SBOM Readiness for the EU CRA

What Digital Product Producers Must Do Now

As cybersecurity regulations tighten worldwide, organizations that build or ship software, firmware, or connected devices face new expectations for Software Bills of Materials (SBOMs). Teams must generate compliance-ready SBOMs, validate accuracy, and report actively exploited vulnerabilities quickly. 
 
The EU Cyber Resilience Act (CRA) raises the bar for any organization bringing software-enabled products to the EU market. It calls for security by design, a documented vulnerability-management process, transparent technical documentation that includes SBOMs, and timely security updates across the product lifecycle. It also requires evidence of compliance through conformity assessment. 
 
In practice, these requirements demand automated and repeatable SBOM workflows. Teams need to:

 

  • Generate complete, machine-readable SBOMs in industry-standard formats
  • Monitor components continuously against vulnerability feeds. 
  • Triage and disclose actively exploited vulnerabilities without delay. 


 In this webinar, you will learn what the EU CRA requires and what engineering and security teams should do now to prepare. We will cover practical ways to uncover deeply embedded third-party components, reduce gaps caused by incomplete SBOMs, and streamline vulnerability identification, triage, and reporting. We will also walk through an SBOM management workflow designed to simplify generation, validation, monitoring, and CRA-ready documentation. 
 
Whether you already manage SBOMs or are just getting started, you will leave with a clear plan for next steps and a stronger foundation for CRA readiness. 

Handouts

Stay up-to-date. Follow us! View/Download
[MP3] EU CRA in 4 Minutes: Why SBOM Matters View/Download

Presenter

  • Zahra Khani
    Principal Product Manager, SBOM Manager, Keysight
    Zahra is a cybersecurity expert who specializes in device and supply chain security. She earned a software engineering degree in 2009 and founded Firmalyzer in 2016, where she pioneered automated OT and IoT firmware security analysis. After Keysight Technologies acquired Firmalyzer in 2023, Zahra became the Product Manager for IoT Security Assessment and SBOM Manager. She combines deep technical expertise with strategic vision and turns complex cybersecurity challenges into opportunities to strengthen and secure the connected world.

Register to watch on demand

Error: Please enter your first name.
Error: Please enter your last name.
This field is required.
This field is required.
This field is required.
This field is required.
Webinar: SBOM Readiness for the EU CRA by Keysight