InsideCRA
InsideCRA › Articles › Article 25

Regulation (EU) 2024/2847 · Chapter

Article 25 — Security attestation of free and open-source software

Security attestation of free and open-source software: a voluntary trust signal.

LAW Official text — verbatim from the Official Journal snapshot; only the Official Journal is authentic.

In order to facilitate the due diligence obligation set out in Article 13(5), in particular as regards manufacturers that integrate free and open-source software components in their products with digital elements, the Commission is empowered to adopt delegated acts in accordance with Article 61 to supplement this Regulation by establishing voluntary security attestation programmes allowing the developers or users of products with digital elements qualifying as free and open-source software as well as other third parties to assess the conformity of such products with all or certain essential cybersecurity requirements or other obligations laid down in this Regulation.

BINDING Source: Regulation (EU) 2024/2847 (Cyber Resilience Act) · publisher European Union · captured 2026-09-16 · snapshot sha256:27b7c6c64c773001… · CELEX 32024R2847

What this article does

Article 25 empowers the Commission to establish, by delegated acts, voluntary security attestation programmes allowing developers or users of free and open-source products, as well as other third parties, to assess the conformity of such products with all or certain essential cybersecurity requirements or other duties set by the Regulation.

Why this is clever

The open-source carve-outs mean much foundational software sits outside the mandatory regime — non-monetised FOSS is not considered placed on the market, and stewards carry a deliberately lighter role F-009. But manufacturers who integrate that software still answer for it inside their own products. Article 25 presents attestation as a way to support the due diligence manufacturers exercise under Article 13(5) when they integrate free and open-source components F-046, without changing the lighter treatment the Regulation gives non-monetised FOSS and stewards F-009.

Status

The programmes are to be established by Commission delegated acts under Article 61; until such acts are adopted, this article is a slot in the architecture rather than a programme you can enrol in.

Verified facts this page relies on

Facts are maintained and human-verified in the CEMarque Facts Table (v2026.09.4, verified 2026-09-10).

Editorial review: Claude (AI reviewer, delegated by the editor), 2026-10-08. Methodology and correction process: how this site works.

Related in the reference

Continue in the reference: Regulation map · topics · timeline.