The EU Cyber Resilience Act and WordPress: who it applies to and when
The Cyber Resilience Act puts its duties on those who supply software on the EU market in the course of a commercial activity, not on a site owner who only uses WordPress. Reporting duties for manufacturers began on 11 September 2026. The rest applies from 11 December 2027.
- By
- WP Ministry
- Published
In short
- A site owner who only uses WordPress, plugins and themes has no duties under the Act. A website is not itself a product under it.
- The duties fall mainly on the manufacturer, the person or company that markets software under its own name in the course of a commercial activity.
- Free and open-source software that its publisher does not monetize is not treated as a commercial activity. Where the line falls is judged case by case.
- Manufacturers have had to report actively exploited vulnerabilities and severe incidents since 11 September 2026.
- Security requirements, stated support periods, conformity assessment and the CE marking apply from 11 December 2027.
- Whatever a seller owes under the Act, installing the updates is still the site owner's job.
The Cyber Resilience Act, Regulation (EU) 2024/2847, is a European Union law that sets security requirements for "products with digital elements", software included, that are supplied on the EU market in the course of a commercial activity. Most of its duties fall on the manufacturer: the person or company that develops a product and markets it under its own name. Its reporting duties began on 11 September 2026, and the rest applies from 11 December 2027.
If you only run a WordPress site, the Act gives you nothing to comply with. It reaches you through the people who make and sell the software you install. This page explains what the regulation and the European Commission's own documents say. It is not legal advice, and it says where the text leaves room for interpretation.
The dates
Article 71 sets the dates. The last column is as of 7 October 2026.
| Date | What begins | Status |
|---|---|---|
| 10 December 2024 | The regulation entered into force. | Past |
| 11 June 2026 | Chapter IV applies: the rules on the bodies that will assess products. | Past |
| 11 September 2026 | Article 14 applies: manufacturers report actively exploited vulnerabilities and severe incidents. | Past |
| 11 December 2027 | Everything else applies: security requirements, support periods, conformity assessment, the CE marking and the duties of stewards. | Still to come |
Under Article 69, a product placed on the market before 11 December 2027 comes under the requirements only if it is substantially modified from that date on. Reporting is the exception: Article 14 covers every product in scope, including those already on the market.
What counts as a product
Article 2 applies the Act to products with digital elements that are made available on the market and can connect to a device or a network. Article 3 defines making available as supply "for distribution or use on the Union market in the course of a commercial activity, whether in return for payment or free of charge".
The Commission's guidance draws a line that matters for WordPress. Software that is installed and runs on the user's own system is a product, in scope when it is supplied in the course of a commercial activity. Software that runs remotely and is only accessed by the user is not a product on that basis alone. Recital 12 puts a website that does not support the functionality of a product outside the Act.
That guidance is not law. The Commission approved its content on 27 July 2026 and says formal adoption follows once it exists in every EU language. It is not binding, and only the Court of Justice of the European Union can interpret the Act with authority. Neither it nor the Commission's FAQ mentions WordPress. How they read onto one plugin or theme is a question for its maker's counsel.
Who has duties, by role
Article 3 defines four roles. A manufacturer develops a product, or has it developed, and markets it under its own name or trademark, whether or not it charges for it. An importer is established in the EU and places on the market a product that bears the name of someone outside it. A distributor makes a product available without changing it. An open-source software steward is a legal person, other than a manufacturer, that gives sustained support to free and open-source software intended for commercial activities.
You sell a plugin, a theme or a paid add-on
Charging a price for software is the plainest form of commercial activity. Recital 15 lists others: charging for technical support beyond the recovery of actual costs, monetizing other services through the software, requiring users' personal data for purposes other than the software's security, compatibility or interoperability, and accepting donations that exceed costs.
The guidance speaks to a free version published beside a paid one, and treats them as different products. The paid version is placed on the market and its publisher is its manufacturer. The free version is not, even where the paid one extends its code. If the publisher is a legal person, the guidance says it also has a steward's obligations for the free version. If the publisher is an individual, the free version is outside the Act.
The guidance adds that software counts as free and open source under the Act only if its source code is publicly available. Code shared only with paying customers does not qualify, whatever its license.
You publish a free plugin and earn nothing from it
Recital 18 says that providing free and open-source software that its manufacturer does not monetize "should not be considered to be a commercial activity". Regular releases do not change that on their own. Nor does the Act apply to people who contribute code to a project they are not responsible for.
- Donations. Recital 15 says accepting donations without the intention of making a profit is not a commercial activity. The guidance says a donation link alone does not show that intention. It becomes a price where access to the software or its updates depends on donating.
- Paid help. The guidance says optional paid services around freely available software, such as consultancy or training, do not place that software on the market. A paid edition that bundles support does.
The line is not sharp: the guidance says whether an activity is commercial can only be judged case by case. If your free plugin feeds a paid service, take that question to counsel.
You run an agency that builds sites from others' software
The guidance gives this example: a service provider that helps a customer install free and open-source software on the customer's server, without substantially modifying it, is not placing it on the market.
Three situations change the picture:
- Substantial modification. Under Article 22, anyone who substantially modifies a product and makes it available on the market is its manufacturer for the part they changed. Article 3 defines that as a change that affects the product's compliance or alters its intended purpose.
