Free and open-source software is understood as software the source code of which is openly shared and the licensing of which provides for all rights to make it freely accessible, usable, modifiable and redistributable. Free and open-source software is developed, maintained and distributed openly, including via online platforms. In relation to economic operators that fall within the scope of this Regulation, only free and open-source software made available on the market, and therefore supplied for distribution or use in the course of a commercial activity, should fall within the scope of this Regulation. The mere circumstances under which the product with digital elements has been developed, or how the development has been financed, should therefore not be taken into account when determining the commercial or non-commercial nature of that activity. More specifically, for the purposes of this Regulation and in relation to the economic operators that fall within its scope, to ensure that there is a clear distinction between the development and supply phases, the provision of products with digital elements qualifying as free and open-source software that are not monetised by their manufacturers should not be considered to be a commercial activity. Furthermore, the supply of products with digital elements qualifying as free and open-source software components intended for integration by other manufacturers into their own products with digital elements should be considered to be making available on the market only if the component is monetised by its original manufacturer. For instance, the mere fact that an open-source software product with digital elements receives financial support from manufacturers or that manufacturers contribute to the development of such a product should not in itself determine that the activity is of commercial nature. In addition, the mere presence of regular releases should not in itself lead to the conclusion that a product with digital elements is supplied in the course of a commercial activity. Finally, for the purposes of this Regulation, the development of products with digital elements qualifying as free and open-source software by not-for-profit organisations should not be considered to be a commercial activity provided that the organisation is set up in such a way that ensures that all earnings after costs are used to achieve not-for-profit objectives. This Regulation does not apply to natural or legal persons who contribute with source code to products with digital elements qualifying as free and open-source software that are not under their responsibility.
Recital 18
Regulation (EU) 2024/2847 — published 10 December 2024 · Last reviewed by Kunnus: March 2026
European Commission Interpretation
Guidance of 27 July 2026The EU Commission guidance of 27 July 2026 provides official interpretation notes on this provision. Each section: summary, key takeaways, and what it means for you in practice.
Section 3.1 – 3.2Open source: when is FOSS 'placed on the market'?
What matters is monetisation by the person responsible (the maintainer), not how development was financed: charging for binaries, monetising other services through the software, requiring personal-data processing, or paid editions bundled with support benefits mean placing on the market. Voluntary donations, optional consultancy and third-party sponsoring do not, on their own, trigger CRA scope.
Key takeaways
- The FOSS definition (Art. 3(48)) cumulatively requires a FOSS licence granting the full set of rights AND openly shared source code — code shared only with paying customers is not FOSS.
- Responsibility lies with whoever controls releases, roadmap and distribution; contributors without that control are not subject to the CRA, even with commit access (Example 13).
- A community version and a paid (open-core) version are two distinct products — the free version remains off-market.
- Optional paid services (consulting, training, deployment help) are harmless; paid access to a version bundled with technical support is monetisation (Examples 17/18).
- Donations only become critical where they are de facto a condition of access — e.g. releases or security fixes only for donors (Examples 21/22); cost recovery including reasonable living expenses is permissible.
- Third-party financing (grants, bug bounties, paid feature development) does not make FOSS commercial (recital 18, Example 23).
In practice
Go through your open-source projects one by one and answer two questions: do we control releases and distribution? And do we monetise this specific version (price, monetisation through the software, mandatory data processing, paid edition with support)? Only two yeses make you a manufacturer. A donation link, sponsoring and optional consultancy change nothing.
Section 3.4 – 3.5Contributors, integration and the FOSS scenarios
Manufacturers integrating FOSS components into their own products do not become responsible for those components' individual CRA compliance — not even by contributing code to their maintenance. The due diligence obligation (Art. 13(5)) and upstream obligations (Art. 13(6)) apply. Eight scenarios (Examples 27–34) walk through the typical constellations of developers, foundations and integrating manufacturers.
Key takeaways
- Individual developer with a donation link: no CRA obligations; integrating manufacturers owe due diligence (Examples 27, 34).
- FOSS intended for integration by other manufacturers and not monetised is not placed on the market — its publisher may be a steward (Examples 25/26, 29).
- A FOSS component's CRA status is unaffected by manufacturers integrating it into monetised products.
- Package repositories likewise bear no CRA obligations (Example 34).
In practice
Keep a list of all integrated FOSS components with version, source and maintainer contact. That is the working basis for your due diligence (Art. 13(5)) and for upstream reporting including fix sharing (Art. 13(6)) — you are not, however, responsible for the component's own compliance.
EU Commission Guidance (C(2026) 5252 final) — The guidance reflects the European Commission's interpretation and is not legally binding. An authoritative interpretation of the EU CRA may only be given by the Court of Justice of the European Union.
This text is reproduced from Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024. It is provided for informational purposes only and does not constitute legal advice. Only the text published in the Official Journal of the European Union is legally binding. Original text on EUR-Lex