Home Content News EU Clarifies CRA Rules For Non Commercial Open Source

EU Clarifies CRA Rules For Non Commercial Open Source

0
1

The European Commission has issued new guidance clarifying when open-source software falls under the Cyber Resilience Act, giving developers and organisations greater legal certainty ahead of upcoming reporting obligations.

The European Commission has published an 80-page guidance document clarifying how the Cyber Resilience Act (CRA) should be interpreted, providing long-awaited legal certainty for free and open-source software before the first reporting obligations begin on 11 September 2026.

The guidance confirms that freely available open-source software is generally outside the scope of the CRA, provided it is not marketed as part of a commercial activity. It also defines commercial activity, stating that projects selling software, offering paid enterprise editions, monetising services through software, requiring personal data beyond security or interoperability purposes, or making donations effectively mandatory for software access or essential updates fall under the regulation.

Conversely, voluntary donations, sponsorships, public funding, and paid consulting, training or support services do not automatically make an open-source project commercial, provided the software itself remains freely available.

The Commission also distinguishes between contributors and project leaders. Developers who submit patches or fix bugs generally bear no CRA responsibility. Instead, obligations apply primarily to individuals or organisations controlling releases, project roadmaps and governance. It also clarifies the responsibilities of open-source stewards, with obligations depending on their involvement in infrastructure, development and security management.

Although the handbook is not legally binding, it is expected to shape how manufacturers and national authorities interpret the CRA. Full manufacturer compliance becomes mandatory on 11 December 2027.
European Commission Vice-President Henna Virkkunen said, “A secure Europe and a business-friendly Europe go hand in hand.”

LEAVE A REPLY

Please enter your comment!
Please enter your name here