Free CRA tool

Manufacturer, steward, or neither?

The Cyber Resilience Act treats open-source software differently depending on who publishes it and how it is monetised. Answer the questions below to see which role you hold for a given project and what follows from it. Nothing is stored on our servers.

Does it qualify as FOSS?

Is it under a licence granting the rights to freely access, use, modify and redistribute it?

The first limb of Article 3(48).

Is the source code publicly available?

The second limb. Source shared only with paying customers or a limited group does not qualify.

Your relationship to the project

Do you control releases, roadmap and governance?

Commit access alone is not enough.

Are you a legal person?

A company or foundation, rather than an individual. The steward category applies only to legal persons.

How is it monetised?

Do you charge a price for the software itself?

Including for pre-compiled binaries.

Is access to a particular version, with support bundled in, conditioned on payment?

A paid or enterprise edition including technical assistance or performance optimisation.

Do you sell optional services around a freely downloadable product?

Consultancy, training or deployment help, where anyone can still download and install the software.

Do you monetise other products or services through the software?

Advertising, commission, or subscriptions sold through it.

Does using it require personal data processing beyond security, compatibility or interoperability?

For example targeted advertising or unrelated analytics.

Is access to the software, its essential functionality or its updates conditioned on donating?

Binaries or security fixes only for donors would count.

Do you publish a free community version alongside a paid one?

These are two different products with two different answers.

Are you a not-for-profit whose earnings after costs serve not-for-profit objectives?

Set up so that all earnings after costs go to those objectives.

For the record

Do you accept unconditional donations?

Recorded for completeness. This does not affect the outcome, even above cost.

Has a third party funded any of the development?

Recorded for completeness. How development was financed is not relevant.

Your role

Not yet determined

This software is not placed on the EU market.

Answer the remaining questions for a determination.

CRA Art 3(48) · CRA recital 18 · C(2026) 5252 section 3

Working out whether the CRA applies to your product at all? Check scope and classification.

How the roles work

What makes software FOSS under the CRA?

Article 3(48) sets two cumulative conditions. The software must be made available under a free and open-source licence granting all rights to access, use, modify and redistribute it, and its source code must be openly shared. Commission guidance C(2026) 5252 confirms that software under a free licence whose source is shared only with paying customers or a limited group of users does not qualify.

Maintainer or contributor?

The CRA does not apply to people who contribute source code to projects that are not under their responsibility. A project is under the responsibility of whoever publishes it and exercises primary control over its development, releases and distribution decisions. The mere existence of commit access does not establish responsibility. Submitting a pull request that maintainers review, accept and ship leaves you a contributor.

What counts as monetisation?

Charging a price for the software, including for pre-compiled binaries. Monetising other products or services through it. Requiring the processing of personal data as a condition of use for reasons beyond security, compatibility or interoperability. Conditioning access, essential functionality or updates on a donation. Making a paid edition available that bundles technical assistance, even where functionally equivalent software is also free.

What does not count: selling optional consultancy, training or deployment services around software anyone can download and install. Accepting unconditional donations, even where they exceed the costs of development. And how the development was financed, which the guidance treats as irrelevant to the commercial character of the supply.

What is an open-source software steward?

A legal person, other than a manufacturer, whose purpose is to provide support on a sustained basis for the development of free and open-source software intended for commercial activities, and which ensures the viability of that software. Stewards carry a narrower set of obligations under Article 24 rather than the full manufacturer set. The category applies only to legal persons, so an individual publishing unmonetised software has no obligations under the CRA for it.

The same legal entity can hold different roles for different projects, and can be a steward for a free community version while being the manufacturer of a paid one.

How far do a steward’s reporting duties go?

Article 24(3) scales them to the support provided. A steward giving only non-technical support, such as branding, governance or organising events, has no reporting duty at all, though it should share what it learns with maintainers and consider voluntary reporting under Article 15. A steward hosting the underlying infrastructure must notify ENISA and the CSIRTs of severe incidents affecting that infrastructure. A steward contributing engineering resources must additionally notify actively exploited vulnerabilities it becomes aware of, and inform impacted users where it has a direct relationship with them.