CRA release readiness

The regulation asks for evidence. Start from the release.

The EU Cyber Resilience Act (Regulation (EU) 2024/2847) makes cybersecurity evidence a condition of market access for products with digital elements. SBOMFlow prepares that evidence from the build you actually ship — and leaves every conformity judgment where the regulation puts it: with people.

The published schedule

These are the dates the official sources currently state.

  1. 10 Dec 2024 In force The Cyber Resilience Act (Regulation (EU) 2024/2847) entered into force.
  2. 11 Sep 2026 Reporting begins Article 14 reporting obligations apply, and ENISA's single reporting platform is scheduled to be operational.
  3. 11 Dec 2027 Main obligations Secure-by-design, vulnerability handling, technical documentation, and conformity assessment apply across the market.

Verify against the primary sources: European Commission — Cyber Resilience Act ↗ European Commission — CRA reporting ↗ Regulation (EU) 2024/2847 (EUR-Lex) ↗

Where SBOMFlow helps

Engineering evidence for four kinds of CRA work.

SBOMFlow supports the evidence side of CRA readiness. It observes, organises, and exposes gaps; it never decides conformity, and it never files anything.

Release-backed technical evidence

Available today

Every audit maps observed evidence to a versioned model of the regulation — Annex I product requirements, Annex VII technical documentation, Article 14 reporting readiness — with technical-documentation workspaces and an explicit list of what is present, what is manual-only, and what is missing.

You get
CRA coverage map, evidence pack, gap list, UNSIGNED drafts for humans to finish
You keep
the conformity judgment, with your assessor or notified body where required

SBOM & component transparency

Available today

Validated CycloneDX and SPDX SBOMs from the real build, with field-presence checks against NTIA minimum elements and BSI TR-03183-2 — presence facts a reviewer can act on, never a conformance verdict — plus a redactable pack for the importers and distributors who ask.

You get
reproducible SBOMs, presence checks, shareable evidence with verification hashes
You keep
the decision about what to share, and with whom

Vulnerability-handling continuity

Available today · post-market case workflow experimental

The CRA expects vulnerability handling to continue after release. SBOMFlow correlates advisories against what each shipped release actually contained, layers in exploitation context as triage input, records human decisions on a tamper-evident trail, and — in the experimental post-market preview — carries PSIRT cases from intake to human-verified remediation.

You get
exposure candidates per shipped release, recorded triage, drift between releases
You keep
every "affected / not affected" call — with a valid justification required

Reporting preparation — never filing

Available today · drafts only

Article 14 reporting is a human act with legal consequences. SBOMFlow prepares clearly-watermarked UNSIGNED DRAFTs with the evidence attached, so the person who submits has the record in front of them. SBOMFlow never transmits, signs, or submits anything, and never contacts a CSIRT, ENISA, or any reporting platform.

You get
draft content traceable to release evidence, ready for a human to complete
You keep
the submission itself — on the official platform, under your authority

The deeper technical detail lives in the docs: CRA-oriented evidence · capability matrix · honest limitations.

Read this before you buy anything CRA-related — from us or anyone else:

  • No tool can make a product CRA-conformant. Conformity is a legal outcome involving your processes, documentation, and — for many products — third-party assessment.
  • SBOMFlow produces engineering evidence and gap assessments to support that work. It is not legal advice, and it does not replace your assessor, notified body, or counsel.
  • Regulatory guidance evolves. We pin our evidence model to a versioned reading of the regulation and update it deliberately — check the primary sources above for the current legal state.

A 20-minute CRA evidence review, from your real release.

Tell us what you build and how you release it. We'll show you what a release-backed evidence pack looks like for a product like yours — including the gaps — and give you a straight answer on fit.