InsideCRA
InsideCRA › Recitals › Recital 77

Regulation (EU) 2024/2847 · Preamble

Recital 77

LAW Official text

(77) In order to facilitate vulnerability analysis, manufacturers should identify and document components contained in the products with digital elements, including by drawing up an SBOM. An SBOM can provide those who manufacture, purchase, and operate software with information that enhances their understanding of the supply chain, which has multiple benefits, in particular it helps manufacturers and users to track known newly emerged vulnerabilities and cybersecurity risks. It is of particular importance that manufacturers ensure that their products with digital elements do not contain vulnerable components developed by third parties. Manufacturers should not be obliged to make the SBOM public.

BINDING Source: Regulation (EU) 2024/2847 (Cyber Resilience Act) · publisher European Union · captured 2026-09-16 · snapshot sha256:27b7c6c64c773001… · CELEX 32024R2847
Recitals are the Regulation's stated reasoning. Obligations live in the articles; the recitals inform how those obligations are read.

← Recital 76 · All recitals · Recital 78 →