Skip to content
You can now search across every topic, entity and event.What's new
European Tech Sovereignty
10JUN

CRA draft pins open-source liability on publishers

3 min read
10:31UTC

The European Commission published draft Cyber Resilience Act open-source guidance on Tuesday 3 March 2026 with consultation closing on Tuesday 31 March, confirming that responsibility for free and open-source software falls on who publishes and controls, not on contributors with commit access.

TechnologyDeveloping
Key takeaway

Maintainer liability is settled at the publisher-control test; donation triggers remain unresolved with the September 2026 reporting clock running.

On Tuesday 3 March 2026, the European Commission published draft implementation guidance for the Cyber Resilience Act (CRA, the EU's binding cybersecurity law covering digital products and software with digital elements) governing how the law applies to free and open-source software 1. Consultation closed on Tuesday 31 March. The guidance establishes that responsibility under the CRA falls on the entity that publishes and controls the software, not on individual contributors who hold commit access.

The CRA reporting clock starts on Friday 11 September 2026 regardless of whether The Commission publishes final guidance before then. The draft closes the contributor-versus-publisher ambiguity Felix Reda, the German digital rights advocate and former MEP, had flagged repeatedly through 2024 and 2025. Hogan Lovells' published analysis of the draft confirms full compliance applies from Saturday 11 December 2027. OpenForum Europe and other open-source advocacy bodies welcomed the publisher-control test as resolving the most acute exposure for individual maintainers.

The grey area that remains is whether financial donations to a project trigger "placed on market" obligations under the CRA. The draft text suggests donations can trigger those obligations where access to essential functionality is conditional on payment. That conditional clause is the file's unresolved question for maintainers operating donation-funded projects with no separation between freely available and donor-tier functionality. The seven-CEO deregulation letter arrived in the same fortnight; the CRA open-source file was not in scope, but the legislative environment is the same. The Commission has not published the final guidance, and no publication date has been announced as of mid-May 2026.

Deep Analysis

In plain English

The Cyber Resilience Act (CRA) is an EU law that will require software sold in Europe to meet minimum security standards; much like toy safety labels or car crash tests, but for software. The CRA creates a problem for open-source software: code that anyone can download freely and modify, written by volunteers who are not paid. The guidance published in March clarifies two things. First, if you publish and control an open-source project, you are responsible for its security, not every individual who has ever contributed code. Second, if your project receives regular financial donations (through crowdfunding or sponsorship platforms), you may count as a commercial entity and lose some of the open-source exemptions. For software developers in Europe, this means they need to track who funds their projects and whether that funding crosses a compliance threshold.

Deep Analysis
Root Causes

The CRA's open-source liability ambiguity was an unintended product of the legislation's history: the original 2022 Commission proposal focused on IoT hardware and commercial software, and the open-source carve-out was added by the European Parliament during trilogue in 2023 without a detailed definition of who fell within the carve-out.

The carve-out's wording; 'freely available software, not in the course of a commercial activity'; was drafted by MEPs without input from open-source foundations, who only engaged fully after the text was finalised.

Felix Reda, the former MEP and open-source advocate, had flagged the contributor-vs-publisher ambiguity publicly from the first published draft, but his interventions during the passage of the legislation were unsuccessful in securing a clearer text. The March 2026 guidance is the belated administrative response to that unresolved legislative gap.

What could happen next?
  • Risk

    The donation-triggers-liability ambiguity may cause GitHub Sponsors and Open Collective to implement EU geo-restrictions on donation features before 11 September 2026, drying up funding for European open-source maintainers at the moment CRA compliance investment is highest.

    Immediate · 0.55
  • Precedent

    The publisher-not-contributor liability rule will become the reference point for all subsequent EU digital product-safety legislation applied to software, including potential extensions of the AI Act to open-weight AI models.

    Long term · 0.7
  • Consequence

    The 11 September 2026 CRA reporting deadline applies regardless of whether the Commission publishes final guidance, meaning open-source publishers must begin compliance preparations under the draft guidance framework with no guarantee that the final rules will match.

    Immediate · 0.85
First Reported In

Update #5 · Brussels' 27 May package, two days before G7

Sovereign Tech Agency· 17 May 2026
Read original
Causes and effects
This Event
CRA draft pins open-source liability on publishers
Resolves the contributor-versus-publisher ambiguity Felix Reda flagged, though the financial-donations grey area remains live before reporting obligations begin on 11 September 2026.
Different Perspectives
Trump administration
Trump administration
Washington defends the MATCH Act as closing a loophole that lets ASML's DUV tools reach Chinese fabs indirectly, dismissing the Dutch Cabinet's June complaint of being treated with disregard. Officials expect the bill's progress through Congress to keep the DUV cross-subsidy question live regardless of ASML's Q2 numbers.
Bruegel
Bruegel
Brussels-based economists argue this week's deliverables, specialist fab aid and a digital euro that restricts no US firm, prove Europe's sovereignty agenda advances only where it meets no American resistance. They expect the leading-edge fabrication gap and dependence on US frontier AI models to persist absent a policy that directly confronts a named US interest.
German federal government
German federal government
Berlin welcomes the €659m tranche funding jobs across North Rhine-Westphalia, Schleswig-Holstein, Hesse and Bavaria, on top of the ESMC Dresden fab already under construction on TSMC-shipped tooling. Officials treat power and analogue capacity as the achievable near-term win while Dresden remains Germany's only bet on leading-edge logic.
House of Commons Science, Innovation and Technology Committee
House of Commons Science, Innovation and Technology Committee
The committee's 7 July report found the UK has "no coherent strategic framework" for sovereign technology and warns it "risks being cut off at whim", citing the June order that barred foreign access to Anthropic's Fable 5 and Mythos 5 as the trigger case. It expects no domestic hyperscaler or foundry response before the gap widens further.
European Commission
European Commission
The Commission cleared €659m in German state aid on 14 July, taking cumulative Chips Act support to roughly €14.2bn, and let the digital-euro mandate reach trilogue after ECON's floor-vote shortcut was overturned. Brussels presents both as sovereignty delivered, without addressing that neither funds leading-edge logic fabrication.
ASML
ASML
ASML raised FY2026 guidance to €43-45bn on 15 July and, for the first time since Q1, dropped the export-control hedge from its release even with the MATCH Act live in Congress. Fouquet frames the order book, 86 systems against 67 in Q1, as strong enough to outrun the DUV dispute rather than evidence it has cooled.