Ga naar inhoud

Regelgeving EU ·

CRA and SBOM: what software vendors must document in 2026

August 2026. The EU Cyber Resilience Act (CRA) affects software vendors and their customers in vital chains. Software Bill of Materials (SBOM) and vulnerability disclosure are becoming due diligence standard — alongside ISO 27001 and NIS2 questionnaires.

What does CRA ask in practice?

  • SBOM: components, versions, licences, known vulnerabilities;
  • security updates: patch timelines and customer communication;
  • coordinated disclosure: process for report and fix;
  • conformity documentation for critical products.

Link with ISO 27001

Secure development and vendor management (Annex A) partly cover CRA — but SBOM is more specific. Build SBOM generation in CI/CD; link to CRA and vendor management pages.

Enterprise procurement asks for SBOM in RFPs in 2026. Start with top products; expand per release. Document toolchain (Dependabot, Syft, CycloneDX).

Deep dive in the knowledge base

See ISO Ready as a practical ISMS

Compare software, consultants and hybrid approaches with a balanced view.

Compare with ISO Ready

← Back to overview