August 2026. The EU Cyber Resilience Act (CRA) affects software vendors and their customers in vital chains. Software Bill of Materials (SBOM) and vulnerability disclosure are becoming due diligence standard, alongside ISO 27001 and NIS2 questionnaires.
What does CRA ask in practice?
- SBOM: components, versions, licences, known vulnerabilities;
- security updates: patch timelines and customer communication;
- coordinated disclosure: process for report and fix;
- conformity documentation for critical products.
Link with ISO 27001
Secure development and vendor management (Annex A) partly cover CRA, but SBOM is more specific. Build SBOM generation in CI/CD; link to CRA and vendor management pages.
Enterprise procurement asks for SBOM in RFPs in 2026. Start with top products; expand per release. Document toolchain (Dependabot, Syft, CycloneDX).
