chiprook
← Policy
PolicyOctober 2, 2026, 08:05

EU's 84-page CRA guidance never mentions SBOM — field report

An analysis of the European Commission's 84-page C(2026) 5252 guidance for the Cyber Resilience Act found zero mentions of SBOM, CycloneDX or SPDX, even though Regulation (EU) 2024/2847 requires a machine-readable software bill of materials. Vulnerability reporting duties have applied since 11 September 2026, with main requirements due 11 December 2027.

EU's 84-page CRA guidance never mentions SBOM — field report
#EU#ENISA
Read next
Policy

SEC Narrows Crypto Buyback Guidance to Protocols With No Central Party

Policy

US Weighs Antitrust Guidance on AI Safety, Top DOJ Official Says

Policy

EU Cyber Resilience Act sets cybersecurity rules for containers and Kubernetes

Policy

EU Cyber Resilience Act: Irish software firms face fines up to €15m