The EU Cyber Resilience Act makes cybersecurity mandatory for all network-connected products with digital elements. Open-source hardware projects are caught in a regulatory gap: they mix design files, firmware, documentation, and physical devices, but the CRA’s open-source exemptions only cover software. This talk works through six common OSH scenarios, from uploading CAD files to selling kits and finished devices, and shows where each triggers manufacturer duties under the CRA. It also covers the new Product Liability Directive, particularly the question of when design files become products and how liability shifts between non-commercial developers, community organisations, and commercial integrators. The goal is concrete guidance for OSH developers and makerspaces dealing with EU product law for the first time.
