Generate an SBOM for CRA: Tools, Formats, CI/CD
A hands-on guide to generating Software Bills of Materials for CRA compliance. Covers open-source tools, format selection, and automated pipeline integration.
Analysis and practical guidance on the EU Cyber Resilience Act. Regulation explainers, SBOM tooling, vulnerability workflows, and ENISA reporting, written for manufacturers, importers, and distributors.
A hands-on guide to generating Software Bills of Materials for CRA compliance. Covers open-source tools, format selection, and automated pipeline integration.
An operational CRA distributor companion: receiving checklist, quick-reference card, real scenarios, and the acts that turn a distributor into a manufacturer.
How a resource-constrained startup meets the EU Cyber Resilience Act: self-assessment, one compliance owner, the support duty, and funding options.
Comparing the EU Cyber Resilience Act with the UK PSTI Act: key differences, where they overlap, and dual-compliance strategies for both markets.
Understanding how CRA and NIS2 interact. A practical guide for organizations that manufacture products and operate critical services.
How to use VEX (Vulnerability Exploitability eXchange) for CRA compliance: formats, status types, SBOM integration, and practical examples.
Get notified when we publish new articles about CRA compliance and product security.