What are the notification obligations of open-source software stewards?

Per Article 24(3), open-source software stewards are subject to a subset of the notification obligations of manufacturers defined in Article 14.

The table below provides an actionable summary of those notification and information obligations that accounts for stewards not necessarily being aware of who their users are nor being able to reach out to them individually.

Steward support level Notify vulnerabilities[1] Notify incidents[2] General announcement[3] Message known users[3:1]
Provides non-technical support only N/A N/A N/A N/A
+ provides IT infrastructure N/A ✅ ✅ N/A
+ provides engineering resources (incl. security) ✅ ✅ ✅ N/A
+ has 1:1 relationship with some users ✅ ✅ ✅ ✅

  1. Article 14(1) â†Šī¸Ž

  2. Article 14(3) â†Šī¸Ž

  3. Article 14(8) â†Šī¸Ž â†Šī¸Ž

Š 2025 ORC WG Authors â€ĸ CC BY 4.0 â€ĸ Source â€ĸ
Disclaimer

Disclaimer: The information contained in this FAQ is of a general nature only and is not intended to address the specific circumstances of any particular individual or entity. It is not necessarily comprehensive, complete, accurate, or up to date. It does not constitute professional or legal advice. If you need specific advice, you should consult a suitably qualified professional.