The regulation looks reasonable: if someone is selling software, or products containing software components, they have to certify the security of their products.
OSS developers who don’t charge for the software have no obligations. If their software is used in a commercial product, the seller of that product is responsible.