Compliance

In the world of compliance, a job well done is often a thankless one. After all, when compliance operations are running effectively, it goes unnoticed. However, when things don't run well, compliance gets a lot of unwanted attention. This is especially true for today's software supply chain in the open source world.

Contrary to popular belief, free and open source software is not free, and using open source software requires that organisations understand the respective legal framework. Just like individually negotiated proprietary software licenses, free and open source software licenses are linked to certain licensing conditions. For example, most free and open software licenses have notice requirements. Some free and open source licenses come with the concept of copyleft that defines the way open source components can interact with proprietary software. Failure to comply with license obligations can result in lawsuits, product recall, and more. To reduce risk and transaction costs in the software supply chain, companies must implement a license and compliance strategy.

In recent years, however, the regulatory landscape has changed rapidly, and compliance in the open source world now reaches well beyond license compliance. Alongside the licensing obligations described above, organisations increasingly face regulatory compliance duties arising under instruments such as the Cyber Resilience Act (CRA), the Cybersecurity Act (CSA), the NIS2 Directive, and the Product Liability Directive. These bring obligations around vulnerability handling and disclosure, security-by-design, conformity attestation, the provision of Software Bills of Materials (SBOMs), and incident reporting. Compliance has thus become a multi-layered exercise that combines traditional intellectual property obligations with cybersecurity, product safety, and broader regulatory duties.

Managing the use of free and open source software in commercial products diverts legal and technical resources. However, performing compliance should not be seen as a cost center but as a competitive advantage. Any company wanting to compete in the fast-paced world of software development must fulfill their obligations and demonstrate they are equipped to operate in accordance with the law.

REFERENCES

License Compliance

A general overview of open source compliance in the business context can be found at the personal website of Ibrahim Haddad: available at http://www.ibrahimatlinux.com/publications.html.

An overview of Free and Open Source legal matters across various jurisdictions can be found at the International Free and Open Source Law Book.

The Free Software Foundation and the Software Freedom Conservancy have published a set of principles on community-oriented GPL enforcement.

The Free Software Foundation Europe provides a dedicated interest group for legal and licensing topics.

A homepage, no longer maintained, but still serving a collection of license compliance related articles is Groklaw.

The Open Source Automation Development Lab develops comprehensive information about the interpretation of license texts, the license checklist.

 

Regulatory Compliance

The full text of the Cyber Resilience Act (Regulation (EU) 2024/2847) is published on EUR-Lex. It entered into force on 10 December 2024, with manufacturers' reporting obligations applying from 11 September 2026 and full application from 11 December 2027. EUR-Lex

The European Commission's Shaping Europe's Digital Future portal provides an official overview of the CRA, including its dedicated approach to free and open source software and the new "open source steward" role.

The Cybersecurity Act (Regulation (EU) 2019/881), establishing ENISA and the EU cybersecurity certification framework, is available on EUR-Lex.

The NIS2 Directive (Directive (EU) 2022/2555), setting cybersecurity and incident-reporting obligations for essential and important entities, is available on EUR-Lex.

The Eclipse Foundation's Open Regulatory Compliance Working Group (ORC WG) helps developers, maintainers, and manufacturers navigate the CRA and related regulations. Its work includes CRA FAQs, a resource inventory, a vulnerability-management specification, and a due-diligence and security-attestation framework, hosted on GitHub.

ENISA, the EU Agency for Cybersecurity, publishes guidance and good-practice material on vulnerability handling, coordinated disclosure, and the certification schemes underpinning the CSA and CRA.