01
CRA readiness
What the Cyber Resilience Act means for software product teams
Understand CRA readiness, product-version evidence, SBOMs, vulnerability handling, remediation history, and the 2026/2027 readiness timeline.
Resources
Practical guides for Cyber Resilience Act readiness, SBOM evidence, vulnerability review, remediation tracking, and retained product-security records.
Start here
Follow the path from CRA readiness context into SBOM evidence and vulnerability review history.
01
CRA readiness
Understand CRA readiness, product-version evidence, SBOMs, vulnerability handling, remediation history, and the 2026/2027 readiness timeline.
02
SBOM evidence
Learn how CycloneDX and SPDX records become useful evidence when they are validated, linked to product versions, retained, and connected to vulnerability review.
03
Vulnerability review
See how CVE triage, ownership, SLA pressure, review decisions, and remediation updates become retained product-security evidence.
Workflow mapping
Each guide maps to a part of the CRA Ledger evidence workflow.
Understand product-version evidence and readiness timelines.
Learn how CycloneDX/SPDX records support retained evidence.
Connect CVE triage, ownership, and remediation decisions.
Prepare structured evidence summaries for internal and customer reviews.
Resource library
The first path covers the evidence basics. These resources go deeper on retained records, manufacturer coordination, formats, and operating workflows.
Product security evidence
A practical checklist for artifacts, decisions, activity history, and product-version records.
CRA readiness
How product-version records, SBOM retention, and vulnerability handling support readiness workflows.
SBOM evidence
How supported SBOM formats can feed intake, normalization, vulnerability review, and retained evidence.
Vulnerability review
A structured process guide for tracking vulnerability remediation, SLA targets, and retained evidence.
Release readiness
Chronological release checklists to prepare structured security evidence before release reviews.
SBOM evidence
How product leads and engineering leads can organize software component ingestion and retention.
How CycloneDX and SPDX SBOM intake, component normalization, product-version records, and evidence retention support CRA readiness workflows.
How CVE review, severity, ownership, SLA pressure, remediation status, and retained decisions support regulated software product security.
How evidence history, audit trails, SBOM records, review decisions, remediation records, and customer evidence fit regulated software workflows.
How teams review SBOMs, vulnerability findings, remediation status, and retained evidence before regulated software releases.
Topics covered
Next step
Join early access or book a focused walkthrough of the SBOM-to-evidence workflow.