free assessment tool to understand your CRA obligations.