Skip to content

Under the CRA, manufacturers must maintain an accurate and up-to-date SBOM for each product. This includes listing all software components, tracking versions, monitoring vulnerabilities, and linking the SBOM to specific product releases. SBOM management must be integrated into the development process and supported by ongoing vulnerability and patch management throughout the product lifecycle.

Read also