Skip to main content

CRA Adoption Best Practices

Open Source Stewards

The new actor introduced by the CRA: what open source stewards are, what the regulation expects from them, and how they help SMEs meet their own obligations.

On this page

A new actor in the CRA

The CRA takes the particularities of open source into account and introduces open source stewards as a new actor. The Open Regulatory Compliance community has published a white paper on open source software stewards and the CRA that reflects their expected role. This category is designed for entities that:

Sustained support

Systematically and sustainably support the development of specific open source software.

Governance role

Play a governance or coordination role.

Not commercial

Do not place the software on the market as a commercial product.

Typical examples include foundations, non-profit organisations, and other coordinating bodies that:

  • Oversee governance structures
  • Maintain infrastructure
  • Coordinate security processes
  • Support long-term maintenance

Stewards are not manufacturers

The key legal distinction is that stewards are not manufacturers, provided they do not commercialise the software in a way that would qualify as placing a product with digital elements on the EU market. This distinction is critical for maintaining the open source development model while introducing structured accountability.

Role and responsibilities

The CRA imposes a tailored set of obligations on open source stewards. These are proportionate and reflect their non-commercial role. Stewards must:

Establish and document a verifiable cybersecurity policy

Support secure development practices

Coordinate vulnerability handling processes

Document, address, and facilitate remediation of vulnerabilities

Share relevant vulnerability information with affected projects

Cooperate with national authorities and Market Surveillance Authorities (MSAs)

Importantly

  • Stewards are not subject to the same administrative fines as manufacturers.
  • Their obligations focus on process, coordination, and transparency rather than product conformity.

The legislative intent is clear: strengthen the resilience of open source infrastructure without transforming stewards into regulated product manufacturers.

Stewards as compliance enablers

Open source stewards can act as an intermediary governance layer between community development and regulated product manufacturers. For SMEs, this creates several advantages:

Structured security policies

Stewards formalise security policies that SMEs can reference when documenting:

  • Secure development practices
  • Upstream governance models
  • Vulnerability coordination processes

This reduces the need for SMEs to individually assess each community from scratch.

Coordinated vulnerability handling

Stewards often manage:

  • Security mailing lists
  • Disclosure channels
  • Patch coordination
  • Public advisories

SMEs can integrate these processes into their own vulnerability management frameworks.

Improved transparency

Stewards typically provide documentation regarding:

  • Governance structure
  • Release management
  • Maintenance commitments
  • Security posture

This documentation supports CRA technical files and risk assessments.

Regulatory interface support

When Market Surveillance Authorities request information, stewards can:

  • Provide upstream documentation
  • Clarify vulnerability handling processes
  • Support transparency around development practices

While responsibility remains with the manufacturer, structured stewardship reduces uncertainty.

Cybersecurity attestations

While FOSS development is not directly regulated as commercial manufacturing, the CRA introduces the concept of voluntary security attestations under Article 25, enabling structured transparency across the supply chain.

Unlike traditional conformity assessment models that rely on external audits or one-size-fits-all certifications, CRA attestations are envisaged as a flexible, risk-based mechanism whereby organisations provide contextualised evidence about their processes, practices, and product characteristics in a structured way. They bridge the gap between regulatory expectations and practical implementation realities.

For manufacturers

By anchoring compliance effort in measurable artefacts and documented practices, attestations offer a pragmatic route to demonstrate due diligence and conformity with security requirements across the product lifecycle.

For open source communities and stewards

Attestations let stewards contribute directly to regulatory readiness without assuming the full burdens of a manufacturer. They communicate risk-based assurances about governance, security practices, and maintenance commitments, forming a reusable and scalable compliance asset when aligned with recognised best practices and transparent operating costs.

For SMEs

By relying on steward-produced attestations and integrating them into their own compliance artefacts, SMEs can reduce the cost, complexity, and uncertainty of implementing CRA requirements, and prioritise resources where risk is highest.

Reusable attestations reduce duplication of effort for individual manufacturers and reinforce stewardship as a trusted bridge between collaborative development and regulatory compliance. Coupled with robust tooling, machine-readable artefacts, and community coordination, this approach can lower barriers to compliance, support more resilient supply chains, and encourage cooperative governance models that benefit the European digital ecosystem as a whole.

Attestations enhance transparency but do not replace contextual risk assessment. See how SMEs should consume them as part of their due diligence.

Consuming security attestations

Back to the top