The situation
A developer submits a patch upstream. Later, their company packages the project and supplies a branded application to customers. The first activity does not by itself establish responsibility for the finished product; the second calls for a fresh scope-and-role assessment.
Facts that change the answer
- Is the activity limited to contribution without product responsibility?
- Who publishes and supplies the finished release?
- Does the company put its name or trademark on the product?
Compare the worked results
These examples use the published assessment with the assumptions shown below. Change the facts in your own assessment before relying on its result.
Contribution without product responsibility
Hypothetical example 1
Key facts in this example
- The supply occurs in the course of a commercial activity
- no
- Free and open-source software position
- non commercial free and open source software
- Assessed role in the supply chain
- contributor without product responsibility
All recorded assumptions (8)
- Product, software or service being assessed
- Hypothetical example product
- How the assessed offering reaches the user
- locally installed software
- The intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network
- yes
- The offering is supplied for distribution or use on the Union market
- yes
- The supply occurs in the course of a commercial activity
- no
- Sector-specific or public-purpose position
- no exclusion identified
- Free and open-source software position
- non commercial free and open source software
- Assessed role in the supply chain
- contributor without product responsibility
Commercial product under the supplier’s name
Hypothetical example 2
Key facts in this example
- The supply occurs in the course of a commercial activity
- yes
- Free and open-source software position
- free and open source software supplied commercially
- Assessed role in the supply chain
- manufacturer under own name or trademark
All recorded assumptions (8)
- Product, software or service being assessed
- Hypothetical example product
- How the assessed offering reaches the user
- locally installed software
- The intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network
- yes
- The offering is supplied for distribution or use on the Union market
- yes
- The supply occurs in the course of a commercial activity
- yes
- Sector-specific or public-purpose position
- no exclusion identified
- Free and open-source software position
- free and open source software supplied commercially
- Assessed role in the supply chain
- manufacturer under own name or trademark
Evaluated on 2026-09-13 using EU Cyber Resilience Act scope and economic-operator determination, version 2026.09.02. A completed example is not a customer Record or a declaration of conformity.
Evidence to keep
- Contribution and release responsibilities
- Branding and distribution agreements
- Commercial supply and product-ownership statement
Keep source artifacts in their controlled systems and record their references, responsible owner and review date with the decision.
Your next step
Assess the activity rather than the person’s job title. Keep contribution evidence distinct from the commercial product’s manufacturer record.
Choose your real product or vulnerability case in the workspace. The selected assessment will be highlighted; example answers are not copied into your record.
Sources and application dates
- Regulation (EU) 2024/2847 (Cyber Resilience Act)Articles 2, 3, 18 and 21–24; recitals 11–19
- European Commission CRA implementation guidance (2026)Sections 2, 3 and 8 — scope, free and open-source software, and remote data processing
Manufacturer reporting applies from 11 September 2026. Broader product requirements apply from 11 December 2027; these product-readiness examples support preparation. Open-source-steward obligations have their own application date.
These examples structure a decision and do not replace the Regulation, official guidance or product-specific professional advice. Not lawyer-reviewed.