- Your name on someone else's product. Under Article 21, an importer or distributor that places a product on the market under its own name or trademark is treated as its manufacturer.
- Custom plugins for clients. The Commission's documents reach this only in part. In one example in the guidance, a company that licenses source code to another company, for a platform that company will adapt, is placing it on the market. The FAQ calls custom-developed software for one business user a possible "tailor-made" product, for which Annex I lets maker and client agree to vary two requirements. Whether code written for one client's site is a product you supply or part of a service is a question for counsel.
You are a host
Hosting is a service. Recital 12 says cloud services designed outside the responsibility of a product's manufacturer are outside the Act, and points to a different law, Directive (EU) 2022/2555, for cloud computing. A host that also supplies software to install has a maker's questions to answer for it.
You own a site and only use WordPress
The Act puts duties on those who supply products and on stewards. Using software is neither. The FAQ adds that a product made only for one's own use is not placed on the market.
What a manufacturer has to do
From Articles 13 and 14 and Annex I, in plain words:
- Build security in. Assess the product's risks, design it to match, and ship it with a secure default configuration.
- Release with no known exploitable vulnerabilities.
- Give people a way to report vulnerabilities. A single point of contact and a policy on coordinated vulnerability disclosure.
- Provide security updates for a stated support period. The period is at least five years, unless the product is expected to be in use for less. Security updates go out without delay and free of charge.
- Report. An actively exploited vulnerability or a severe incident is notified through the Single Reporting Platform that ENISA runs: an early warning within 24 hours, a fuller notification within 72 hours, and a final report later. Affected users are told as well. This duty already applies.
- Document. Technical documentation, a software bill of materials, an EU declaration of conformity and the CE marking. Unless a product falls in one of the Act's "important" or "critical" categories, the manufacturer may assess conformity itself.
A steward's duties under Article 24 are lighter: a documented cybersecurity policy, cooperation with authorities, and some reporting. The Commission's FAQ confirms that they apply from 11 December 2027, reporting included.
Article 64 sets the upper limits of fines. For breaches of the essential requirements or of Articles 13 and 14 it is EUR 15 million or, for a company, 2.5% of worldwide annual turnover, whichever is higher. It exempts micro and small enterprises from fines for missing the 24-hour deadline, and stewards from fines altogether. Member States set the actual rules.
What changes for a site owner
A commercial product in scope that is placed on the market from 11 December 2027 has to come with:
- The end date of its support period, shown at the time of purchase.
- A contact for reporting vulnerabilities.
- Information about vulnerabilities that have been fixed, once the update is out.
The Commission's FAQ covers one model: free and open-source software monetized only through support sold by subscription. There, the support period equals the duration of the active subscription. How that reads onto a license that ends updates when it lapses is for the seller to state.
None of this updates your site. So, whatever the Act requires of sellers:
- Keep WordPress, plugins and themes updated. How to safely update WordPress has the routine. If you would rather not do that upkeep yourself, our update service applies updates weekly on a care plan, looks at the site after each run, and undoes an update that went wrong.
- Choose plugins that someone maintains. A free plugin with no commercial activity behind it carries none of the manufacturer's duties, so its listing is still how you judge it. How to choose a WordPress plugin shows what to read.
What WordPress and open-source bodies have said
- WordPress, with Drupal, Joomla! and TYPO3. In 2023, while the Act was still a proposal, the four projects sent an open letter to the Commission. WordPress.org wrote that August that it endorsed the Act's objectives and was concerned about unclear terms, the definition of commercial activity among them. In September 2026 it reported that WordPress now leads the Open Website Alliance, whose members are the same four projects.
- The Open Source Initiative. It wrote in February 2024 that the final text had dealt with nearly all the risks it had identified for individual developers and open-source foundations.
- The Open Regulatory Compliance Working Group. Hosted by the Eclipse Foundation, it publishes a community FAQ on the Act at
cra.orcwg.org.
If you make a plugin or theme, start with the Commission's guidance and FAQ, then that working group's material.
What not to rely on
- "Every plugin author must comply" and "free plugins are exempt." Both are too simple. The test is commercial activity.
- A product that promises to make your site compliant. A site owner who only uses software has nothing under the Act to comply with.
Common questions
Does the Cyber Resilience Act apply to my WordPress website?
Not if you only use the software. The Act regulates products supplied on the EU market, and recital 12 puts a website that does not support a product's functionality outside it.
Does it apply to plugin makers outside the EU?
A maker's address does not take a product out of scope. The Act applies to products made available on the EU market, and Article 14 sets out where a manufacturer with no establishment in the Union sends its reports.
Is a free plugin with a paid version covered?
The Commission's guidance treats the two as different products: the paid one is placed on the market, the free one is not. The guidance is not binding, so confirm your own position with counsel.
- Cost guideWhat WordPress malware removal costs: how it is priced and what a cleanup should include
- ResourceHacked WordPress site: a runbook for the first hour
- GuideHow to set up two-factor authentication in WordPress
- GuideWordPress search results pages (/?s=) in Google and Search Console: what they are and what to do
- GuideHow to audit a WordPress site for security weaknesses
- GuideHow to remove malware from a hacked WordPress site

