Dependency Firewall offer: 50% off your base fee for 3 months + €100 usage credit.Start trialSee what’s new

CRA Compliance

The Cyber Resilience Act asks for an SBOM, vulnerability handling and a stated support period for products sold in the EU. Trust Repository keeps all three per release, for your own products and for the components you buy.

Orbit Desktop Agent: vulnerabilities and SBOM quality per release, and the 1.x end of support date.
Orbit Desktop Agent: vulnerabilities and SBOM quality per release, and the 1.x end of support date.

The CRA turns SBOMs into obligations

Reporting obligations have applied since September 11, 2026. The main obligations, including the software bill of materials, apply from December 11, 2027. Both cover the components you buy as well as your own code.

An SBOM for every supported release
You need the SBOM for each release you still support, and the supplier SBOMs behind it.
Vulnerability status per release
When a vulnerability is reported, you need to know which releases contain the component and whether it affects them.
A stated support period
Customers need end-of-support and end-of-security-fix dates they can plan around.
Many readers ask for the same evidence
Customers, auditors and market surveillance authorities all ask, each in their own format.

How it works with Trust Repository

  1. 1Upload the SBOM per release

    From CI/CD or by hand, in CycloneDX or SPDX. Supplier SBOMs sit next to yours.

  2. 2Record VEX on each finding

    State whether each vulnerability affects the product, why, and what you will do about it.

  3. 3Publish support dates

    End-of-life and end-of-support per version range, as ECMA-428 documents on your Trust Portal.

VEX with its history

Record a state, a justification and a response for each finding, and choose whether subscribers see it. A new assessment adds to the history. Published revisions do not change afterwards.

Adding a VEX analysis for CVE-2023-4863: state, justification, response and whether to publish it.
Adding a VEX analysis for CVE-2023-4863: state, justification, response and whether to publish it.

Support dates customers can read

Lifecycle events have an effective date, a version range and a note. Customers see them on the Trust Portal and download them as ECMA-428 files.

Orbit Desktop Agent on the Trust Portal: 1.x end of support on Oct 13, 2026 and end of life on Mar 27, 2027.
Orbit Desktop Agent on the Trust Portal: 1.x end of support on Oct 13, 2026 and end of life on Mar 27, 2027.

Who works with it

Product security teams
Keep SBOM, VEX and support dates for every release you still support.
Compliance and legal
Show what was published for each release, when, and who downloaded it.
Customer-facing teams
Answer SBOM requests and security questionnaires with a link to the Trust Portal.

Questions

When do the CRA obligations apply?

The CRA entered into force on December 10, 2024. Reporting obligations have applied since September 11, 2026. The main obligations, including the software bill of materials, apply from December 11, 2027. This is a summary, not legal advice.

Does Trust Repository cover components from our suppliers?

Yes. Suppliers publish their SBOM, VEX and assessments into their own space, and each SBOM is checked against known advisories when it arrives.

Which formats does Trust Repository support?

SBOM in CycloneDX and SPDX, VEX, and lifecycle metadata as ECMA-428. Trust Repository is compatible with the Transparency Exchange API (ECMA-TC54).

Which SBOM quality checks are included?

CISA minimum elements, BSI TR-03183-2 (the German technical guideline for SBOMs under the CRA) and SPDX license expressions. Each finding has a severity of low, medium or high.

Where does SBOM Observer fit?

SBOM Observer adds impact analysis across your own and supplier software, and your own policies in CI/CD. See the Regulatory Compliance use case.

Start with one supplier

In a demo we invite a supplier, publish a release and show what your customers download from the Trust Portal.

Book a demo
A Trust Portal product page with lifecycle events, releases and downloadable files