Skip to content
You can now search across every topic, entity and event.What's new
European Tech Sovereignty
17MAY

CRA draft pins open-source liability on publishers

3 min read
14:28UTC

The European Commission published draft Cyber Resilience Act open-source guidance on Tuesday 3 March 2026 with consultation closing on Tuesday 31 March, confirming that responsibility for free and open-source software falls on who publishes and controls, not on contributors with commit access.

TechnologyDeveloping
Key takeaway

Maintainer liability is settled at the publisher-control test; donation triggers remain unresolved with the September 2026 reporting clock running.

On Tuesday 3 March 2026, the European Commission published draft implementation guidance for the Cyber Resilience Act (CRA, the EU's binding cybersecurity law covering digital products and software with digital elements) governing how the law applies to free and open-source software 1. Consultation closed on Tuesday 31 March. The guidance establishes that responsibility under the CRA falls on the entity that publishes and controls the software, not on individual contributors who hold commit access.

The CRA reporting clock starts on Friday 11 September 2026 regardless of whether the Commission publishes final guidance before then. The draft closes the contributor-versus-publisher ambiguity Felix Reda, the German digital rights advocate and former MEP, had flagged repeatedly through 2024 and 2025. Hogan Lovells' published analysis of the draft confirms full compliance applies from Saturday 11 December 2027. OpenForum Europe and other open-source advocacy bodies welcomed the publisher-control test as resolving the most acute exposure for individual maintainers.

The grey area that remains is whether financial donations to a project trigger "placed on market" obligations under the CRA. The draft text suggests donations can trigger those obligations where access to essential functionality is conditional on payment. That conditional clause is the file's unresolved question for maintainers operating donation-funded projects with no separation between freely available and donor-tier functionality. The seven-CEO deregulation letter arrived in the same fortnight; the CRA open-source file was not in scope, but the legislative environment is the same. the Commission has not published the final guidance, and no publication date has been announced as of mid-May 2026.

Deep Analysis

In plain English

The Cyber Resilience Act (CRA) is an EU law that will require software sold in Europe to meet minimum security standards; much like toy safety labels or car crash tests, but for software. The CRA creates a problem for open-source software: code that anyone can download freely and modify, written by volunteers who are not paid. The guidance published in March clarifies two things. First, if you publish and control an open-source project, you are responsible for its security, not every individual who has ever contributed code. Second, if your project receives regular financial donations (through crowdfunding or sponsorship platforms), you may count as a commercial entity and lose some of the open-source exemptions. For software developers in Europe, this means they need to track who funds their projects and whether that funding crosses a compliance threshold.

Deep Analysis
Root Causes

The CRA's open-source liability ambiguity was an unintended product of the legislation's history: the original 2022 Commission proposal focused on IoT hardware and commercial software, and the open-source carve-out was added by the European Parliament during trilogue in 2023 without a detailed definition of who fell within the carve-out.

The carve-out's wording; 'freely available software, not in the course of a commercial activity'; was drafted by MEPs without input from open-source foundations, who only engaged fully after the text was finalised.

Felix Reda, the former MEP and open-source advocate, had flagged the contributor-vs-publisher ambiguity publicly from the first published draft, but his interventions during the passage of the legislation were unsuccessful in securing a clearer text. The March 2026 guidance is the belated administrative response to that unresolved legislative gap.

What could happen next?
  • Risk

    The donation-triggers-liability ambiguity may cause GitHub Sponsors and Open Collective to implement EU geo-restrictions on donation features before 11 September 2026, drying up funding for European open-source maintainers at the moment CRA compliance investment is highest.

    Immediate · 0.55
  • Precedent

    The publisher-not-contributor liability rule will become the reference point for all subsequent EU digital product-safety legislation applied to software, including potential extensions of the AI Act to open-weight AI models.

    Long term · 0.7
  • Consequence

    The 11 September 2026 CRA reporting deadline applies regardless of whether the Commission publishes final guidance, meaning open-source publishers must begin compliance preparations under the draft guidance framework with no guarantee that the final rules will match.

    Immediate · 0.85
First Reported In

Update #5 · Brussels' 27 May package, two days before G7

Sovereign Tech Agency· 17 May 2026
Read original
Causes and effects
This Event
CRA draft pins open-source liability on publishers
Resolves the contributor-versus-publisher ambiguity Felix Reda flagged, though the financial-donations grey area remains live before reporting obligations begin on 11 September 2026.
Different Perspectives
Germany (Bundeskartellamt)
Germany (Bundeskartellamt)
Germany's Bundeskartellamt declined to open antitrust proceedings against SAP, the company disclosed on 30 July, in the same fortnight the Commission's EUR 890m DMA fine against Google approached its 21 September compliance deadline. A German software champion cleared domestic scrutiny while an American platform faces enforcement, in the same regulatory season.
United States (USTR)
United States (USTR)
Washington's Section 301 investigation into EU digital enforcement, opened 24 July, had produced no Federal Register docket as of 4 August, even as Dell and 1,008 Nvidia GB200 NVL4 accelerators sit inside the EU's own sovereignty-branded MeluXina-AI build. The absent docket and the American hardware inside a European sovereignty project pull the same relationship in opposite directions.
UK government
UK government
The UK's Sovereign AI vehicle took a nine-figure equity stake in chip startup OLIX on 30 July, its fifth deal since April, while the Cabinet Office's 27 July fact sheet named no accounting officer for the GBP 1.1bn AI Hardware Plan. Whitehall is buying equity rather than capacity, inside a department mid-rename to Business, Innovation, Science and Trade.
Luxembourg government
Luxembourg government
Luxembourg is covering half of the newly disclosed EUR 80m contract value for MeluXina-AI, EuroHPC's Grand Duchy build, with Dell Technologies confirmed as supplying 1,008 Nvidia GB200 NVL4 accelerators, a hardware detail absent from the earlier project description. The disclosure means Luxembourg's national co-funding buys a facility built on American silicon under a European ownership badge.
European Commission
European Commission
The Commission activated its Article 101 fining power on 2 August while the Article 70 register it must keep current still showed a 26 September 2025 footer and blank rows for Denmark, Finland and Hungary. It issued no comment, though Article 70 puts the publication duty on Brussels, not member states.
China's Ministry of Commerce
China's Ministry of Commerce
Spokesperson He Yadong said on 16 July that Beijing and the Netherlands should let firms settle the Nexperia dispute through consultation, after a Dutch ministerial visit to Beijing. The conciliatory tone contrasts with the confrontational US trade response to the same fortnight's DMA enforcement.