A separately supplied software library can be a product with digital elements. Commercial supply, FOSS distribution and stewardship must be assessed separately from the obligations of a manufacturer integrating the library.
Apply this to your product

Answer the questions and see the reasoning.

Open scope & role

Separate component supply from integration

The CRA expressly includes software components placed separately on the market. Source code can be software; providing binaries is not a prerequisite for analysis. But source publication alone does not establish a commercial market supply.

The manufacturer of a commercial application integrating a library has its own component due-diligence obligations. Those obligations do not automatically turn an upstream community contributor into the manufacturer of the downstream application.

Articles 3(1), 3(4) and 13(5); guidance sections 2.3 and 3CRA text Commission guidance

Typical distribution arrangements

A paid SDK supplied under the publisher’s brand can be a commercially supplied component. An individual publishing a freely available FOSS library and receiving donations can be outside the ordinary CRA product obligations.

A legal entity systematically sustaining a specific FOSS library intended for commercial activities may qualify as a steward. An optional consulting service does not, by itself, make freely available FOSS a commercial supply; a paid edition or access arrangement needs separate analysis.

Article 2(3); Articles 3(14) and 24; guidance section 3CRA text Commission guidance

What the integrator should document

Record the component and version, its intended use, known vulnerabilities and the steps used to assess and address integration risk. The whole product remains the manufacturer’s responsibility even where a component has a different upstream legal status.

Do not assume every library is Default. If the separately supplied product’s core functionality matches a listed category, investigate that technical description. Conversely, an important component does not automatically transfer its classification to an unrelated application.

Article 13(5); Annex I, Part II; Regulation 2025/2392, recital 3CRA text Implementing Regulation (EU) 2025/2392

Dates and next actions

Article 14 reporting for manufacturers applies from 11 September 2026, including to older in-scope products. Most requirements apply from 11 December 2027, subject to the rules for products already placed on the market and subsequent substantial modifications.

If you are the manufacturer of an in-scope product, establish the product risk assessment, support-period decision, vulnerability handling and technical documentation. Select the applicable conformity route before making a compliance claim. A reseller should use the importer and distributor assessment for its distinct duties.

Articles 13, 14, 19–20, 32, 69 and 71CRA text ↗

Frequently asked questions

Does a permissive licence guarantee exemption?

No. Evaluate the particular supply, monetisation and role. The licence is relevant to FOSS status but is not the whole scope test.

Does downloading a FOSS dependency remove my duties?

No. Manufacturers integrating third-party components must exercise due diligence and ensure the security of their own product.

This guide supports an initial assessment. Your result depends on the product facts and the applicable measures. Read how to use this guidance.