COMPLIANCE OBLIGATIONS
Companies integrate our open source software in commercial services or products they sell on the EU market. NLnet Labs is an Open-Source Software Steward under the Cyber Resilience Act for a subset of our open source projects. We can assist companies with their CRA compliance obligations through our professional support services.
Commercial use of our software
Companies integrate our open source software as components in commercial services or products they sell on the EU market.
Vulnerability reporting obligations
The CRA puts a vulnerability reporting obligation on Manufacturers that integrate our software to notify and share patches (Article 13(6)).
- If you identify a vulnerability, please report it to us.
- If you have a fix, please share your patch and any related documentation under the project's open source license.
See report a security issue for details.
Due diligence obligations
The CRA puts a due diligence obligation on Manufacturers that integrate our software. Due diligence is risk-based and more involved for load-bearing and security critical components. Our software is frequently employed in such a role, making due diligence more involved than automated checks.
We can assist companies with their CRA compliance obligations through our professional support services. These relationships in turn allow us to recuperate our costs of long-term maintenance.
NLnet Labs is an Open-Source Software Steward
The Cyber Resilience Act (Regulation (EU) 2024/2847) regulates software on the EU market. Manufacturers under the CRA, those that make software available on the EU market in the course of a commercial activity, are required to CE mark software.
Not-for-profit organisations that develop and publish open source software, such as ourselves, are under a different CRA regime. NLnet Labs is a so-called Open-Source Software Steward under the CRA to the open source projects it publishes that:
- qualify as a "product",
- are "(ultimately) intended for commercial activities",
- where we "systematically provide support on a sustained basis for the development”
- and we “ensure the viability of those products”.
The following open source software projects are in this category:
- Unbound
- NSD
- Cascade
- OpenDNSSEC (until EOL, October 2027)
- Routinator
- Krill
- Rotonda
Also included in this category, but not exhausively listed here, are dependencies of the listed projects that we maintain ourselves. An example is the domain Rust crate, which is used in Cascade.
Our other open-source software projects do not meet one or more of the listed criteria and thereby fall out of scope of the CRA. These include open-source projects that are not or no longer supported (EOL), developed for purposes other than commercial activities (research) etc.
Our obligations under the CRA
From December 11, 2027, we are required to report to the public authorities:
- actively exploited vulnerabilities in our stewarded projects that we become aware of, and
- severe incidents having an impact on the security of our stewarded projects that we become aware of (such as a compromise of our infrastructure).
We handle security and vulnerability remediation in line with our security and software support policies. We will cooperate with market surveillance authorities at their request in either English (preferred) or Dutch.