CRA: Maintainer, Steward or Manufacturer?
Berlin, 10 September 2026
The Cyber Resilience Act has no category of "maintainer". The European Commission’s guidance nevertheless uses the term — for whoever publishes free and open-source software and exercises primary control over its development, releases and distribution. That is the point at which responsibility attaches, not an exemption. Our new topic page places the role: Cyber Resilience Act – Maintainers.
The three positions
Either no one is covered, or an open-source software steward is, or a manufacturer. Natural persons who publish free and open-source software without monetising it remain outside the scope; so does anyone who merely contributes code to a project they do not control. A legal person that provides sustained support for free and open-source software intended for commercial activities is a steward. Whoever supplies under their own name in the course of a commercial activity — for instance by charging for the pre-compiled binaries — is a manufacturer.
What this means in practice
The exit is narrow and turns on legal form: only a legal person can be a steward. Publishing in a public repository is not placing a product on the market, but neither is it an exit from the Regulation — what matters is the commercial purpose for which the software is intended. And status is determined per project and per supply channel, not once for the organisation as a whole. The same organisation can therefore be the steward of one component and the manufacturer of another.
For manufacturers the reporting obligations of Article 14 CRA apply from 11 September 2026. For stewards the date is disputed; the Commission and ENISA now proceed on the basis that the obligations extended by Article 24(3) CRA apply from 11 December 2027. Neither statement is binding, which is why the status question comes before the date question. Details in our article CRA: are open-source software stewards required to report from 11 September 2026?
Provisions
- Article 3(13), (14), (48) CRA – manufacturer, open-source software steward, free and open-source software
- Article 14 CRA – reporting obligations, deadlines of 24 hours, 72 hours, 14 days and one month
- Article 24 CRA – obligations of open-source software stewards, extension of the reporting duties in paragraph 3
- Article 64 CRA – administrative fines, paragraph 2 and the limited exemption in paragraph 10(b)
- Article 71(2) CRA – application from 11 December 2027, Article 14 from 11 September 2026
More on the CRA
- Cyber Resilience Act – Maintainers
- Cyber Resilience Act – what must be done?
- FAQ on the CRA
- Regulation text with article navigation – every article individually linked
- CRA: are open-source software stewards required to report from 11 September 2026?
- All news
About SES Berlin
SES Berlin is a firm of lawyers and civil-law notaries based in Berlin. Our IT and technology practice advises manufacturers, importers, consortia, standards organisations and open-source bodies on the Cyber Resilience Act – from classification as manufacturer or steward, through licensing and contribution frameworks, to disclosure policy, reporting workflow and governance. Roman Ronneburger, Rechtsanwalt and specialist lawyer for copyright and media law, leads the firm’s CRA work and advises international consortia on their European product-security obligations. We work project by project, document each classification so that it can be relied on, and deliver the instruments that follow from it.
We establish the classification per project and put the reporting readiness in place – licensing, disclosure policy, reporting workflow and governance. Your contact: Roman Ronneburger, or through our contact page.
CRA: Maintainer, Steward or Manufacturer?
Berlin, 10 September 2026
The Cyber Resilience Act has no category of "maintainer". The European Commission’s guidance nevertheless uses the term — for whoever publishes free and open-source software and exercises primary control over its development, releases and distribution. That is the point at which responsibility attaches, not an exemption. Our new topic page places the role: Cyber Resilience Act – Maintainers.
The three positions
Either no one is covered, or an open-source software steward is, or a manufacturer. Natural persons who publish free and open-source software without monetising it remain outside the scope; so does anyone who merely contributes code to a project they do not control. A legal person that provides sustained support for free and open-source software intended for commercial activities is a steward. Whoever supplies under their own name in the course of a commercial activity — for instance by charging for the pre-compiled binaries — is a manufacturer.
What this means in practice
The exit is narrow and turns on legal form: only a legal person can be a steward. Publishing in a public repository is not placing a product on the market, but neither is it an exit from the Regulation — what matters is the commercial purpose for which the software is intended. And status is determined per project and per supply channel, not once for the organisation as a whole. The same organisation can therefore be the steward of one component and the manufacturer of another.
For manufacturers the reporting obligations of Article 14 CRA apply from 11 September 2026. For stewards the date is disputed; the Commission and ENISA now proceed on the basis that the obligations extended by Article 24(3) CRA apply from 11 December 2027. Neither statement is binding, which is why the status question comes before the date question. Details in our article CRA: are open-source software stewards required to report from 11 September 2026?
Provisions
- Article 3(13), (14), (48) CRA – manufacturer, open-source software steward, free and open-source software
- Article 14 CRA – reporting obligations, deadlines of 24 hours, 72 hours, 14 days and one month
- Article 24 CRA – obligations of open-source software stewards, extension of the reporting duties in paragraph 3
- Article 64 CRA – administrative fines, paragraph 2 and the limited exemption in paragraph 10(b)
- Article 71(2) CRA – application from 11 December 2027, Article 14 from 11 September 2026
More on the CRA
- Cyber Resilience Act – Maintainers
- Cyber Resilience Act – what must be done?
- FAQ on the CRA
- Regulation text with article navigation – every article individually linked
- CRA: are open-source software stewards required to report from 11 September 2026?
- All news
About SES Berlin
SES Berlin is a firm of lawyers and civil-law notaries based in Berlin. Our IT and technology practice advises manufacturers, importers, consortia, standards organisations and open-source bodies on the Cyber Resilience Act – from classification as manufacturer or steward, through licensing and contribution frameworks, to disclosure policy, reporting workflow and governance. Roman Ronneburger, Rechtsanwalt and specialist lawyer for copyright and media law, leads the firm’s CRA work and advises international consortia on their European product-security obligations. We work project by project, document each classification so that it can be relied on, and deliver the instruments that follow from it.
We establish the classification per project and put the reporting readiness in place – licensing, disclosure policy, reporting workflow and governance. Your contact: Roman Ronneburger, or through our contact page.