InsideCRA
InsideCRA › Topics › The SBOM requirement

Topic

The SBOM requirement

What the software bill of materials duty actually asks for.

Manufacturers identify and document vulnerabilities and components, including by drawing up a software bill of materials in a commonly used machine-readable format covering at least the top-level dependencies F-019. Annex VII lists the SBOM among the vulnerability-handling information in the technical documentation, and the Regulation does not make it public by default: Annex II only asks the manufacturer to say where it can be accessed if it decides to make it available to users F-022 F-020.

Getting it done

Generate it in CI from the lockfile, refresh it per release, and store it with the release evidence F-019. Format arguments (CycloneDX vs SPDX) matter less than regeneration being automatic.

Verified facts this page relies on

Facts are maintained and human-verified in the CEMarque Facts Table (v2026.09.4, verified 2026-09-10).

Editorial review: Claude (AI reviewer, delegated by the editor), 2026-10-08. Methodology and correction process: how this site works.

Related in the reference

Ready to work through your obligations? Get your CE readiness verdict on CEMarque.