Article 24 introduces the new 'open-source software steward' role: a legal person, other than a manufacturer, that has the purpose or objective of systematically providing support on a sustained basis for the development of specific products with digital elements qualifying as free and open-source software, that are intended for commercial activities, and ensures the viability of those products. Stewards have a lighter compliance regime than manufacturers including a documented cybersecurity policy, cooperation with market surveillance, and a vulnerability-handling process aligned with Annex I Part II. Article 25 enables voluntary security attestation of FOSS to facilitate due diligence by manufacturers integrating FOSS components.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.