Supply chain transparency required by the CRA, NIS2 and your customers

SBOM: the software parts list that is becoming mandatory

An SBOM (Software Bill of Materials) lists all components of your software in machine-readable form and makes the supply chain transparent. The EU Cyber Resilience Act turns it into a manufacturer obligation: reporting duties from 11 September 2026, full applicability from December 2027. We introduce SBOM processes vendor-neutrally: tool selection, CI/CD automation, VEX, vulnerability integration and CRA-compliant evidence.

  • Answers in minutes instead of weeks: which products contain the vulnerable component?
  • CRA-compliant: SBOM per Annex I, presentable to the BSI (TR-03183-2)
  • Automated instead of hand-maintained: SBOM generation in every pipeline (Syft, Trivy, CycloneDX, SPDX)
  • VEX instead of alert floods: documented exploitability assessment per vulnerability
  • Connected to your vulnerability management and reporting processes from 11 Sep 2026

Your strategic success starts here

Our clients trust our expertise in digital transformation, compliance, and risk management

30 Minutes • Non-binding • Immediately available

For optimal preparation of your strategy session:

  • Your strategic goals and objectives
  • Desired business outcomes and ROI
  • Steps already taken

Or contact us directly:

Certifications, Partners and more...

ISO 9001 CertifiedISO 27001 CertifiedISO 14001 CertifiedBeyondTrust PartnerBVMW Bundesverband MitgliedMitigant PartnerGoogle PartnerTop 100 InnovatorMicrosoft AzureAmazon Web Services

What is an SBOM, and why is it becoming mandatory now?

Our SBOM Expertise

  • Comprehensive experience in strategic SBOM implementation
  • Proven methods for automated SBOM generation
  • Integrated supply chain security and vulnerability management
  • Long-term partnership for SBOM excellence and CRA compliance

SBOM Strategy Note

Successful SBOM implementation requires a comprehensive consideration of technology, processes, and partnerships. Automation and continuous improvement are crucial for sustainable supply chain security and CRA compliance.

ADVISORI in Numbers

11+

Years of Experience

120+

Employees

520+

Projects

We start with the products facing the earliest CRA deadlines and bring generation, management and vulnerability integration into steady state one after the other.

Our Approach:

Phase 1, readiness (weeks 1 to 2): product inventory, CRA applicability per product, build landscape, gap against BSI TR-03183-2. Output: prioritised roadmap.

Phase 2, pilot (weeks 3 to 4): tool selection in a PoC on a real product, format decision CycloneDX or SPDX, first automatically generated SBOM in the build.

Phase 3, rollout: pipeline integration across all affected products, central versioned storage, artefact signing.

Phase 4, operation: Dependency-Track or comparable platform, continuous CVE matching, VEX process, connection to vulnerability and reporting processes.

Phase 5, supply chain and evidence: demand and validate supplier SBOMs, CRA documentation per Annex VII, preparation for BSI and customer audits.

"SBOM implementation is the key to transparent and secure supply chains in the Cyber Resilience Act. Our clients benefit from strategic SBOM approaches that not only ensure compliance but also create operational excellence through improved transparency, proactive vulnerability management, and trustworthy partnerships along the entire value chain."
Sarah Richter

Sarah Richter

Head of Information Security, Cyber Security

Expertise & Experience:

10+ years of experience, CISA, CISM, Lead Auditor, DORA, NIS2, BCM, Cyber and Information Security

Our Services

We offer you tailored solutions for your digital transformation

SBOM readiness assessment

Baseline in one to two weeks: which products need SBOMs, which build processes exist, where you stand against CRA Annex I and BSI TR-03183-2.

  • Product inventory with CRA applicability per product
  • Gap rating against CRA, NIS2 and customer requirements
  • Prioritised roadmap with effort estimate

Tool selection and format strategy

Vendor-neutral choice: CycloneDX or SPDX, Syft, Trivy, Microsoft SBOM Tool or platform generators, matched to your build landscape.

  • Format decision aligned with customer and authority requirements
  • Tool evaluation in a PoC against your real builds
  • Container, firmware and legacy strategies

CI/CD integration and automation

SBOM generation as a fixed step in every pipeline: automatic, versioned, signed. Manually maintained SBOMs are outdated with the first release.

