The EU's CRA guidance is 84 pages long and never says "SBOM" — a field report
Date: 2026-10-02 · Method: primary sources only (EUR-Lex + European Commission, both retrieved 2026-10-02) · Framing: what a 5-person connected-device firm actually finds when it "follows the guidance" The setup The Cyber Resilience Act (Regulation (EU) 2024/2847) entered into force 10 December 2024. Two dated obligations matter right now: Reporting obligations are ALREADY in force — since 11…
The Cyber Resilience Act (CRA) guidance, published on 27 July 2026, is an 84-page document aimed at manufacturers, developers, and businesses of all sizes. However, it never explicitly mentions a Software Bill of Materials (SBOM). The guidance discusses the definition of a SBOM in the regulation, which states that manufacturers must identify and document vulnerabilities and components in products with digital elements, including by drawing up an SBOM in a commonly used and machine-readable format.
The guidance does not specify which format to use, leaving that decision to the reader. The guidance covers various aspects of the CRA, such as scope, substantial modification, support periods, reporting mechanics, and risk assessment, but it does not provide guidance on SBOMs. This leaves manufacturers to choose a format for their SBOM, such as CycloneDX or SPDX, without any Commission endorsement.
The guidance also mentions the 10 EU-funded projects related to the CRA, but none of them directly provide an answer to the SME's SBOM needs. Despite the regulatory requirement for SBOMs, the guidance does not offer a clear solution, leaving SMEs to navigate this aspect independently.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.