15

Recital 15

Regulation (EU) 2024/2847 — published 10 December 2024 · Last reviewed by Kunnus: March 2026

This Regulation applies to economic operators only in relation to products with digital elements made available on the market, hence supplied for distribution or use on the Union market in the course of a commercial activity. Supply in the course of a commercial activity might be characterised not only by charging a price for a product with digital elements, but also by charging a price for technical support services where this does not serve only the recuperation of actual costs, by an intention to monetise, for instance by providing a software platform through which the manufacturer monetises other services, by requiring as a condition for use the processing of personal data for reasons other than exclusively for improving the security, compatibility or interoperability of the software, or by accepting donations exceeding the costs associated with the design, development and provision of a product with digital elements. Accepting donations without the intention of making a profit should not be considered to be a commercial activity.

European Commission Interpretation

Guidance of 27 July 2026

The EU Commission guidance of 27 July 2026 provides official interpretation notes on this provision. Each section: summary, key takeaways, and what it means for you in practice.

Section 3.1 – 3.2Open source: when is FOSS 'placed on the market'?

What matters is monetisation by the person responsible (the maintainer), not how development was financed: charging for binaries, monetising other services through the software, requiring personal-data processing, or paid editions bundled with support benefits mean placing on the market. Voluntary donations, optional consultancy and third-party sponsoring do not, on their own, trigger CRA scope.

Key takeaways

  • The FOSS definition (Art. 3(48)) cumulatively requires a FOSS licence granting the full set of rights AND openly shared source code — code shared only with paying customers is not FOSS.
  • Responsibility lies with whoever controls releases, roadmap and distribution; contributors without that control are not subject to the CRA, even with commit access (Example 13).
  • A community version and a paid (open-core) version are two distinct products — the free version remains off-market.
  • Optional paid services (consulting, training, deployment help) are harmless; paid access to a version bundled with technical support is monetisation (Examples 17/18).
  • Donations only become critical where they are de facto a condition of access — e.g. releases or security fixes only for donors (Examples 21/22); cost recovery including reasonable living expenses is permissible.
  • Third-party financing (grants, bug bounties, paid feature development) does not make FOSS commercial (recital 18, Example 23).

In practice

Go through your open-source projects one by one and answer two questions: do we control releases and distribution? And do we monetise this specific version (price, monetisation through the software, mandatory data processing, paid edition with support)? Only two yeses make you a manufacturer. A donation link, sponsoring and optional consultancy change nothing.

Section in the guidance overview
Browse all guidance chapters

EU Commission Guidance (C(2026) 5252 final)The guidance reflects the European Commission's interpretation and is not legally binding. An authoritative interpretation of the EU CRA may only be given by the Court of Justice of the European Union.

Related Articles

(1)

This text is reproduced from Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024. It is provided for informational purposes only and does not constitute legal advice. Only the text published in the Official Journal of the European Union is legally binding. Original text on EUR-Lex