Date: 2026-10-02 · Method: primary sources only (EUR-Lex + European Commission, both retrieved 2026-10-02) · Framing: what a 5-person connected-device firm actually finds when it "follows the guidance"
The setup
The Cyber Resilience Act (Regulation (EU) 2024/2847) entered into force 10 December 2024. Two dated obligations matter right now:
- Reporting obligations are ALREADY in force — since 11 September 2026 (three weeks ago). Manufacturers must report actively exploited vulnerabilities and security incidents to the national coordination centre (ENISA) on 24-hour/14-day clocks.
- The main requirements apply from 11 December 2027.
On 27 July 2026 the Commission published its flagship non-binding guidance — Communication C(2026) 5252 with an 84-page annex — explicitly pitched at "manufacturers, developers, and businesses of all sizes", with 67 practical examples and "particular attention" to microenterprises and SMEs. That annex is the document a small device maker is supposed to follow.
What the regulation itself says about SBOMs
EUR-Lex text of Regulation (EU) 2024/2847 (retrieved 2026-10-02):
- Art. 3(39): defines "software bill of materials".
- Recital 24: the Commission may specify "the format and elements of the software bill of materials" by implementing act. (None has been issued as of 2026-10-02 — the format remains unspecified in law.)
- Annex I, Part II, point 1 (documentation requirements, applicable to all products with digital elements): manufacturers shall "identify and document vulnerabilities and components contained in products with digital elements, including by drawing up a software bill of materials in a commonly used and machine-readable format covering at the very least the top-level dependencies of the products."
- "bill of materials" occurs 7 times in the regulation.
What the Commission's own 84-page guidance says
I extracted the full text of the C(2026) 5252 annex (84 pages, ~251k characters) and counted:
| term | hits in 84-page guidance |
|---|---|
| "bill of materials" / "SBOM" / "BOM" | 0 |
| "CycloneDX" | 0 |
| "SPDX" | 0 |
| "firmware" | 1 (and it is a spare-parts exemption example, not an update-cycle requirement) |
| "machine-readable" | 1 (in the security-fix-sharing context of Art. 13(6), not the SBOM) |
The guidance discusses Annex I heavily ("Annex I": 35 hits, "Part II": 12 hits, "technical documentation": 13 hits) and the exact regulatory phrase "identify and document" appears 0 times. It covers scope, substantial modification, support periods, reporting mechanics and risk assessment in depth — and leaves the SBOM, the one deliverable the regulation names with a format requirement, to… the reader.
What this means for the 5-person device firm
- The law tells you to produce an SBOM "in a commonly used and machine-readable format." The Commission's guidance never names which formats are commonly used. You must choose CycloneDX vs SPDX yourself (industry default: CycloneDX for component SBOMs, SPDX for license metadata) with no Commission blessing either way.
- The "simplified technical documentation form targeted at the needs of micro- and small enterprises" promised on the Commission's own MSME page is still a may — not issued as of its 31 July 2026 update.
- The 10 funded EU projects listed on the same page (OCCTET, CONFIRMATE, CRACY, CYBERFORT, CURIUM, OSCRAT, CRA-AI, SECURE, STAN4CR, CYBERSTAND) are mostly research-grade tools — none is the "the" SME SBOM answer.
- The reporting obligation that is already in force (since 2026-09-11) is the least-discussed dated hook: most small firms do not know their 24h/14d vulnerability-reporting duty started three weeks before the guidance even shipped.
Competing view / caveats
- "0 hits" is a search over extracted PDF text (pypdf); the term could appear in a figure I did not OCR. The "firmware: 1 hit" context was manually verified, which makes the extraction trustworthy, but a human should re-verify the SBOM count against the PDF before this is published.
- One could argue the guidance deliberately defers SBOM detail to the future implementing act (Recital 24). That is plausible — but then the gap is even larger: the law demands it now (in 14 months), the format is unspecified, and the flagship guidance stays silent.
- ENISA's old CRA topic page (enisa.europa.eu/topics/cyber-resilience-act) 404s after a site restructure; ENISA's MSME angle currently points to its pre-CRA "Secure by Design and Default Playbook".
Sources
- EUR-Lex, Regulation (EU) 2024/2847 (OJ version): https://eur-lex.europa.eu/eli/reg/2024/2847/oj
- Commission CRA policy page (last update 7 September 2026): https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act
- Commission guidance announcement, 27 July 2026: https://digital-strategy.ec.europa.eu/en/library/commission-publishes-new-guidance-support-timely-cyber-resilience-act-implementation
- Guidance annex PDF (C(2026) 5252): https://ec.europa.eu/newsroom/dae/redirection/document/131456
- MSME card (last update 31 July 2026): https://digital-strategy.ec.europa.eu/en/policies/cra-msmes
Pennyforge (one-person studio) · full text extractions + probe data available on request · AI-assisted research, studio-owned
Top comments (0)