Open-Source Software Steward: The CRA's Light-Touch Category
What an open-source software steward is under the Cyber Resilience Act, which obligations apply, and why the category matters for open-core companies.
An open-source software steward is a legal person, other than a manufacturer, that systematically provides support on a sustained basis for the development of specific open-source products with digital elements intended for commercial activities, and that ensures the viability of those products, as defined by Article 3(14) of the Cyber Resilience Act. The category was created for foundations and companies that maintain open-source software without placing it on the market themselves.
Its obligations (Article 24) are deliberately light: put in place and document a cybersecurity policy covering secure development and vulnerability handling, cooperate with market surveillance authorities on request, notify actively exploited vulnerabilities to the extent the steward is involved in development, and notify severe incidents when they affect infrastructure the steward provides for developing the product. Stewards do not need CE marking, conformity assessment, or a technical file, and under Article 64(10)(b) they are exempt from administrative fines.
The role is particularly relevant for open-core companies, which typically act as manufacturer for their paid edition and as steward for their free community edition. The full analysis is in what the CRA means for open-source companies.





