CRA Kit
Blog · · 2 min read · CRA · Cyber Resilience Act

A paid tier can make your open source project a manufacturer

A donation-funded library stays out of scope under recital 18, but a paid subscription tier makes its maintainer a manufacturer under Article 3(13).

Picture a maintainer who has run a popular open source library for years. Donations come in through GitHub Sponsors. There's no company behind the project.

Recital 18 keeps that kind of project out of the Cyber Resilience Act. Open source software supplied outside a commercial activity stays outside the regulation. A donation button doesn't change that.

The tier changes the activity

Last month the maintainer added a paid tier: priority support and a few extra plugins, sold through a subscription. That's a commercial activity under Article 3(22).

Article 3(13) defines a manufacturer as whoever develops a product and markets it under their own name. That's true whether the product is sold, given away, or monetised some other way. Once the subscription exists, the maintainer fits that definition. The free core library doesn't need to change hands for money. The commercial activity around it is what counts.

A coordinated vulnerability disclosure policy and a public contact address are the baseline under Annex I, points 5 and 6, once the manufacturer label applies from 11 December 2027, under Article 71.

What doesn't change

Article 24 gives open source software stewards a lighter regime. That regime is for stewards, not for manufacturers who happen to publish source code. This maintainer sells a subscription, so the steward regime doesn't apply.

The clock that's already running

Since 11 September 2026, Article 14 applies to the maintainer the same way it applies to any manufacturer. If an actively exploited vulnerability turns up in the library, the maintainer has 24 hours to send an early warning to the CSIRT designated as coordinator and to ENISA. Then 72 hours for the full notification. A final report follows 14 days after a fix or mitigation becomes available. The clock starts the moment the maintainer knows, which can come from a user's report, not when an authority writes to them.

The rest of the regulation, including the SBOM under Annex I and the declaration of conformity under Annex V, applies from 11 December 2027, under Article 71. Fines under Article 64 start the same date.

Check before you add a tier

A subscription tier looks like a small business decision. Under the regulation it can be the detail that moves a project from recital 18 to Article 3(13). The scope test walks through it in a few questions: https://crakit.eu/scope/

Not legal advice.

This is not legal advice.

LD
Louann Duclos

Built CRA Kit. Writes here about what the regulation asks of a small software company. All posts · RSS feed