This week the European Commission published the draft for a guidance document for the Cyber Resilience Act (CRA). It is 70 pages, but contains some helpful examples and flowcharts, like this one, making it accessible even to Open Source folks with limited time.

Here: Quick guidance for the question if your FOSS component is in scope for the CRA, and if so, wether you're deemed a steward or manufacturer in regards of the component.

A flowchart illustrating if your FOSS component is in scope of the CRA, and if you're deemed to be a manufacturer or steward.
0

If you have a fediverse account, you can quote this note from your own instance. Search https://chaos.social/users/mechko/statuses/116181555928058184 on your instance and quote it. (Note that quoting is not supported in Mastodon.)