The commercial-activity line Art. 3(22), Recital 17, Recital 18
The CRA reaches economic operators only for products made available on the market, meaning supplied for distribution or use in the course of a commercial activity. For open-source software the recitals are explicit: only free and open-source software supplied in the course of a commercial activity falls within scope, and software not monetised by its manufacturer is not a commercial activity.
The recitals go further to reassure maintainers. The circumstances under which the software was developed, how development was financed, financial support or contributions from manufacturers, and the mere presence of regular releases do not, by themselves, make the activity commercial. Persons who merely contribute source code to a project not under their responsibility are outside scope.
What monetisation looks like Recital 15, Recital 18
The recitals describe commercial supply broadly: charging a price, charging for technical support beyond recovering actual costs, an intention to monetise (for instance a platform through which the maker monetises other services), requiring personal-data processing as a condition of use for reasons beyond security or interoperability, or accepting donations that exceed the costs of development and provision.
For components, there is a specific rule: supplying an open-source component intended for integration by other manufacturers counts as making available on the market only if the original manufacturer monetises the component. So an unmonetised component you publish for others to build on is treated differently from one you charge for.
Judgment call: Whether a specific model (paid support only, a maker-hosted version, generous donations) crosses into commercial activity is the sharpest judgment call in the CRA and turns on the facts.
Open-source software stewards, a lighter regime Art. 3(14), Art. 24, Recital 19
A distinct category sits between "out of scope" and "manufacturer": the open-source software steward. That is a legal person, other than a manufacturer, that systematically supports on a sustained basis the development of specific open-source products intended for commercial activities, and ensures their viability, without monetising them. Certain foundations fit here.
Stewards are not manufacturers: no CE marking, no conformity assessment. They put in place and document a cybersecurity policy, cooperate with market surveillance authorities on request, and carry a trimmed reporting duty to the extent they are involved in development.
Judgment call: When the trimmed steward reporting duty starts is unsettled: Art. 71(2) accelerates Art. 14 to 11 September 2026 but does not name Art. 24, whose general date is 11 December 2027. Prudent practice is to be ready for the earlier date.
If in scope, the public-documentation relief Art. 32(5), Art. 71(2)
Where open-source software is in scope and falls under a listed important category, its manufacturer can still use the ordinary conformity procedures of Article 32(1), including internal control, despite the Annex III listing, provided the technical documentation is made available to the public at the time the product is placed on the market. That eases the route the Class listing would otherwise impose. The reporting date of 11 September 2026 and the full-obligations date of 11 December 2027 apply to in-scope open-source products.