The 24-hour CRA Deadline: Enhancing Software Supply Chain Visibility
The EU Cyber Resilience Act (CRA) is introducing a significant change with its 24-hour deadline for notifying regulators about actively exploited vulnerabilities in products. This shift in regulation brings greater attention to the visibility of software within supply chains, especially for complex products containing various components and dependencies.
The Challenge of Multi-Tiered Dependencies
Products in industries like automotive, medical devices, aerospace, and consumer electronics often incorporate proprietary software, supplier-developed applications, commercial packages, microcontroller software, and open-source libraries. Manufacturers may have numerous supplier relationships but limited insight into the specific software within individual components.
Software Bills of Materials (SBOMs): A Crucial Foundation
IBM defines an SBOM as a machine-readable inventory of software components, libraries, modules, and dependencies. It helps organizations understand the software in their products and systems. With increased regulatory requirements and supply chain concerns, broader adoption of SBOM practices is evident across sectors. However, challenges arise when supplier files arrive in different formats and with varying levels of detail, making reconciliation at the product level difficult.
Time-Sensitive Vulnerability Reporting
The CRA’s September 11 deadline for vulnerability notifications becomes a challenge when organizations cannot quickly establish which software is present in their products or when a vulnerability was first discovered. Changes in software composition through releases, patches, dependency updates, or new components can alter the SBOM’s accuracy.
The Role of Source-Code Analysis
Aaron Branson, Chief Growth Officer at FossID, emphasizes the importance of reliability in SBOM information. For companies dealing with multiple suppliers, ensuring the accuracy and completeness of SBOMs is crucial. He suggests that source-code analysis provides the verification layer necessary to transform SBOM documents into reliable supply chain intelligence.
According to Branson, "An SBOM is only as useful as the confidence an organization can place in the information inside it…" With FossID’s focus on source-code intelligence and software supply chain transparency, they aim to address these challenges and enhance visibility in the face of evolving regulatory demands.