On 9/5/2026 2:39 AM, Arnout Engelen
wrote:
I read that to mean "the circumstances described in Article
24(3)" (and I guess further guidance or precedent that may come
in the future).
Thanks. Here is Article 24(3) text:
3. The obligations laid down in Article 14(1) shall apply to
open-source software stewards to the extent that they are involved
in the development of the products with digital elements. The
obligations laid down in Article 14(3) and (8) shall apply to
open-source software stewards to the extent that severe incidents
having an impact on the security of products with digital elements
affect network and information systems provided by the open-source
software stewards for the development of such products.
[Scott] I would interpret this to say that the Article 14(1,3,8)
obligations apply if severe incidents can affect product security
that use/depend upon oss...e.g. frameworks/libraries/comm
infrastructure/tools platforms, etc.
1) Is that a correct interpretation, or does the legalese
restrict or broaden the scope beyond my interpretation?
2) If correct, my interpretation would suggest a very broad
application...e.g. any project (used/depended upon by commercial
systems) that has 'severe' security implications on network and
information systems (use internet for install/update?). As an
example: would this include openssl, encryption impls, dependency
mgmt systems?