Cyber Resilience Act · Article 24

Obligations of open-source software stewards

Binds
open source steward
Applies from
Evidence
document

Article 24(1): Obligations of open-source software stewards

open source steward · Article 24(1)

Obligations of open-source software stewards 1. Open-source software stewards shall put in place and document in a verifiable manner a cybersecurity policy to foster the development of a secure product with digital elements as well as an effective handling of vulnerabilities by the developers of that product. That policy shall also foster the voluntary reporting of vulnerabilities as laid down in Article 15 by the developers of that product and take into account the specific nature of the open-source software steward and the legal and organisational arrangements to which it is subject. That policy shall, in particular, include aspects related to documenting, addressing and remediating vulnerabilities and promote the sharing of information concerning discovered vulnerabilities within the open-source community.

How to satisfy it: Note 'in a verifiable manner' — an undocumented policy does not satisfy this. Whether an organisation is a steward, a manufacturer, or neither is the single most contested scope question in the CRA and changes the entire obligation set.

Article 24(1) on EUR-Lex · as of 2026-08-13 · Regulation (EU) 2024/2847

Every quoted requirement on this page is verbatim Official Journal text. The surrounding guidance is Legalithm’s commentary and is not regulation. This page states the obligation and its legal basis; it is not legal advice, and the corpus has not been reviewed by counsel.