SBOM Readiness for the EU CRA

Webinars

Webinar Summary

The EU Cyber Resilience Act (CRA) introduces mandatory cybersecurity obligations for products with digital elements, and accurate, machine-readable Software Bills of Materials (SBOMs) sit at the center of nearly every one of them. This webinar walks through the CRA's SBOM and vulnerability management requirements: from generating and validating machine-readable SBOMs, to continuously monitoring components against vulnerability intelligence, to meeting the CRA's strict timelines for reporting actively exploited vulnerabilities.

 

It also covers the practical side of compliance: uncovering third-party and open-source components that a typical source-based SBOM misses, cutting through false positives and false negatives in vulnerability data, and using VEX (Vulnerability Exploitability eXchange) and automated reachability analysis to focus remediation on the vulnerabilities that actually matter. Finally, the session explains how Keysight SBOM Manager and Keysight's CRA readiness and conformity assessment services can help organizations build these capabilities ahead of the September 2026 and December 2027 compliance deadlines.

 

New to the EU Cyber Resilience Act (CRA) or need a quick refresher? Listen to our 4-minute podcast, EU CRA in 4 Minutes: Why SBOM Matters, and get up to speed on the essentials in just a few minutes.

 

Key Highlights from the Webinar

  • Understand the EU CRA's SBOM and vulnerability requirements: Learn what the CRA requires for SBOM generation, third-party dependency tracking, and vulnerability handling, and the compliance deadlines that apply.
  • Know what to report, and when: See how the CRA's reporting obligations work for actively exploited vulnerabilities, including the 24-hour early warning, 72-hour detailed notification, and follow-up reporting timelines.
  • Why SBOM accuracy and standards conformance matter: Understand why SBOMs must reflect what's actually shipped, and how frameworks like NTIA's minimum elements and BSI TR-03183 are shaping what a compliant SBOM looks like.
  • Binary-based SBOM generation: Learn how analyzing the actual shipped binary, rather than relying only on build-time data, uncovers hidden dependencies and improves SBOM accuracy for both producers and consumers.
  • Cutting through vulnerability noise: Discover how enriching SBOM data with multiple vulnerability sources, filtering by patch level, and automating CVE reachability analysis eliminates irrelevant vulnerabilities and cuts manual triage time.
  • VEX and vulnerability context: Understand how VEX documents whether a vulnerability actually affects a product, turning long CVE lists into actionable intelligence.
  • Support beyond the platform: Learn about Keysight's CRA readiness and conformity assessment services, and how they complement SBOM Manager across the full compliance journey.
  • Preparing for CRA compliance today: Explore concrete first steps organizations can take now, so SBOM and vulnerability management capabilities are in place well ahead of the CRA's deadlines.

 

Download the SBOM Readiness for the EU CRA webinar slides.

 

Frequently Asked Questions

1. What is an SBOM, and why is it important for the EU Cyber Resilience Act?

An SBOM (Software Bill of Materials) is a machine-readable inventory of components, both open-source and proprietary, that make up a software product, including details like component name, version, license, and origin. Under the CRA, manufacturers must generate and maintain SBOMs to improve software transparency, support vulnerability management, and demonstrate compliance to market surveillance authorities on request.

 

2. What are the key CRA compliance deadlines, and what are the penalties for non-compliance?

The CRA's reporting obligations for actively exploited vulnerabilities apply from September 2026, and its broader cybersecurity and compliance requirements apply from December 2027. Non-compliance can result in fines of up to €15 million or 2.5% of a company's global annual turnover, whichever is higher. The full requirements are set out in Regulation (EU) 2024/2847, particularly Annex I and Articles 13 and 14.

 

3. Does the CRA require manufacturers to track all software dependencies?

The CRA requires manufacturers to identify and document software components, including at least top-level third-party dependencies. Transitive dependencies (components pulled in indirectly through another library) aren't explicitly mandated, but many organizations track these too, since vulnerabilities are often hidden several layers deep in the supply chain.

 

4. What must manufacturers do if a vulnerability is actively exploited?

Once a manufacturer becomes aware, with reasonable certainty, that a vulnerability is being actively exploited, the CRA requires an early warning within 24 hours, a more detailed notification within 72 hours, and a final report within 14 days of a fix becoming available. Reports go simultaneously to the relevant national CSIRT and ENISA through a single reporting platform, and manufacturers must also inform affected users on a risk-based approach.

 

5. What is VEX, and how does it help with vulnerability management?

VEX (Vulnerability Exploitability eXchange) adds context to the vulnerabilities identified in an SBOM. Instead of treating every associated CVE as equally actionable, VEX lets manufacturers document whether a vulnerability is affected, not affected (with justification), fixed, under investigation, or a false positive, turning a raw vulnerability list into information teams can actually act on.

 

6. How can organizations reduce false positives and false negatives in vulnerability data?

Many vulnerability tools rely solely on the NVD and automated CPE (Common Platform Enumeration) matching, which can be incomplete, too broad, or simply wrong, leading to both missed vulnerabilities and irrelevant alerts. Enriching SBOM data with multiple, authoritative vulnerability and threat intelligence sources, filtering by a component's exact patch level, and using automated CVE reachability analysis to confirm whether vulnerable code is actually present can significantly cut this noise and save security teams substantial manual review time.

 

7. Why is binary-based (analyzed) SBOM generation valuable?

Binary analysis generates an SBOM directly from the actual shipped software or firmware, rather than relying only on build-time artifacts. This doesn't require access to the build process, works even for legacy firmware, and can uncover hidden or undeclared dependencies that other SBOM generation methods miss, which matters because every component declared in an SBOM carries potential compliance liability.

 

8. Do all products need third-party conformity assessment under the CRA?

No. The CRA defines several product classes (Default, Important Class I, Important Class II, and Critical), each with its own conformity route. Default and Important Class I products can generally be self-assessed against the relevant standards, while Important Class II and Critical products require third-party conformity assessment and certification by an accredited body, such as under the EU Cybersecurity Certification (EUCC) scheme.2

 

9. Does Keysight offer support beyond the SBOM Manager platform?

Yes. Keysight supports organizations across the full CRA compliance journey: a Phase 1 Readiness engagement (product classification, design and process review, and gap analysis, resulting in a compliance plan), and a Phase 2 Evaluation (documentation review, SBOM vulnerability verification, and security testing, resulting in a conformity assessment report). Keysight is also an accredited EUCC evaluation body for products that require third-party certification.

 

10. How can organizations begin preparing for CRA compliance today?

Organizations should start by establishing accurate, binary-verified SBOM generation processes, implementing continuous vulnerability monitoring and reachability analysis, validating SBOM quality against frameworks like NTIA's minimum elements and BSI TR-03183, and documenting remediation activities. Starting early, well ahead of the September 2026 and December 2027 deadlines, makes meeting the CRA's reporting and compliance obligations significantly easier.