Why You Need an SBOM for CRA
CRA Annex I Part II, §1 requires a Software Bill of Materials listing every component in your product.
Formats: CycloneDX vs SPDX
| Feature | CycloneDX | SPDX |
|---|---|---|
| Maintained by | OWASP | Linux Foundation |
| Primary focus | Security & vulnerability tracking | License compliance |
| CRA suitability | Recommended | Acceptable |
Tool Comparison
| Tool | Languages | CVE Scanning | CI/CD |
|---|---|---|---|
| cdxgen | JS, Python, Java, .NET, Go, Rust | No | |
| Syft | Multi-language, containers | No (use Grype) | |
| Trivy | Multi-language, containers, IaC | Yes |
Recommendation: Trivy for starting out. Syft + Dependency-Track for production. See full SBOM guide →
Get the CRA deadline calendar
A one-page PDF showing every CRA date that matters for your product team. Free — no spam, unsubscribe anytime.
Ready to Take Action?
Start your CRA compliance journey with our free assessment tool.