Software bill of materials (Art. 13(8)/(24), Annex I Part II point 1)
Summary
Manufacturers must maintain a software bill of materials covering at least the top-level dependencies of the product, as part of the vulnerability-handling requirements for the support period.
sbomvulnerability handlingannex i part ii
Read the full official text: https://www.cyberresilienceact.eu/regulation.html
Track CRA article 13 as evidence
eurocompliant maps this obligation to a checklist task and the evidence that satisfies it, alongside every other framework you follow.
Start free trial