SBOM Creation and Maintenance (CRA Art. 13)
The Cyber Resilience Act (Art. 13 para. 3) requires all manufacturers of digital products to create and maintain a complete Software Bill of Materials. The SBOM must cover all software components - direct and transitive dependencies - be versioned, and updated with each product release. It must be made available to market surveillance authorities (in the EU: national competent authorities such as BSI in Germany) upon request.
Cyber Resilience Act