COTECNA GROUP WEBSITES
Cotecna is a leading provider of testing, inspection
and certification services. Discover our full range of
dedicated country websites and businesses.

NEWS

HOME/NEWS/News

CRA Mandatory Requirement | Non‑Standard SBOM Risks EU Detention & Heavy Fines

Many smart product manufacturers face the same pitfall in CRA compliance: using manual Excel, PDF or Word to list materials instead of formal SBOM, thinking that just organizing the tables and recording the version information is considered compliance. In fact, the EU regulation does not recognize such documents. Excel, PDF, and self-made tables all lack compliance validity and can only be used as internal reference materials. If it is found during verification that the SBOM format does not meet the standards, it will directly be judged as non-compliant and cannot pass CRA, potentially leading to fines, product removal, seizure of goods, and other multiple losses.

 

Hard requirements for compliant SBOM format

CRA clearly stipulates that the software bill of materials (SBOM) for products with digital elements must adopt machine-readable format, such as SPDX, CycloneDX. Excel, PDF, and self-made tables can only be used as internal references and cannot be used as official compliance materials.

Self-made tables often have problems such as component omissions, incomplete version information, and ambiguous dependency relationships, and cannot connect with the EU's automated vulnerability verification system.

 

Core information of qualified SBOM

The SBOM must at least cover the top-level dependencies relationships of the product, track the components and their vulnerabilities, and update the SBOM synchronously with each firmware iteration to ensure consistency with the delivered version. All files should be retained for at least 10 years for future reference.

 

Practical consequences of non-compliant SBOM

  1.  Severe-level violation: maximum fine of 15 million euros or 2.5% of global revenue (whichever is higher);
  2.  Product delisting on Amazon Europe Marketplaces, with disrupted peak-season orders;
  3.  Failed customs clearance: full-container detention plus high storage and return-shipping costs;
  4.  Lack of rapid traceability for vulnerabilities, failing to meet the mandatory 24-hour CSIRT/ENISA reporting requirements effective September 2026.

 

Services that Toby Testing Provides

Automatically generate SBOM, provide SaaS cloud services to complete automated vulnerability reporting, fulfill reporting obligations, save enterprise-related human resources and time, and facilitate product compliance.

 

Toby Testing holds A2LA accreditation and EN 18031 qualification, delivering authoritative cybersecurity testing and technical support aligned with standard requirements to facilitate market access into the EU.

 

During the window period when the 2027 regulations will be fully implemented, SBOM is the basic entry requirement for CRA. Early deployment will be more conducive to subsequent planning and review.

 

For SBOM preparation, compliance assessment, or related inquiries, please contact Toby.

 

 

About Toby Testing
Toby Testing is a third-party testing company with CMA and ISO 17025 accreditations from CNAS and A2LA. Operating two laboratories in Shenzhen, China, Toby specializes in electronic and electrical (E&E) product safety, EMC, wireless, chemical, and physical testing and certification. With advanced facilities and expert staff, Toby delivers global market access solutions, enabling clients to expand into international markets.