CRA guidance · Published 2026-07-03

CRA SBOM requirements: useful inventory, not checkbox paperwork

An SBOM becomes useful evidence when it is release-specific and connected to vulnerability handling.

What this guide covers

  • Use a commonly used machine-readable format covering at least top-level dependencies
  • Bind inventory and provenance to the exact product release
  • Treat scanner matches as triage signals requiring product-context assessment

This article provides general information about the EU Cyber Resilience Act. It is not legal advice.

Take the CRA readiness assessment · Read all CRA guides