The open-source software steward

This is the CRA’s genuine innovation on open source: the creation of an intermediate status between the volunteer contributor, out of scope, and the manufacturer, fully responsible.

The definition

An open-source software steward is a legal person, other than a manufacturer, which has the purpose or objective of systematically providing support on a sustained basis for the development of specific products with digital elements, qualifying as free and open-source software and intended for commercial activities, and which ensures the viability of those products.

Four cumulative elements, each of them discriminating:

Element What it rules out
Legal person, other than a manufacturer Natural persons; whoever places the product on the market is a manufacturer, not a steward
Systematic and sustained support One-off funding, occasional patronage, episodic contribution
Products intended for commercial activities Purely academic or hobby projects
Ensures viability Mere hosting or matchmaking

The entities targeted are chiefly software foundations — Apache, Eclipse, the Linux Foundation and their equivalents — and certain structures providing sustained funding for code.

The obligations actually owed

The list is exhaustive. A steward must:

  1. put in place and document, in a verifiable manner, a cybersecurity policy to foster the development of a secure product and effective handling of vulnerabilities, appropriate to the nature of the entity and its resources;
  2. cooperate with market surveillance authorities, at their request, to mitigate the cybersecurity risks of the products concerned;
  3. comply with the reporting obligations relating to actively exploited vulnerabilities and severe incidents affecting the security of the product, to the extent it is involved in the development of that product;
  4. provide, on request from the authorities, the necessary information in a language easily understood.

The phrase “appropriate to the nature of the entity and its resources” is essential: a foundation with three employees is not held to the same arrangement as one with two hundred people.

What a steward is NOT subject to

Manufacturer obligation Steward
CE marking No
EU declaration of conformity No
Annex VII technical documentation No
Conformity assessment procedure No
Annex I essential requirements as such No — replaced by the cybersecurity policy
Five-year support period No
Annex II information to the user No
Administrative fines No — the financial penalty regime does not apply to stewards

The exclusion of administrative fines is the most commented point. It does not mean no consequences: market surveillance authorities keep their powers of injunction and cooperation, and a foundation’s reputation is its principal asset.

Your self-qualification grid

Answer yes or no for each structure you run or fund:

  • Is the structure a separate legal person?
  • Is it other than a manufacturer of the product concerned — that is, does it not place the product on the market itself?
  • Does its purpose or objective include supporting the development of identified free software?
  • Is that support systematic and sustained, rather than one-off?
  • Is the software concerned intended for commercial activities, that is, used in products placed on the market by third parties?
  • Does the structure ensure the viability of that software — governance, funding, continuity over time?

Six yeses: the steward status is probably established, and the four obligations above apply. A single no: it is not, but the qualification must be revisited if circumstances change.

What this changes for you as an integrator

A component maintained by an identified steward offers more assurance than one maintained by an isolated individual: there is a documented cybersecurity policy, a reporting channel and a duty to cooperate. That is a selection criterion to build into your diligence grid — see Integrating open source.