Article 14
CRA
Cybersécurité
Firmware
Gestion des vulnérabilités
SBOM
SBOM: what the CRA actually requires and how to prepare
The SBOM (Software Bill of Materials) is required by Annex VII of the CRA, but its regulatory value exceeds the documentary checkbox: without an up-to-date SBOM that can be correlated against vulnerability databases, the 24-hour Article 14 deadline is unmanageable. Formats, minimum content, challenges specific to embedded firmware, and what a viable SBOM looks like for an industrial SME without a full CI/CD pipeline.