Chapter II - OBLIGATIONS OF ECONOMIC OPERATORS AND PROVISIONS IN RELATION TO FREE AND OPEN-SOURCE SOFTWARE
24

Article 24

Obligations of open-source software stewards

Regulation (EU) 2024/2847 — published 10 December 2024 · Last reviewed by Kunnus: March 2026

Quick Answer for Manufacturers

Article 24 introduces a new actor category: the 'open-source software steward.' Stewards are legal persons that systematically support and commercially exploit open-source software — they bear reduced but explicit obligations.

This quick answer + FAQ supplements the original legal text with practice-oriented interpretation. Only the original text is legally binding.

(1)

Open-source software stewards shall put in place and document in a verifiable manner a cybersecurity policy to foster the development of a secure product with digital elements as well as an effective handling of vulnerabilities by the developers of that product. That policy shall also foster the voluntary reporting of vulnerabilities as laid down in Article 15 by the developers of that product and take into account the specific nature of the open-source software steward and the legal and organisational arrangements to which it is subject. That policy shall, in particular, include aspects related to documenting, addressing and remediating vulnerabilities and promote the sharing of information concerning discovered vulnerabilities within the open-source community.

(2)

Open-source software stewards shall cooperate with the market surveillance authorities, at their request, with a view to mitigating the cybersecurity risks posed by a product with digital elements qualifying as free and open-source software.

Further to a reasoned request from a market surveillance authority, open-source software stewards shall provide that authority, in a language which can be easily understood by that authority, with the documentation referred to in paragraph 1, in paper or electronic form.

(3)

The obligations laid down in Article 14(1) shall apply to open-source software stewards to the extent that they are involved in the development of the products with digital elements. The obligations laid down in Article 14(3) and (8) shall apply to open-source software stewards to the extent that severe incidents having an impact on the security of products with digital elements affect network and information systems provided by the open-source software stewards for the development of such products.

European Commission Interpretation

Guidance of 27 July 2026

The EU Commission guidance of 27 July 2026 provides official interpretation notes on this provision. Each section: summary, key takeaways, and what it means for you in practice.

Section 3.3Open-source software stewards — graduated obligations

Stewards are legal persons that systematically support FOSS intended for commercial activities without placing it on the market (Art. 3(14), Art. 24). The guidance grades the reporting obligations by type of support: purely non-technical support, hosting the infrastructure, or active engineering contributions.

Key takeaways

  • The role applies per FOSS project: the same organisation can be steward for product A and manufacturer for product B (e.g. community vs. paid edition).
  • Non-technical support only (branding, governance, events, donations): no obligation to report actively exploited vulnerabilities — but share information with maintainers and consider voluntary reporting under Art. 15.
  • Infrastructure steward (repos, version control, signing keys): notify ENISA/CSIRTs of severe incidents affecting product security (Art. 14(3)) and inform users where appropriate.
  • Engineering steward (developers, releases, vulnerability handling): report actively exploited vulnerabilities (Art. 14(1)) and inform users (Art. 14(8)).
  • Not-for-profit entities whose earnings serve not-for-profit objectives do not place their FOSS on the market even where it is monetised — steward obligations apply (Example 24: browser funded via search-engine partnerships).

In practice

Clarify per FOSS project what kind of support you provide — governance/branding only, infrastructure (repos, signing keys), or active engineering. That directly determines which reporting and information duties under Article 24 apply to you. The same organisation can be steward for project A and manufacturer for project B.

Section in the guidance overview
Browse all guidance chapters

EU Commission Guidance (C(2026) 5252 final)The guidance reflects the European Commission's interpretation and is not legally binding. An authoritative interpretation of the EU CRA may only be given by the Court of Justice of the European Union.

Common Manufacturer Questions

Who qualifies as an open-source steward under Article 24?

Legal persons whose purpose is the systematic support of the development of commercially used open-source software — for example, the Apache Software Foundation, Eclipse Foundation, Linux Foundation, or the ownership entities of major commercial OSS projects.

What obligations do stewards have?

A reduced set compared to manufacturers: establish a cybersecurity policy, facilitate voluntary vulnerability disclosure, cooperate with market surveillance authorities. But no full Annex I requirements as for manufacturers.

What about non-commercial open-source software?

Remains generally outside CRA scope. Only when a commercial actor integrates the OSS into a product with digital elements or commercially distributes it do CRA obligations apply — and they apply to the integrating manufacturer, not to the OSS project.

Related Recitals

(4)

CRA updates by email

Deadlines, official guidance, and myth-busting fact-checks on the Cyber Resilience Act — compact in our newsletter.

View newsletters

This text is reproduced from Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024. It is provided for informational purposes only and does not constitute legal advice. Only the text published in the Official Journal of the European Union is legally binding. Original text on EUR-Lex