- The EU Cyber Resilience Act mostly excludes open-source authors and programmers, with key provisions in the preamble rather than the act itself.
- Recitals in EU law are not legally binding but can clarify ambiguous provisions and limit scope, acting like #pragma directives rather than comments.
- Open source activities like accepting donations without profit intent or contributing code not under one's responsibility are not considered commercial under the CRA.
- The recitals instruct market surveillance authorities on guidelines and affect transposition and adaptation of the legislation.
- Some open-source foundations may need to do actual work, and the CRA may incentivize users to support open-source software via due diligence.