Skip to content

Cyber Resilience Act

Does the Cyber Resilience Act require an SBOM?

LAST REVIEWED

The practical requirement is not the file but the accuracy. An SBOM generated from the build system reflects what shipped; one maintained by hand drifts within a release or two and undermines both vulnerability triage and the reporting timelines.

  • Generate per build artefact, versioned with the release.
  • Use CycloneDX or SPDX, both commonly used machine-readable formats.
  • Retain historical SBOMs so shipped versions can be queried during incident response.

Want this answered for your product?

The scope checker gives you a documented read in a few minutes, including a full PDF.