SBOM and Component Records
The CRA uses component visibility as part of vulnerability handling. Annex I requires manufacturers to identify and document vulnerabilities and components, including by drawing up a software bill of materials.
Annex I requirement
identify and document vulnerabilities and components contained in products with digital elements, including by drawing up a software bill of materials in a commonly used and machine-readable format covering at the very least the top-level dependencies of the products;
Regulation (EU) 2024/2847, Annex I, Part II, point (1)
The SBOM is part of a wider component record. It helps the manufacturer understand which components are contained in the product and which vulnerabilities can affect those components.
What to distinguish
SBOM
A machine-readable software component record. Annex I requires at least top-level dependencies.
Integrated component
A component contained in the product can create vulnerability handling duties for the finished product.
Third-party component
Article 13 requires due diligence when third-party components are integrated into the product.
Authority access
Annex VII includes SBOM access on reasoned request when needed to check Annex I compliance.
Technical documentation link
Annex VII places component and SBOM information in the technical documentation. It also asks for vulnerability-handling process information, the coordinated vulnerability disclosure policy, the reporting contact, and secure update distribution.
The process side is explained in Vulnerability Handling Records and prEN 40000-1-3 Vulnerability Handling.
Format status
Article 13 allows the Commission to specify the format and elements of the SBOM by implementing act, taking into account European or international standards and best practices. Until that act exists, the safe statement is that Annex I requires a commonly used, machine-readable format and at least top-level dependencies.
- Do not treat a PDF component list as the SBOM format required by Annex I.
- Do not treat the SBOM as the whole vulnerability-handling process.
- Do not assume the SBOM is always public; Annex VII has a specific authority-request rule.