Result · C

Non-commercial / open source — no manufacturer obligations.

What this means for you

If you are an organisation that systematically supports open-source software intended for commercial use ("open-source software steward", Article 24), a light regime applies: a vulnerability disclosure policy and cooperation on reporting, no CE marking. Note: if you monetise the software (paid edition, licences), you are a manufacturer — run the checker again with Q3 = a.

Key facts

  • The Cyber Resilience Act is Regulation (EU) 2024/2847; obligations phase in over time.
  • From 11 September 2026: report actively exploited vulnerabilities and severe incidents (24 h / 72 h / 14 days) via ENISA's Single Reporting Platform.
  • From 11 December 2027: no product with digital elements on the EU market without CE marking and the Annex I security requirements.
  • Penalties up to €15 million or 2.5 % of worldwide annual turnover.

Source: EUR-Lex (Regulation (EU) 2024/2847); European Commission guidance of 27 July 2026.

Disclaimer

Informational tool based on Regulation (EU) 2024/2847 and the European Commission's guidance as of 27 July 2026. Not legal advice and not a conformity assessment; borderline cases (especially SaaS, open source and custom development) should be reviewed with a professional.