acquis · Law · Cyber Resilience Act
Cyber Resilience Act · CELEX 02024R2847-20241120
Article 24
Verbatim text of the current consolidated version (consolidated 2024-11-20) · status: in force. Check it on EUR-Lex ↗
Cyber Resilience Act, Article 24(1) — Obligations of open-source software stewards
Open-source software stewards shall put in place and document in a verifiable manner a cybersecurity policy to foster the development of a secure product with digital elements as well as an effective handling of vulnerabilities by the developers of that product. That policy shall also foster the voluntary reporting of vulnerabilities as laid down in Article 15 by the developers of that product and take into account the specific nature of the open-source software steward and the legal and organisational arrangements to which it is subject. That policy shall, in particular, include aspects related to documenting, addressing and remediating vulnerabilities and promote the sharing of information concerning discovered vulnerabilities within the open-source community.
Cyber Resilience Act, Article 24(2) — Obligations of open-source software stewards
Open-source software stewards shall cooperate with the market surveillance authorities, at their request, with a view to mitigating the cybersecurity risks posed by a product with digital elements qualifying as free and open-source software. Further to a reasoned request from a market surveillance authority, open-source software stewards shall provide that authority, in a language which can be easily understood by that authority, with the documentation referred to in paragraph 1, in paper or electronic form.
Cyber Resilience Act, Article 24(3) — Obligations of open-source software stewards
The obligations laid down in Article 14(1) shall apply to open-source software stewards to the extent that they are involved in the development of the products with digital elements. The obligations laid down in Article 14(3) and (8) shall apply to open-source software stewards to the extent that severe incidents having an impact on the security of products with digital elements affect network and information systems provided by the open-source software stewards for the development of such products.
This text is not written by an AI. It is rendered from a corpus built from the official EUR-Lex source, where every fragment is content-hashed and signed at ingestion — which is what lets you cite it and defend the citation. Ask a question about this article →
Other articles of the Cyber Resilience Act
Art. 1Art. 2Art. 3Art. 4Art. 5Art. 6Art. 7Art. 8Art. 9Art. 10Art. 11Art. 12Art. 13Art. 14Art. 15Art. 16Art. 17Art. 18Art. 19Art. 20Art. 21Art. 22Art. 23Art. 24Art. 25Art. 26Art. 27Art. 28Art. 29Art. 30Art. 31Art. 32Art. 33Art. 34Art. 35Art. 36Art. 37Art. 38Art. 39Art. 40Art. 41Art. 42Art. 43Art. 44Art. 45Art. 46Art. 47Art. 48Art. 49Art. 50Art. 51Art. 52Art. 53Art. 54Art. 55Art. 56Art. 57Art. 58Art. 59Art. 60Art. 61Art. 62Art. 63Art. 64Art. 65Art. 66Art. 67Art. 68Art. 69Art. 70Art. 71
Acquis returns official sources verbatim with citations; it is not legal advice. Texts © European Union, reuse permitted (Decision 2011/833/EU) — only the EUR-Lex original is authentic. Why legal AI fails · Coverage