The situation
A team distributes a network utility under an open-source licence. One project is maintained outside commercial activity; another is supplied as a commercial product under the company’s name. Payment, support and governance facts need to be assessed together instead of treating a licence label as an exemption.
Facts that change the answer
- Is this supply part of commercial activity?
- Who takes responsibility for releasing the product?
- Is the organisation a manufacturer, a contributor or an open-source steward?
Compare the worked results
These examples use the published assessment with the assumptions shown below. Change the facts in your own assessment before relying on its result.
Documented non-commercial project
Hypothetical example 1
Key facts in this example
- The supply occurs in the course of a commercial activity
- no
- Free and open-source software position
- non commercial free and open source software
All recorded assumptions (8)
- Product, software or service being assessed
- Hypothetical example product
- How the assessed offering reaches the user
- locally installed software
- The intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network
- yes
- The offering is supplied for distribution or use on the Union market
- yes
- The supply occurs in the course of a commercial activity
- no
- Sector-specific or public-purpose position
- no exclusion identified
- Free and open-source software position
- non commercial free and open source software
- Assessed role in the supply chain
- manufacturer under own name or trademark
Commercial product under the supplier’s name
Hypothetical example 2
Key facts in this example
- The supply occurs in the course of a commercial activity
- yes
- Free and open-source software position
- free and open source software supplied commercially
All recorded assumptions (8)
- Product, software or service being assessed
- Hypothetical example product
- How the assessed offering reaches the user
- locally installed software
- The intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network
- yes
- The offering is supplied for distribution or use on the Union market
- yes
- The supply occurs in the course of a commercial activity
- yes
- Sector-specific or public-purpose position
- no exclusion identified
- Free and open-source software position
- free and open source software supplied commercially
- Assessed role in the supply chain
- manufacturer under own name or trademark
Evaluated on 2026-09-13 using EU Cyber Resilience Act scope and economic-operator determination, version 2026.09.02. A completed example is not a customer Record or a declaration of conformity.
Evidence to keep
- Distribution and commercial model
- Licence and release-governance record
- Documented assessment of the organisation’s role
Keep source artifacts in their controlled systems and record their references, responsible owner and review date with the decision.
Your next step
Preserve the commercial-activity reasoning with the scope result. Reassess when the distribution model or responsible organisation changes.
Choose your real product or vulnerability case in the workspace. The selected assessment will be highlighted; example answers are not copied into your record.
Sources and application dates
- Regulation (EU) 2024/2847 (Cyber Resilience Act)Articles 2, 3, 18 and 21–24; recitals 11–19
- European Commission CRA implementation guidance (2026)Sections 2, 3 and 8 — scope, free and open-source software, and remote data processing
Manufacturer reporting applies from 11 September 2026. Broader product requirements apply from 11 December 2027; these product-readiness examples support preparation. Open-source-steward obligations have their own application date.
These examples structure a decision and do not replace the Regulation, official guidance or product-specific professional advice. Not lawyer-reviewed.