CRA who is responsible for vulnerabilities and SBOM?

CRA: Which obligations for vulnerability handling and SBOM apply to manufacturers, importers and distributors? Explained with a mechanical engineering example and diagram.

This article places the CRA roles along the supply chain and focuses on what causes the most friction in practice: the relationship between supplier and manufacturer.

A complete overview of all manufacturer obligations can be found on the CRA main page.

The CRA distinguishes economic operators by their position in the supply chain. The manufacturer bears the largest set of obligations. Importers and distributors mainly have inspection and reporting duties.

Task Manufacturer Importer Distributor
Create software bill of materials (SBOM) yes no no
Remediate vulnerabilities and provide updates yes no no
Check conformity (CE, documentation) prepares it checks before placing on the market checks when making available
On knowledge of a vulnerability treats and reports informs the manufacturer informs the manufacturer
Report to authorities for actively exploited vulnerability yes no (informs manufacturer) no (informs manufacturer)

The manufacturer carries the substantive obligations for vulnerability handling and for the SBOM. The importer checks, before placing on the market, among other things the CE marking, technical documentation and conformity assessment and informs the manufacturer immediately if it becomes aware of a vulnerability. The distributor checks the CE marking and the manufacturer obligations and also reports a vulnerability it knows about to the manufacturer.

Important for the supply chain: Whoever places a product on the market under their own name or brand or substantially modifies it is considered the manufacturer and is subject to the full set of manufacturer obligations. This equivalence often affects mechanical engineering — more on that below.

What an SBOM under the CRA is

A software bill of materials (SBOM) is an inventory of the software components of a product. The CRA requires the manufacturer to identify and document vulnerabilities and components, among other things via an SBOM in a common machine-readable format. The statutory minimum depth is limited: the SBOM must show “at least the top-level dependencies.” The law does not require a comprehensive deep analysis down to the last transitive dependency at this point.

The SBOM is not a public document. The manufacturer is not required to publish it, but must present it upon justified request by the market surveillance authority. There is also no obligation to hand over the SBOM to the user. The information duties only require indicating where the SBOM is available, if the manufacturer provides it.

Thus the SBOM is primarily an internal tool. This is exactly where the supply chain question begins: if you integrate third-party components, how do you know what they contain?

When an internal component itself falls under the CRA

The CRA defines a product with digital elements as a hardware or software product including components that are placed on the market separately. The decisive attribute in the regulation is therefore separate placement on the market.

It follows that: a controller available on the open market is itself a CRA product of its manufacturer. It is marketed independently, so the controller manufacturer bears the manufacturer obligations. If, on the other hand, a component is only installed in your machine and is not offered separately on the market, it is not a standalone product with digital elements. The machine is then placed on the market, and the manufacturer obligations apply to it including that component.

In practice this means: if you buy a controller that is available on the market, it is an independent CRA product with its own manufacturer. As soon as you integrate it into your machine, it becomes an integrated third-party component for you, for which special due diligence obligations apply.

Which evidence and which SBOM you need from your suppliers

This is the core of the supplier relationship. Whoever integrates third-party components must exercise due diligence so that these components do not impair the cybersecurity of the overall product. This explicitly also applies to free and open-source software.

What “due diligence” specifically means is clarified by recital 34 of the CRA. Among the measures listed as suitable are: check the conformity of the component (including CE marking, where the CRA applies), ensure that the component receives regular security updates, consult relevant vulnerability databases, or perform additional security tests.

The European Commission’s guidelines on applying the Cyber Resilience Act are not binding on economic operators; only the Court of Justice of the European Union can interpret the CRA bindingly. The guidelines describe two complementary duties: the risk assessment for the overall product and the due-diligence check for integrated third-party components. For conformity, integrated third-party components are treated like external inputs whose properties the manufacturer must verify by due-diligence checks when integrating them. The manufacturer cannot redevelop third-party components, so they must verify that these components deliver what their product needs. As evidence, the guidelines mention, for example, technical specifications, security documentation or conformity and assurance documents of the component manufacturer, supplemented where appropriate by their own functional tests.

If the manufacturer finds a vulnerability in an integrated component, they report it to the person or entity that manufactures or maintains that component and remediate it according to the CRA requirements. If they develop a fix themselves, they share the code or the documentation with the component maintainer, preferably in a machine-readable format.

Should you request an SBOM from your suppliers?

The CRA obliges every manufacturer to create an SBOM for its own product. There is no explicit requirement that says “demand an SBOM from your supplier.” However, it is a justified practical recommendation to do exactly that. The rationale is clear: recital 34 requires knowing and verifying the properties of integrated components, and the guidelines explicitly list documentation from the component manufacturer as suitable evidence. A supplier’s SBOM is precisely such documentation. It makes visible which components are contained in the purchased item and makes vulnerability database checks easier for you.

The VDMA document series on supply chain security goes in the same direction: supplier self-disclosures, clear minimum requirements in the specification and contractual coverage of these points are recommended. If a supplier provides conformity assessments for its component, the machine builder can assume a documented presumption of conformity for that component. That does not relieve them of the due-diligence check for the overall product, but it reduces the effort for the individual component.

Where do you stand on SBOM and supplier management?

The CRA readiness check shows you in a few minutes which processes you already cover and where the biggest gaps are.

Mechanical engineering example the machine is the product not the controller

Take a machine builder who integrates a purchased controller into their system. For the CRA, the machine is a product with digital elements that in turn consists of subproducts that are also affected by the CRA. Whoever places the finished product on the market under their own name or brand is considered the manufacturer and bears the full manufacturer obligations for the machine. The CRA requires the manufacturer to ensure vulnerabilities are addressed during the support period, and that applies to the product including its components.

For the operator this means: the machine builder is responsible for vulnerabilities and updates for the entire machine, regardless of which controller is installed. The operator should not have to see the inner workings. For them it is the machine of a manufacturer, and that single manufacturer is their contact.

The hardware analogy makes this clear: a manufacturer such as Siemens or ABB also does not go to replace a defective controller directly in the delivered machine. The machine builder does this as part of their responsibility for the machine. The same logic applies to software updates and vulnerability handling. The component manufacturer supplies updates for its component to you. What reaches the operator is your responsibility as the machine manufacturer.

For machines, the Machinery Regulation (MVR, Regulation (EU) 2023/1230) also comes into play. It requires, among other things, that a machine be protected against tampering and that the software installed for safe operation remains identifiable. Machines can therefore fall under both the CRA and the MVR. How the two legal acts interlock is treated separately under CRA and machinery regulation.

What you should do now as a machine builder

Supplier management is central. The following steps are an actionable practical recommendation, derived from the obligations mentioned:

  • Clarify your own role under the CRA. Whoever integrates and places a product on the market under their own name or brand is usually the manufacturer within the meaning of the CRA.
  • Request conformity evidence (including CE, where the CRA applies) and the components’ SBOMs from your suppliers. Secure these requirements contractually.
  • Build your own SBOM for your machine that at least maps the top-level dependencies.
  • Establish a process for vulnerability handling and update provision, including a reporting channel to the component maintainers.
  • Prepare the reporting channels for actively exploited vulnerabilities so that you can meet the statutory deadlines.

If you implement these five points properly, you will cover the bulk of the CRA supply chain requirements and can demonstrate to the operator and the market surveillance authority that responsibility for the entire machine rests with a single party: you.

Tackle CRA implementation in mechanical engineering

Secuvise supports machine builders from role clarification through SBOM construction to CE conformity. Contact us with specifics about your products.