Skip to content
CRA Navigator

Assessment 04

SBOM Readiness Assessment

A focused assessment of the software bill of materials your product ships with, reporting separately on what Annex I Part II(1) actually requires and how much operational use you get from the SBOM you have.

Length
5–8 minutes
Questions
14 questions

What it covers

  • SBOM coverage across the products you place on the EU market
  • Dependency depth, and why transitive coverage is not mandatory
  • Machine readability and the SPDX / CycloneDX question
  • Whether the SBOM matches the artefact you actually shipped
  • Build-time generation as the way accuracy is sustained
  • Vulnerability monitoring against the components you ship
  • Retention and disclosure to market surveillance authorities

Built for

Engineering leads, product security officers, release managers

What you get back

Two independent verdicts — a pass or fail against the CRA minimum and an operational stage — plus a findings list that separates legal obligations from good practice.

Complete the questionnaire

Answer as your product stands today rather than as you intend it to be. An accurate baseline produces a usable remediation plan.

No email address. No registration. No account.

You get your full results immediately. Nothing is gated, nothing is emailed to you, and nothing is asked of you in exchange. Every question is scored in your browser, so your answers are never sent to us or to anyone else.

SBOM Readiness Assessment

Fourteen questions on the software bill of materials your product ships with. You will get two separate answers: whether your SBOM meets what the Cyber Resilience Act actually requires, and how much operational use you are getting out of it.

No email address, no registration, no account. Everything runs in your browser: nothing you enter is sent anywhere, stored on our servers, or seen by us.

Your answers are kept in this browser tab while you work, so a reload will not lose them. Closing the tab clears them.