SBOM and Vulnerability Scanning: What the EU Cyber Resilience Act Means for Your Dependencies
Starting September 2026, the EU Cyber Resilience Act requires vulnerability and incident reporting for software sold in Europe. By December 2027, you'll need a machine-readable Software Bill of Materials. If your software has open-source dependencies — and it does — this directly affects you.