Source: OJ L 2024/2847, 20.11.2024

Current language: EN

Article 24 Obligations of open-source software stewards


Summary What does Article 24 of the CRA regulation say?

This article carves out a tailored regime for open-source software stewards, a category of legal person distinct from manufacturers that supports the development of free and open-source software intended for commercial activities.

Rather than applying the full manufacturer obligations found elsewhere in the regulation, Article 24 establishes a lighter-touch but still meaningful set of requirements.

The core obligation is to have a documented, verifiable cybersecurity policy covering how vulnerabilities are handled, reported, and shared within the open-source community.

The article also connects directly to Article 14, extending certain incident and vulnerability reporting obligations to stewards, but only to the extent they are involved in development or where severe incidents affect their own systems.

Important points:

  • Open-source software stewards are required to put in place and document a verifiable cybersecurity policy covering vulnerability handling, remediation, and information sharing within the open-source community.
  • Open-source software stewards must cooperate with market surveillance authorities on request and provide their cybersecurity policy documentation in a language easily understood by those authorities.
  • Reporting obligations from Article 14 apply to open-source software stewards, but only in a scoped manner — vulnerability reporting applies where they are involved in development, and severe incident reporting applies where their own systems are affected.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

    1. Open-source software stewards shall put in place and document in a verifiable manner a cybersecurity policy to foster the development of a secure product with digital elements as well as an effective handling of vulnerabilities by the developers of that product. That policy shall also foster the voluntary reporting of vulnerabilities as laid down in Article 15 by the developers of that product and take into account the specific nature of the open-source software steward and the legal and organisational arrangements to which it is subject. That policy shall, in particular, include aspects related to documenting, addressing and remediating vulnerabilities and promote the sharing of information concerning discovered vulnerabilities within the open-source community.

    1. Open-source software stewards shall cooperate with the market surveillance authorities, at their request, with a view to mitigating the cybersecurity risks posed by a product with digital elements qualifying as free and open-source software.

    2. Further to a reasoned request from a market surveillance authority, open-source software stewards shall provide that authority, in a language which can be easily understood by that authority, with the documentation referred to in paragraph 1, in paper or electronic form.

    1. The obligations laid down in Article 14(1) shall apply to open-source software stewards to the extent that they are involved in the development of the products with digital elements. The obligations laid down in Article 14(3) and (8) shall apply to open-source software stewards to the extent that severe incidents having an impact on the security of products with digital elements affect network and information systems provided by the open-source software stewards for the development of such products.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod