sbom-cra-checker

Validate SBOMs against EU Cyber Resilience Act requirements and ENISA reporting standards.

3|2|Updated Jan 23, 2026
One-click install
npx skills add https://github.com/robotijn/ctoc --skill sbom-cra-checker
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: sbom-cra-checker
Source: https://github.com/robotijn/ctoc/tree/main/skills/compliance/sbom-cra-checker
Command: npx skills add https://github.com/robotijn/ctoc --skill sbom-cra-checker

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill eliminates the risk of costly non-compliance with the EU Cyber Resilience Act (CRA) caused by invalid, unsigned, or poorly retained SBOMs, which can trigger fines of up to €15 million or 2.5% of global annual turnover for manufacturers of products with digital elements sold in the EU market.

Core Features & Use Cases

  • Regulatory Compliance Validation: Checks SBOMs against NTIA minimum elements, CRA requirements, and ENISA Single Reporting Platform (SRP) wiring rules.
  • Pipeline and Process Auditing: Verifies SBOM signing, build provenance, 10-year retention policies, and end-to-end vulnerability reporting runbooks.
  • Use Case: A SaaS company preparing for the 2026 CRA reporting deadline can use this skill to audit their release pipeline, confirm every shipped artifact has a compliant signed SBOM, and validate their 24-hour CRA notification runbook before market surveillance audits.

Quick Start

Use the sbom-cra-checker skill to audit your project's SBOMs and CRA vulnerability reporting processes for EU regulatory compliance.

Frequently Asked Questions about sbom-cra-checker

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I check if my SBOM meets EU Cyber Resilience Act requirements?

Auditing your SBOM for EU Cyber Resilience Act compliance involves validating it against NTIA minimum elements, verifying build provenance, and confirming SBOM signing. This process ensures your software bill of materials meets regulatory standards for vulnerability reporting.

What is needed for CRA compliance regarding vulnerability reporting and the ENISA SRP?

CRA compliance for vulnerability reporting requires a complete notification runbook wired to the ENISA Single Reporting Platform (SRP). You must validate this 24-hour reporting process alongside your SBOM retention policies before market surveillance audits.

How do I validate SBOM signing and build provenance for a release pipeline?

Validating SBOM signing and build provenance in a release pipeline requires checking that every shipped artifact has a compliant, signed software bill of materials. This pre-deployment audit verifies your supply chain security meets CRA standards.

Does my SaaS company need a 10-year SBOM retention policy for EU market compliance?

Yes, a 10-year SBOM retention policy is required for EU market compliance under the Cyber Resilience Act. You must verify your release pipeline enforces this retention rule for all shipped artifacts with digital elements to avoid non-compliance penalties.

What happens if my software bill of materials is missing NTIA minimum elements?

If your software bill of materials is missing NTIA minimum elements, it fails EU Cyber Resilience Act compliance validation. This invalid SBOM exposes your products to supply chain security risks and potential regulatory fines during market audits.