Scope

Free software and the CRA: money is not the test

By Matic Jezeršek, MSc.

Published . Reviewed against Regulation (EU) 2024/2847, OJ L, 20.11.2024, and Commission guidance C(2026) 5252, 27 July 2026.

A reader of this site put it plainly: it seems to think placing on the market is limited to the exchange of money. For free and open-source software, the Regulation never asked that question, and on 27 July 2026 the Commission published guidance that removes any doubt. The test is supply in the course of a commercial activity. A price is one way to trigger it. It is not the only way, and it is not required.

The test is commercial activity, not a price tag

Two definitions carry the whole rule. “Making available on the market” is the supply of a product for distribution or use on the Union market in the course of a commercial activity, and the Regulation says explicitly that this counts whether the supply is paid or free. “Manufacturer” reaches anyone who develops or manufactures a product, or has it made, and markets it under its own name or trademark, and again the Regulation names payment, monetisation and free distribution side by side, not one at the expense of the others.

“the supply of a product with digital elements for distribution or use on the Union market in the course of a commercial activity, whether in return for payment or free of charge”

“a natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under its name or trademark, whether for payment, monetisation or free of charge”

A free tier, an ad-funded app, a donation-supported tool and a give-away installer all pass through the same word: supply. Whether that supply happens in the course of a commercial activity is a separate question, and it is the question that decides whether the supply counts as making available on the market.

Recital 15's list of what makes supply commercial

The Regulation does not leave “commercial activity” undefined for open source. Recital 15 lists five circumstances that can characterise a commercial activity, and guidance paragraph 41 recalls them: a price for the software itself, paid technical support that goes beyond recovering the actual costs of providing it, an intention to monetise through the software such as a platform that monetises other products or services, a condition that ties use to processing personal data for reasons beyond security, compatibility or interoperability, or donations that exceed cost recovery (guidance paragraph 41, quoting recital 15). The guidance narrows two of them. Paid support around software that stays freely available is not enough on its own: what decides it is whether access to the software itself is conditioned on payment (paragraphs 55 to 56). And donations, even where they exceed costs, count only when they gate access to the software, to its functions or to its updates; a donation link that gates nothing is not an intention to make a profit (paragraphs 61 to 62).

“open-source software supplied for distribution or use in the course of a commercial activity”

How the Commission guidance sorts eleven situations

The recital sets the categories; the guidance works through how they apply. It is non-binding, published as the Commission's own reading rather than as law, but it is the clearest statement yet of where the five triggers land in practice.

SituationPlaced on the market?Where the Commission says so
Charging a price for the software itself, such as pre-compiled binariesYesSection 3.2.1, paragraph 51
A free community edition sitting next to a paid edition of the same codebase, including an open-core arrangementThe free edition is not placed on the market. The paid edition is. A legal person publishing the free edition is also subject to the obligations on stewards.Section 3.2.1, paragraphs 52 to 53
A marketplace app that earns the publisher commission, advertising or subscription revenueYesSection 3.2.2, example 14
A VPN app that sells access to extra servers or dedicated IP addressesYesSection 3.2.2, example 15
A fitness app that conditions use on processing personal data for advertising or unrelated analyticsYesSection 3.2.2, example 16
A paid edition that adds technical assistance or performance optimisation over the free oneYesSection 3.2.3, paragraph 57, example 17
Optional consultancy or training sold separately from a tool that stays free to download, install and updateNoSection 3.2.3, paragraph 56, example 18
Donations that gate nothing: the software, its source and its updates stay open to everyoneNoSection 3.2.4, paragraph 61, example 20
Releases or security updates provided to donors onlyYesSection 3.2.4, paragraph 62, example 21
Sponsorship or grants that fund development of software that is openly shared and not otherwise monetisedNoSection 3.2.5, paragraphs 63 to 65, example 23
A not-for-profit publisher whose earnings after costs all go to not-for-profit objectivesNo, though steward duties can still applySection 3.2.6, paragraph 66, example 24

Read down the table and the pattern repeats: the guidance keeps asking whether access to the software itself, or to a version, function or update of it, is conditioned on payment, and it treats a fee dressed up as a donation the same way it treats a fee.

A steward, not a manufacturer, for the free edition

Where a legal person publishes the free edition that recital 18 and the guidance both agree is not placed on the market, that person does not walk away without duties. The Regulation gives it a lighter role of its own: open-source software steward. A steward systematically supports the development of a free and open-source product intended for commercial activities and ensures its viability, and its core obligation under Art. 24(1) is to document a cybersecurity policy.

“a legal person, other than a manufacturer, that has the purpose or objective of systematically providing support on a sustained basis for the development of specific products with digital elements, qualifying as free and open-source software and intended for commercial activities, and that ensures the viability of those products”

“Open-source software stewards shall put in place and document in a verifiable manner a cybersecurity policy to foster the development of a secure product with digital elements as well as an effective handling of vulnerabilities by the developers of that product.”

Not for profit does not mean not regulated. It means a different, lighter set of duties, and the guidance's not-for-profit example above states the same thing directly: the browser stays outside placing on the market, and the organisation publishing it still carries the steward obligations.

What changed on the checker

The Cybiq wizard now asks who supplies the product and in what setting, not whether money changes hands first. For a free and open-source answer, it runs through the same list the guidance uses: a price, support that in substance conditions access to the software on payment, monetisation through the software, a personal-data condition, or donations that gate access. Run the free check at cybiq.eu and the verdict names which of those applies, alongside the guidance section and paragraph or example behind it. The full text sits at Commission guidance C(2026) 5252, 27 July 2026, non-binding.

Orientation, not legal advice. Verify against the official text before relying on any item.