Sustained support
Systematically and sustainably support the development of specific open source software.
CRA Adoption Best Practices
The new actor introduced by the CRA: what open source stewards are, what the regulation expects from them, and how they help SMEs meet their own obligations.
The CRA takes the particularities of open source into account and introduces open source stewards as a new actor. The Open Regulatory Compliance community has published a white paper on open source software stewards and the CRA that reflects their expected role. This category is designed for entities that:
Systematically and sustainably support the development of specific open source software.
Play a governance or coordination role.
Do not place the software on the market as a commercial product.
Typical examples include foundations, non-profit organisations, and other coordinating bodies that:
Stewards are not manufacturers
The key legal distinction is that stewards are not manufacturers, provided they do not commercialise the software in a way that would qualify as placing a product with digital elements on the EU market. This distinction is critical for maintaining the open source development model while introducing structured accountability.
The CRA imposes a tailored set of obligations on open source stewards. These are proportionate and reflect their non-commercial role. Stewards must:
Importantly
The legislative intent is clear: strengthen the resilience of open source infrastructure without transforming stewards into regulated product manufacturers.
Open source stewards can act as an intermediary governance layer between community development and regulated product manufacturers. For SMEs, this creates several advantages:
Stewards formalise security policies that SMEs can reference when documenting:
This reduces the need for SMEs to individually assess each community from scratch.
Stewards often manage:
SMEs can integrate these processes into their own vulnerability management frameworks.
Stewards typically provide documentation regarding:
This documentation supports CRA technical files and risk assessments.
When Market Surveillance Authorities request information, stewards can:
While responsibility remains with the manufacturer, structured stewardship reduces uncertainty.
While FOSS development is not directly regulated as commercial manufacturing, the CRA introduces the concept of voluntary security attestations under Article 25, enabling structured transparency across the supply chain.
Unlike traditional conformity assessment models that rely on external audits or one-size-fits-all certifications, CRA attestations are envisaged as a flexible, risk-based mechanism whereby organisations provide contextualised evidence about their processes, practices, and product characteristics in a structured way. They bridge the gap between regulatory expectations and practical implementation realities.
By anchoring compliance effort in measurable artefacts and documented practices, attestations offer a pragmatic route to demonstrate due diligence and conformity with security requirements across the product lifecycle.
Attestations let stewards contribute directly to regulatory readiness without assuming the full burdens of a manufacturer. They communicate risk-based assurances about governance, security practices, and maintenance commitments, forming a reusable and scalable compliance asset when aligned with recognised best practices and transparent operating costs.
By relying on steward-produced attestations and integrating them into their own compliance artefacts, SMEs can reduce the cost, complexity, and uncertainty of implementing CRA requirements, and prioritise resources where risk is highest.
Reusable attestations reduce duplication of effort for individual manufacturers and reinforce stewardship as a trusted bridge between collaborative development and regulatory compliance. Coupled with robust tooling, machine-readable artefacts, and community coordination, this approach can lower barriers to compliance, support more resilient supply chains, and encourage cooperative governance models that benefit the European digital ecosystem as a whole.
Attestations enhance transparency but do not replace contextual risk assessment. See how SMEs should consume them as part of their due diligence.