OSPulse

Does the CRA apply to open source?

The Cyber Resilience Act doesn’t regulate open source itself. It regulates the commercial activity built on top of it. A hobby project given away for free is generally outside its reach. A foundation that sustains one gets a lighter duty. A company that ships one inside a paid product carries the full weight, same as if they’d written it themselves.

This isn’t legal advice, and no tool, OSPulse included, can tell you your project’s status with certainty. What follows is the general shape of the rule; where it sits on your own project is a question for counsel.

Shipping open source inside a commercial product and not sure where you stand? Run the scope check first: it’s free and takes a minute.

Same code, three different duty sets, depending on how it reaches the market.

The CRA doesn’t ask what licence a piece of software carries. It asks how (and by whom) that software is put on the EU market.

01

A hobby project, given away for free.

Software developed and supplied outside the course of a commercial activity generally falls outside the CRA’s scope. Volunteers maintaining a project on evenings and weekends, with no price, no paid support tier and no commercial platform sitting underneath it, are the case the exemption was written for. That said, the line isn’t judged by intent alone: it’s assessed against how the specific product is developed and supplied, and things like paid support contracts or a commercial platform built around the project can pull it back in. If a project sits anywhere near that edge, this is a question for counsel, not a marketing page.

02

A foundation or company that sustains one: the “open-source software steward.”

The CRA creates a specific category for an organisation that provides sustained, systematic support for an open-source project used in commercial activity, or keeps that project viable, without itself being the manufacturer selling a product. Think foundations, consortia and companies that fund maintenance. Stewards carry a lighter set of duties than a manufacturer: a documented cybersecurity policy for the project, cooperation with market surveillance authorities, and, from 11 September 2026, a version of the same active-exploitation and severe-incident reporting duty that applies to manufacturers. They’re not required to CE-mark anything, and they sit outside the CRA’s administrative fines. A natural person can’t be a steward: it’s an organisational category.

03

A company that ships open source inside a commercial product: full stop, you’re the manufacturer.

This is the one that catches people out. If you take an open-source library, framework or component and ship it as part of a product with digital elements you place on the EU market, you’re the manufacturer of that product under the CRA, the same as if you’d written every line yourself. That means the full set of manufacturer duties for your product: essential security requirements, technical documentation, due diligence on the components you’ve integrated, and Article 14 reporting of actively exploited vulnerabilities and severe incidents from 11 September 2026. Using open source doesn’t transfer the obligation to whoever wrote the library: it sits with whoever ships the product.

We help with tier three: the manufacturer case.

If you’re a hobby maintainer or a steward, the lighter duties above are the ones that apply to you, and OSPulse isn’t really built for that problem. Where OSPulse earns its keep is the third tier: a company shipping open-source components inside a commercial product, carrying the full manufacturer duty for that product. Knowing exactly which open-source dependencies you’ve shipped, in which releases, and whether any of them are being actively exploited right now is most of the hard part of staying ahead of that duty.

OSPulse generates the SBOM from the scans you already run, watches your dependencies against exploitation intelligence, and assembles a submission-ready pack the moment a finding is reportable. See how OSPulse builds the pack.

Frequently asked

I maintain an open-source project in my spare time. Does the CRA apply to me?

Generally, no: software developed and supplied outside a commercial activity is meant to sit outside the CRA’s scope, and that’s the exemption a typical hobby project falls under. But the assessment is product-by-product, not identity-by-identity: things like a paid support tier or a commercial platform built around the project can change the answer. If that’s close to your situation, take advice rather than relying on a general answer. This isn’t legal advice, and no tool, OSPulse included, can tell you your project’s status with certainty.

What exactly is an “open-source software steward”?

It’s a CRA-specific category for an organisation (a foundation, consortium or company) that sustains an open-source project used in commercial activity without being the manufacturer that sells a product built on it. Stewards get a lighter duty set than manufacturers: a documented security policy for the project and cooperation with authorities, plus a version of the reporting duty from 11 September 2026. No CE marking, and they’re outside the CRA’s administrative fines. It doesn’t apply to individuals.

We build a commercial product on top of open-source components. Are we in scope?

Yes, for that product. Shipping open-source components inside a product you place on the EU market makes you the manufacturer of that product: the full duty set applies, including due diligence on what you’ve integrated and Article 14 reporting of actively exploited vulnerabilities and severe incidents from 11 September 2026. The open-source origin of a component doesn’t move the obligation off your desk.

Does OSPulse help pure open-source maintainers or stewards?

Honestly, not much. OSPulse is built for the manufacturer case: knowing which open-source components you’ve shipped inside a commercial product, whether any of them are being actively exploited, and having the reporting pack ready if one is. If you’re a steward or a non-commercial maintainer, the lighter duties above are the ones that apply to you, not the manufacturer machinery this site is built around.

Does OSPulse make us CRA compliant if we ship open source inside our product?

No tool can. OSPulse gives you the inventory of what you’ve shipped, an exploitation watch, and a submission-ready report pack for the manufacturer duties the CRA sets: your team, and for many firms your counsel, makes the compliance decisions. We make those decisions fast and defensible, not automatic.

Shipping open source inside a commercial product?

That’s the manufacturer duty, full weight, from 11 September 2026. Know what you ship before you have to report on it.