CRA guidance · Published 2026-07-03
CRA SBOM requirements: useful inventory, not checkbox paperwork
An SBOM becomes useful evidence when it is release-specific and connected to vulnerability handling.
What this guide covers
- Use a commonly used machine-readable format covering at least top-level dependencies
- Bind inventory and provenance to the exact product release
- Treat scanner matches as triage signals requiring product-context assessment
This article provides general information about the EU Cyber Resilience Act. It is not legal advice.