RoleArt. 3(14)

Open-source steward

An open-source software steward is any legal person who provides systematic support for the development of a free and open-source software product, the intended use of which can reasonably be expected to be commercial.

Key facts

  • New category introduced by the CRA to address OSS without penalising individual developers
  • Lighter obligations than manufacturers (no CE marking, no DoC)
  • Must put a cybersecurity policy in place and cooperate with authorities
  • Commercial-activity test determines whether an OSS project is in scope
  • Steward status does not apply to downstream users who package/distribute the software

Obligations (4)

OBL-ART24-01Binding

Establish and document a cybersecurity policy for open-source software

Open-source software stewards must put in place and document a cybersecurity policy that fosters the development of a secure product and enables effective handling of vulnerabilities in the open-source software components they support.

Art. 24(1)
Open-source steward
OBL-ART24-02Binding

Notify actively exploited vulnerabilities and severe incidents

Open-source software stewards must notify the relevant CSIRT (computer security incident response team) designated as coordinator without undue delay of any actively exploited vulnerability contained in their open-source software components, as well as any severe incident affecting the security of those components.

Art. 24(2)
Open-source steward
OBL-ART24-03Binding

Cooperate with market surveillance authorities

Open-source software stewards must cooperate with market surveillance authorities upon request and provide all information required for the performance of their regulatory tasks.

Art. 24(3)
Open-source steward
OBL-ART24-04Binding

Draw up technical documentation on request

Upon request from market surveillance authorities, open-source software stewards must draw up and keep up-to-date technical documentation for the open-source software components they administer, sufficient to allow assessment of cybersecurity compliance.

Art. 24(4)
Open-source steward
Open-source steward obligations — CRA Compliance Hub