August 2026. The EU Cyber Resilience Act (CRA) affects software vendors and their customers in vital chains. Software Bill of Materials (SBOM) and vulnerability disclosure are becoming due diligence standard — alongside ISO 27001 and NIS2 questionnaires.
What does CRA ask in practice?
- SBOM: components, versions, licences, known vulnerabilities;
- security updates: patch timelines and customer communication;
- coordinated disclosure: process for report and fix;
- conformity documentation for critical products.
Link with ISO 27001
Secure development and vendor management (Annex A) partly cover CRA — but SBOM is more specific. Build SBOM generation in CI/CD; link to CRA and vendor management pages.
Enterprise procurement asks for SBOM in RFPs in 2026. Start with top products; expand per release. Document toolchain (Dependabot, Syft, CycloneDX).