  • Pipeline integration (GitLab, GitHub, Jenkins, Azure DevOps)
  • Signing and integrity evidence for SBOM artefacts
  • Central storage versioned per product release

SBOM management and vulnerability integration

SBOMs create value in operation: continuous matching against CVE feeds, VEX statements, connection to your vulnerability management.

  • Dependency-Track or comparable platform set-up
  • VEX process: documented assessment instead of alert floods
  • Connection to vulnerability management and incident response

CRA compliance and evidence

The SBOM as part of the technical documentation under CRA Annex VII: presentable to the BSI, robust in conformity assessment.

  • Documentation structure per CRA Annex I and VII
  • Reporting processes from 11 Sep 2026 (ENISA early warning 24h/72h)
  • Preparation for market surveillance requests

Supplier SBOMs and procurement

Demand, validate and merge SBOMs from your suppliers: contract clauses, quality criteria and handling incomplete deliveries.

  • SBOM requirement catalogue for procurement and contracts
  • Quality checks on incoming SBOMs (NTIA minimum elements)
  • Merging into complete product SBOMs

Our Competencies

Choose the area that fits your requirements

BSI CRA

BSI oversees CRA conformity of digital products as market surveillance authority in Germany. Vulnerability reporting obligations begin September 2026, and all manufacturers must be fully compliant by December 2027. We guide you through every BSI CRA requirement.

CRA Audit

Systematic CRA audits verify compliance with all Cyber Resilience Act requirements. From gap analysis through conformity assessment under Module A, B, C or H to market surveillance preparation, with a clear roadmap for the deadlines starting June 2026.

CRA Certification

CRA certification ensures conformity of your digital products with the Cyber Resilience Act. From self-assessment to third-party conformity assessment.

CRA Compliance

Complete CRA compliance for digital product manufacturers. From security by design through vulnerability management to CE marking. Deadline: December 2027.

CRA Consulting: Cyber Resilience Act

The EU Cyber Resilience Act (Regulation (EU) 2024/2847) imposes binding cybersecurity standards on all manufacturers, importers, and distributors of products with digital elements. From September 2026, reporting obligations apply for actively exploited vulnerabilities (24-hour deadline to ENISA); from December 2027, all products must be fully CRA-compliant, otherwise fines of up to €15 million or 2.5% of global annual turnover and loss of EU market access are at risk. ADVISORI ensures you are compliant in time.

CRA Cyber Resilience Act Conformity Assessment

CRA conformity assessment demonstrates your product meets all cybersecurity requirements. Different modules by risk class through to CE marking.

CRA Cyber Resilience Act Germany

The EU Cyber Resilience Act explained for the German market. From September 2026, manufacturers must report actively exploited vulnerabilities within 24 hours. By December 2027, all digital products must be CRA-compliant. Learn how BSI enforces CRA requirements in Germany.

CRA Cyber Resilience Act Market Surveillance

BSI oversees CRA conformity as national market surveillance authority. Learn about inspection procedures, corrective actions and potential sanctions.

CRA Cyber Resilience Act Product Security Requirements

The EU Cyber Resilience Act (CRA) Annex I defines 13 mandatory product security requirements for digital products. From security by design to SBOM documentation and vulnerability handling, these requirements become mandatory from December 2027 for all manufacturers. ADVISORI supports you in fully implementing the Annex I obligations.

CRA Data Breach Management

The CRA mandates reporting of vulnerabilities and security incidents within 24 hours. ENISA reporting channels and incident response planning.

Frequently Asked Questions about SBOM (Software Bill of Materials)

What is an SBOM (Software Bill of Materials)?

An SBOM is a machine-readable inventory of all components in a piece of software: in-house modules, open-source libraries, purchased components and their dependencies, each with version, licence and origin. It makes the software supply chain transparent and answers within minutes which products contain a vulnerable component. Common formats are CycloneDX and SPDX.

Is an SBOM mandatory under the Cyber Resilience Act?

