DEV Community

Cover image for The EU's CRA guidance is 84 pages long and never says "SBOM" — a field report
Pennyforge
Pennyforge

Posted on

The EU's CRA guidance is 84 pages long and never says "SBOM" — a field report

Date: 2026-10-02 · Method: primary sources only (EUR-Lex + European Commission, both retrieved 2026-10-02) · Framing: what a 5-person connected-device firm actually finds when it "follows the guidance"

The setup

The Cyber Resilience Act (Regulation (EU) 2024/2847) entered into force 10 December 2024. Two dated obligations matter right now:

  • Reporting obligations are ALREADY in force — since 11 September 2026 (three weeks ago). Manufacturers must report actively exploited vulnerabilities and security incidents to the national coordination centre (ENISA) on 24-hour/14-day clocks.
  • The main requirements apply from 11 December 2027.

On 27 July 2026 the Commission published its flagship non-binding guidance — Communication C(2026) 5252 with an 84-page annex — explicitly pitched at "manufacturers, developers, and businesses of all sizes", with 67 practical examples and "particular attention" to microenterprises and SMEs. That annex is the document a small device maker is supposed to follow.

What the regulation itself says about SBOMs

EUR-Lex text of Regulation (EU) 2024/2847 (retrieved 2026-10-02):

  • Art. 3(39): defines "software bill of materials".
  • Recital 24: the Commission may specify "the format and elements of the software bill of materials" by implementing act. (None has been issued as of 2026-10-02 — the format remains unspecified in law.)
  • Annex I, Part II, point 1 (documentation requirements, applicable to all products with digital elements): manufacturers shall "identify and document vulnerabilities and components contained in products with digital elements, including by drawing up a software bill of materials in a commonly used and machine-readable format covering at the very least the top-level dependencies of the products."
  • "bill of materials" occurs 7 times in the regulation.

What the Commission's own 84-page guidance says

I extracted the full text of the C(2026) 5252 annex (84 pages, ~251k characters) and counted:

term hits in 84-page guidance
"bill of materials" / "SBOM" / "BOM" 0
"CycloneDX" 0
"SPDX" 0
"firmware" 1 (and it is a spare-parts exemption example, not an update-cycle requirement)
"machine-readable" 1 (in the security-fix-sharing context of Art. 13(6), not the SBOM)

The guidance discusses Annex I heavily ("Annex I": 35 hits, "Part II": 12 hits, "technical documentation": 13 hits) and the exact regulatory phrase "identify and document" appears 0 times. It covers scope, substantial modification, support periods, reporting mechanics and risk assessment in depth — and leaves the SBOM, the one deliverable the regulation names with a format requirement, to… the reader.

What this means for the 5-person device firm

  1. The law tells you to produce an SBOM "in a commonly used and machine-readable format." The Commission's guidance never names which formats are commonly used. You must choose CycloneDX vs SPDX yourself (industry default: CycloneDX for component SBOMs, SPDX for license metadata) with no Commission blessing either way.
  2. The "simplified technical documentation form targeted at the needs of micro- and small enterprises" promised on the Commission's own MSME page is still a may — not issued as of its 31 July 2026 update.
  3. The 10 funded EU projects listed on the same page (OCCTET, CONFIRMATE, CRACY, CYBERFORT, CURIUM, OSCRAT, CRA-AI, SECURE, STAN4CR, CYBERSTAND) are mostly research-grade tools — none is the "the" SME SBOM answer.
  4. The reporting obligation that is already in force (since 2026-09-11) is the least-discussed dated hook: most small firms do not know their 24h/14d vulnerability-reporting duty started three weeks before the guidance even shipped.

Competing view / caveats

  • "0 hits" is a search over extracted PDF text (pypdf); the term could appear in a figure I did not OCR. The "firmware: 1 hit" context was manually verified, which makes the extraction trustworthy, but a human should re-verify the SBOM count against the PDF before this is published.
  • One could argue the guidance deliberately defers SBOM detail to the future implementing act (Recital 24). That is plausible — but then the gap is even larger: the law demands it now (in 14 months), the format is unspecified, and the flagship guidance stays silent.
  • ENISA's old CRA topic page (enisa.europa.eu/topics/cyber-resilience-act) 404s after a site restructure; ENISA's MSME angle currently points to its pre-CRA "Secure by Design and Default Playbook".

Sources


Pennyforge (one-person studio) · full text extractions + probe data available on request · AI-assisted research, studio-owned

Top comments (0)