Skip to main content

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] [List Home]
Re: [open-regulatory-compliance] Update on reporting obligations for open source software stewards


On 9/5/2026 12:39 PM, Tobie Langel wrote:

On Sat, Sep 5, 2026 at 21:09 Scott Lewis via open-regulatory-compliance <open-regulatory-compliance@xxxxxxxxxxx> wrote:
On 9/5/2026 2:39 AM, Arnout Engelen wrote:
I read that to mean "the circumstances described in Article 24(3)" (and I guess further guidance or precedent that may come in the future).

The text of the CRA is linked at the top of the FAQ, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ:L_202402847

Thanks.   Here is Article 24(3) text:

3.   The obligations laid down in Article 14(1) shall apply to open-source software stewards to the extent that they are involved in the development of the products with digital elements. The obligations laid down in Article 14(3) and (8) shall apply to open-source software stewards to the extent that severe incidents having an impact on the security of products with digital elements affect network and information systems provided by the open-source software stewards for the development of such products.

[Scott] I would interpret this to say that the Article 14(1,3,8) obligations apply if severe incidents can affect product security that use/depend upon oss...e.g. frameworks/libraries/comm infrastructure/tools platforms, etc.

1) Is that a correct interpretation, or does the legalese restrict or broaden the scope beyond my interpretation?

2) If correct, my interpretation would suggest a very broad application...e.g. any project (used/depended upon by commercial systems) that has 'severe' security implications on network and information systems (use internet for install/update?).  As an example:  would this include openssl, encryption impls, dependency mgmt systems?

No, the only thing this is referring to is any kind of infrastructure a steward is providing to the open source project it is stewarding. Eg a build server. 

Does it then apply to the oss projects that the steward is using/depending upon to provide that build server (eg. compilers, encryption, dependency mgmt systems, etc)?



Back to the top