EU's 84-page CRA guidance never mentions SBOM — field report
An analysis of the European Commission's 84-page C(2026) 5252 guidance for the Cyber Resilience Act found zero mentions of SBOM, CycloneDX or SPDX, even though Regulation (EU) 2024/2847 requires a machine-readable software bill of materials. Vulnerability reporting duties have applied since 11 September 2026, with main requirements due 11 December 2027.
- The EU's 84-page CRA guidance contains zero mentions of SBOM, CycloneDX or SPDX
- Regulation (EU) 2024/2847 requires a machine-readable SBOM but leaves the format unspecified
- Vulnerability reporting obligations have been in force since 11 September 2026
- Main CRA requirements apply from 11 December 2027
Read next
Policy