OSS, SBOM & vulnerability management
From SBOM creation and OSS governance to vulnerability management and audit-ready documentation, BearingPoint helps manufacturers meet Cyber Resilience Act requirements with confidence.
The EU Cyber Resilience Act (CRA) introduces mandatory cybersecurity requirements for all products with digital elements placed on the European market. This includes software components,whether proprietary or open source,used in commercial products.
Non-compliance can lead to severe penalties (up to €15M or 2.5% of global turnover) and removal of products from the market. With enforcement starting in September 2026, now is the time to prepare. Enforcement begins September 2026. Full compliance required by December 2027.
The CRA applies to a broad range of organizations involved in creating, distributing, or maintaining products with digital components.
The Cyber Resilience Act (Regulation (EU) 2024/2847) is a mandatory EU regulation setting cybersecurity standards for products with "digital elements" (software and hardware). It requires manufacturers to ensure products are secure-by-design and maintainable throughout their lifecycle.
While the Act entered into force in December 2024, the timelines are staggered:
BearingPoint offers Outcome-as-a-Service, meaning we don't just provide a tool for you to manage. Our experts take end-to-end responsibility for delivering audit-ready documentation, managing your Software Bill of Materials (SBOM), and ensuring regulatory conformity.
Under the CRA, manufacturers must demonstrate full visibility into their software supply chain. BearingPoint’s SBOM Management Services provide the foundational visibility needed to track thousands of open-source and third-party components, facilitating mandatory vulnerability reporting.
No, we are tool-agnostic. We use a curated combination of best-of-breed scanning technologies tailored to your specific codebase—whether source code or compiled binaries integrating directly into your existing infrastructure.
Failing to meet CRA requirements can lead to severe financial penalties up to €15 million or 2.5% of total global annual turnover, whichever is higher, and the potential removal of products from the EU market.
Yes. A core part of our CRA Compliance Services is Supplier Governance. We collect, verify, and risk-assess SBOMs from your suppliers, consolidating them into a single product SBOM to ensure your entire supply chain is compliant.
BearingPoint offers flexible engagement models, beginning with a CRA Readiness Assessment to identify gaps in your current security-by-design processes and technical documentation.