The open-source software steward
This is the CRA’s genuine innovation on open source: the creation of an intermediate status between the volunteer contributor, out of scope, and the manufacturer, fully responsible.
The definition
An open-source software steward is a legal person, other than a manufacturer, which has the purpose or objective of systematically providing support on a sustained basis for the development of specific products with digital elements, qualifying as free and open-source software and intended for commercial activities, and which ensures the viability of those products.
Four cumulative elements, each of them discriminating:
| Element | What it rules out |
|---|---|
| Legal person, other than a manufacturer | Natural persons; whoever places the product on the market is a manufacturer, not a steward |
| Systematic and sustained support | One-off funding, occasional patronage, episodic contribution |
| Products intended for commercial activities | Purely academic or hobby projects |
| Ensures viability | Mere hosting or matchmaking |
The entities targeted are chiefly software foundations — Apache, Eclipse, the Linux Foundation and their equivalents — and certain structures providing sustained funding for code.
The obligations actually owed
The list is exhaustive. A steward must:
- put in place and document, in a verifiable manner, a cybersecurity policy to foster the development of a secure product and effective handling of vulnerabilities, appropriate to the nature of the entity and its resources;
- cooperate with market surveillance authorities, at their request, to mitigate the cybersecurity risks of the products concerned;
- comply with the reporting obligations relating to actively exploited vulnerabilities and severe incidents affecting the security of the product, to the extent it is involved in the development of that product;
- provide, on request from the authorities, the necessary information in a language easily understood.
The phrase “appropriate to the nature of the entity and its resources” is essential: a foundation with three employees is not held to the same arrangement as one with two hundred people.
What a steward is NOT subject to
| Manufacturer obligation | Steward |
|---|---|
| CE marking | No |
| EU declaration of conformity | No |
| Annex VII technical documentation | No |
| Conformity assessment procedure | No |
| Annex I essential requirements as such | No — replaced by the cybersecurity policy |
| Five-year support period | No |
| Annex II information to the user | No |
| Administrative fines | No — the financial penalty regime does not apply to stewards |
The exclusion of administrative fines is the most commented point. It does not mean no consequences: market surveillance authorities keep their powers of injunction and cooperation, and a foundation’s reputation is its principal asset.
Your self-qualification grid
Answer yes or no for each structure you run or fund:
- Is the structure a separate legal person?
- Is it other than a manufacturer of the product concerned — that is, does it not place the product on the market itself?
- Does its purpose or objective include supporting the development of identified free software?
- Is that support systematic and sustained, rather than one-off?
- Is the software concerned intended for commercial activities, that is, used in products placed on the market by third parties?
- Does the structure ensure the viability of that software — governance, funding, continuity over time?
Six yeses: the steward status is probably established, and the four obligations above apply. A single no: it is not, but the qualification must be revisited if circumstances change.
What this changes for you as an integrator
A component maintained by an identified steward offers more assurance than one maintained by an isolated individual: there is a documented cybersecurity policy, a reporting channel and a duty to cooperate. That is a selection criterion to build into your diligence grid — see Integrating open source.