The rule: manufacturers must identify and document the components in their product, "including by drawing up a software bill of materials in a commonly used and machine-readable format covering at the very least the top-level dependencies of the products" (Annex I, Part II, point 1).
The floor is top-level dependencies: the packages your product directly depends on. Transitive dependencies are not required by the text, though a lockfile-derived full tree is both easy to produce and far more useful when a vulnerability lands three levels down. The SBOM must be machine-readable; a spreadsheet of names does not qualify.
The regulation defines the term itself: a software bill of materials is "a formal record containing details and supply chain relationships of components included in the software elements of a product with digital elements" (Art. 3(39)).
The CRA does not name CycloneDX or SPDX. Instead, Art. 13(24) lets the Commission specify "the format and elements" of the SBOM by implementing act, taking into account European or international standards. As of this writing that implementing act has not been adopted, and standardisation work at CEN/CENELEC is ongoing. Practical consequence: produce both of the two established formats today, and be ready to regenerate when the format is fixed. Anyone selling you a "CRA-certified SBOM format" is ahead of the law.
Two things people get wrong. First, the SBOM is part of your technical documentation (Annex VII, point 2), so it must exist and be maintained. Second, you do not have to publish it: Recital 77 states that manufacturers should not be obliged to make the SBOM public, and Annex VII, point 8 frames it as something produced to market surveillance authorities on request, where necessary to verify compliance. Keep it, be able to hand it over, but you choose whether customers get a copy.
Technical documentation, SBOM included, must stay at the disposal of authorities for at least ten years after the product is placed on the market or for the support period, whichever is longer (Art. 13(13)). A ten-year horizon is why a tamper-evident, signed SBOM is worth more than a plain JSON file: the question in 2035 will be "is this really what shipped in 2027?"
The documentation obligations, SBOM among them, apply from 11 December 2027 (Art. 71(2)). Products already on the market before that date are not retroactively subjected to the full requirements unless substantially modified, but the separate reporting duty of Article 14 has applied to all in-scope products since 11 September 2026.
Two free tools that apply this to your case: the 2-minute applicability check (does the CRA apply to you, with the clauses) and the SBOM generator (CycloneDX + SPDX from your manifest, signed). No signup for either.
Sources, primary only: Regulation (EU) 2024/2847 — EUR-Lex · European Commission — CRA summary · European Commission — CRA reporting · ENISA — Single Reporting Platform. Not legal advice; the regulation text controls.