Regulation (EU) 2024/2847 · Chapter
Article 24 — Obligations of open-source software stewards
Open-source stewards: the light-touch regime for foundations and similar supporting bodies.
LAW Official text — verbatim from the Official Journal snapshot; only the Official Journal is authentic.
1.1. Open-source software stewards shall put in place and document in a verifiable manner a cybersecurity policy to foster the development of a secure product with digital elements as well as an effective handling of vulnerabilities by the developers of that product. That policy shall also foster the voluntary reporting of vulnerabilities as laid down in Article 15 by the developers of that product and take into account the specific nature of the open-source software steward and the legal and organisational arrangements to which it is subject. That policy shall, in particular, include aspects related to documenting, addressing and remediating vulnerabilities and promote the sharing of information concerning discovered vulnerabilities within the open-source community.
2.2. Open-source software stewards shall cooperate with the market surveillance authorities, at their request, with a view to mitigating the cybersecurity risks posed by a product with digital elements qualifying as free and open-source software.
Further to a reasoned request from a market surveillance authority, open-source software stewards shall provide that authority, in a language which can be easily understood by that authority, with the documentation referred to in paragraph 1, in paper or electronic form.
3.3. The obligations laid down in Article 14(1) shall apply to open-source software stewards to the extent that they are involved in the development of the products with digital elements. The obligations laid down in Article 14(3) and (8) shall apply to open-source software stewards to the extent that severe incidents having an impact on the security of products with digital elements affect network and information systems provided by the open-source software stewards for the development of such products.
sha256:27b7c6c64c773001… · CELEX 32024R2847What this article does
Article 24 gives open-source software stewards — foundations and similar bodies supporting open-source products intended for commercial use — a lighter regime than manufacturers, and non-monetised free and open-source software is not considered placed on the market in the first place F-009.
Reading it as a developer
The steward regime is about institutions, not hobbyists F-009. Monetising — charging a price, charging for support, or monetising through advertising or data — is commercial activity F-007, which points toward the manufacturer track rather than this one; the open-source topic page walks the boundary cases.
Verified facts this page relies on
- F-009 Free and open-source software not monetised is not considered placed on the market. Open-source software stewards (legal persons that systematically support free and open-source software intended for commercial activities) have a light regime: a documented cybersecurity policy, cooperation with authorities, and Article 14 reporting only where they are involved in development or where an incident affects their own development infrastructure; they do not affix CE marking and are not subject to fines. Art. 3(14), Art. 3(48), Art. 24, Art. 64(10)(b), Recitals 18–19
- F-007 The Regulation applies to products made available on the market in the course of a commercial activity; charging a price, charging for support, monetising via advertising or data, or otherwise intending to monetise are commercial activity. Art. 2(1), Art. 3(22), Recitals
Facts are maintained and human-verified in the CEMarque Facts Table (v2026.09.4, verified 2026-09-10).
Editorial review: Claude (AI reviewer, delegated by the editor), 2026-10-08. Methodology and correction process: how this site works.