EU Cyber Resilience Act · updated 2026-09-23

SBOM requirements under the Cyber Resilience Act

The rule: manufacturers must identify and document the components in their product, "including by drawing up a software bill of materials in a commonly used and machine-readable format covering at the very least the top-level dependencies of the products" (Annex I, Part II, point 1).

Minimum content

The floor is top-level dependencies: the packages your product directly depends on. Transitive dependencies are not required by the text, though a lockfile-derived full tree is both easy to produce and far more useful when a vulnerability lands three levels down. The SBOM must be machine-readable; a spreadsheet of names does not qualify.

The regulation defines the term itself: a software bill of materials is "a formal record containing details and supply chain relationships of components included in the software elements of a product with digital elements" (Art. 3(39)).

The format question

The CRA does not name CycloneDX or SPDX. Instead, Art. 13(24) lets the Commission specify "the format and elements" of the SBOM by implementing act, taking into account European or international standards. As of this writing that implementing act has not been adopted, and standardisation work at CEN/CENELEC is ongoing. Practical consequence: produce both of the two established formats today, and be ready to regenerate when the format is fixed. Anyone selling you a "CRA-certified SBOM format" is ahead of the law.

Who sees it

Two things people get wrong. First, the SBOM is part of your technical documentation (Annex VII, point 2), so it must exist and be maintained. Second, you do not have to publish it: Recital 77 states that manufacturers should not be obliged to make the SBOM public, and Annex VII, point 8 frames it as something produced to market surveillance authorities on request, where necessary to verify compliance. Keep it, be able to hand it over, but you choose whether customers get a copy.

How long to keep it

Technical documentation, SBOM included, must stay at the disposal of authorities for at least ten years after the product is placed on the market or for the support period, whichever is longer (Art. 13(13)). A ten-year horizon is why a tamper-evident, signed SBOM is worth more than a plain JSON file: the question in 2035 will be "is this really what shipped in 2027?"

When it applies

The documentation obligations, SBOM among them, apply from 11 December 2027 (Art. 71(2)). Products already on the market before that date are not retroactively subjected to the full requirements unless substantially modified, but the separate reporting duty of Article 14 has applied to all in-scope products since 11 September 2026.

Sources, primary only: Regulation (EU) 2024/2847 — EUR-Lex · European Commission — CRA summary · European Commission — CRA reporting · ENISA — Single Reporting Platform. Not legal advice; the regulation text controls.

← All explainers