Start here

This site is a public reference on software bills of materials (SBOM) and Regulation (EU) 2024/2847, the Cyber Resilience Act. It addresses two teams whose obligations are distinct but inseparable: Legal / Compliance and Cybersecurity / DevSecOps.

The organising principle

Three failure modes threaten this kind of reference: duplicating the regulatory content across a Legal section and a Cyber section — they diverge within six months; following the order of the Regulation’s articles, which nobody reads; and mixing doctrine (what the law says) with internal practice (what you do).

The site therefore separates four layers:

Layer Role Sections
Regulatory reference Single source of truth on the Regulation. Neutral, sourced, dated. The CRA framework
Technical reference Single source of truth on the SBOM: formats, quality, VEX, licensing. SBOM
Role-based paths Translation into obligations, risks and actions for a given role. Redefines nothing. Legal, Cyber, Leadership
Operational Your organisation, tooling, templates and roadmap. Organisation, Tooling, Resources

Editorial rule. A regulatory concept is defined exactly once, in “The CRA framework”. The Legal and Cyber paths only offer role-oriented readings of it, with a link to the canonical page. A duplicated definition is a defect to be reported.

How to read a page

Every page carries the same markers, in the same place:

  • a primary audience badge — Legal, Cyber, Leadership or Cross-cutting;
  • a deadline where one of the Regulation’s three dates applies;
  • an “At a glance” box in the side column: legal basis (articles and annexes), the evidence artefact expected at audit, the owning function, and the last review date.

The review date is not decoration. Undated regulatory content is content you cannot know is still true; three topics are still moving (harmonised standards, delegated acts, designation of national authorities), and the updates section exists for that reason.

Choosing a path

  • Legal path — from qualifying the product to affixing the CE marking, in ten steps and about thirty minutes.
  • Cyber path — from generating an SBOM to the 24-hour reporting procedure, in ten steps.
  • Leadership view — exposure, cost, trade-offs.

If you do not yet know whether you are in scope, start with scope and then exclusions: together they answer the only question that matters at the outset, in ten minutes.

Four things to know before anything else

  1. The CRA is a Regulation: directly applicable, with no national transposition. There will be no national law that pushes the deadline back.
  2. The first deadline is not CE marking, it is reporting. Since 11 September 2026, an actively exploited vulnerability must be reported within 24 hours — including for products placed on the market before that date.
  3. The SBOM is part of the technical documentation. Without complete technical documentation there is no EU declaration of conformity; without a declaration there is no CE marking; without CE marking there is no sale in the Union.
  4. Generating an SBOM in the build chain and steering the portfolio from a central platform are two different jobs — see Generate and steer.

In this section

  • Legal

    Legal path in 10 steps

    A linear thirty-minute reading path, from qualifying the product to affixing the CE marking, for a lawyer new to the Cyber Resilience Act.

  • Cyber

    Cyber path in 10 steps

    A linear thirty-minute reading path, from generating an SBOM to the 24-hour reporting procedure, for an engineer new to the Cyber Resilience Act.