Does the Cyber Resilience Act Apply to Open Source Software?
Learn if the EU CRA applies to Open Source Software, what the core compliance requirements are, and how to start preparing your engineering teams automatically.
Core Definition
undefined. Exempt for non-commercial use, but commercial distribution is covered. A solo maintainer distributing a library for free is generally outside CRA scope, but a company packaging and selling that same library commercially pulls it into scope. If you do not fall into an explicit exemption, your Open Source Software will be subjected to the CRA's strict requirements.
Key Compliance Steps for Open Source Software
- Determine Classification: Check if your Open Source Software falls under the default category or Class I/Class II, which dictate stricter conformity assessment paths.
- Perform Risk Assessment: Map out the attack surface for your It Depends and document the mitigations for the "secure by design" requirement.
- Implement Vulnerability Reporting: Provide a 24-hour reporting mechanism to ENISA for actively exploited vulnerabilities.
- Generate an SBOM: Ensure all dependencies used in your Open Source Software are documented in a machine-readable Software Bill of Materials.
- Avoid the Common Pitfall: Foundations assume all open source is CRA-exempt; commercial redistribution and support contracts change that.
How This Plays Out in Practice
A solo maintainer distributing a library for free is generally outside CRA scope, but a company packaging and selling that same library commercially pulls it into scope.
What to Watch For
Foundations assume all open source is CRA-exempt; commercial redistribution and support contracts change that.
Assess Your CRA Readiness
Evaluate your product's Cyber Resilience Act readiness using our interactive tool. Find exactly which of the 22 security requirements apply directly to Open Source Software.