Yes. The CRA (Regulation (EU) 2024/2847) requires manufacturers to document product components, at least the top-level dependencies, as an SBOM and to present it to market surveillance authorities on request. In Germany the BSI is responsible; Technical Guideline TR‑03183–2 specifies the requirements. Reporting obligations for actively exploited vulnerabilities apply from

11 September 2026, full CRA applicability from

11 December 2027.

What is the difference between CycloneDX and SPDX?

CycloneDX originates from the OWASP community and is designed for security use cases: vulnerability matching, VEX integration, DevSecOps toolchains. SPDX comes from the Linux Foundation, is standardised as ISO/IEC

5962 and historically strong in licence compliance. Both are machine-readable and accepted by the BSI. In practice the ecosystem decides: Dependency-Track and security tooling favour CycloneDX; licence management favours SPDX. Many tools export both.

What must an SBOM contain?

The NTIA Minimum Elements are the established baseline: component name, version, supplier, unique identifiers (such as purl or CPE), dependency relationships, SBOM author and timestamp. BSI TR‑03183–2 adds licence information and hashes among others. Unique component identification is critical; without it, automated matching against vulnerability databases fails.

Which tools generate SBOMs?

Established open-source tools are Syft (Anchore) and Trivy (Aqua Security); both produce CycloneDX and SPDX from source code, artefacts and container images. Microsoft provides the SBOM Tool, GitLab and GitHub generate SBOMs directly in the pipeline. For management and CVE matching, Dependency-Track (OWASP) is the de-facto standard. Tooling is rarely the bottleneck; automated generation on every release is.

What is VEX and how does it complement the SBOM?

VEX (Vulnerability Exploitability eXchange) is the SBOM's counterpart: a machine-readable manufacturer statement on whether a product is actually affected by a known vulnerability. Without VEX, SBOM matching against CVE databases produces many false alarms, because a contained component is not automatically exploitable. With VEX you document 'not affected' with reasoning and focus remediation on real risk.

Do containers and firmware need SBOMs too?

Yes. Container images are the most common use case: tools like Syft and Trivy scan images including OS packages. Firmware and embedded systems are more demanding (binary analysis, Yocto and Buildroot integration), but that is exactly where the CRA applies, since products with digital elements are in scope. Manufacturers of connected devices should start early.

How do SBOM and vulnerability management connect?

The SBOM is the inventory foundation of vulnerability management for software components: continuous matching against CVE feeds shows which products are affected by new vulnerabilities, VEX assesses actual exploitability, and remediation runs through your patch and release processes. The CRA requires exactly this chain, including reporting actively exploited vulnerabilities to ENISA within

24 hours from

11 September 2026.

Success Stories

Discover how we support companies in their digital transformation

Digitalization in Steel Trading

Steel trading company from Germany

Digital Transformation in Steel Trading

Case Study

Results

Over 2 billion euros in annual revenue through digital channels
More than half of revenue through online channels as a strategic goal
Improved customer satisfaction through automated processes

AI-Powered Manufacturing Optimization

Industrial group from Germany

Smart Manufacturing Solutions for Maximum Value Creation

Case Study

Results

Significant increase in production performance
Reduction of downtime and production costs
Improved sustainability through more efficient resource utilization

AI Automation in Production

Automation specialist from Germany

Intelligent Networking for Future-Proof Production Systems

Case Study

Results

Improved production speed and flexibility
Reduced manufacturing costs through more efficient resource utilization
Increased customer satisfaction through personalized products

Generative AI in Manufacturing

Technology group from Germany

AI Process Optimization for Improved Production Efficiency

Case Study

Results

Reduction of AI application implementation time to just a few weeks
Improvement in product quality through early defect detection
Increased manufacturing efficiency through reduced downtime

Let's

Work Together!

Is your organization ready for the next step into the digital future? Contact us for a personal consultation.

Your strategic success starts here

Our clients trust our expertise in digital transformation, compliance, and risk management

Ready for the next step?

Schedule a strategic consultation with our experts now

30 Minutes • Non-binding • Immediately available

For optimal preparation of your strategy session:

Your strategic goals and challenges
Desired business outcomes and ROI expectations
Current compliance and risk situation
Stakeholders and decision-makers in the project

Prefer direct contact?

Direct hotline for decision-makers

Strategic inquiries via email

Detailed Project Inquiry

For complex inquiries or if you want to provide specific information in advance