Press Releases
>
ONEKEY Report: SBOM Is a Key Foundation for CRA Compliance

ONEKEY Report: SBOM Is a Key Foundation for CRA Compliance

ONEKEY Report: SBOM Is a Key Foundation for CRA Compliance
Tanja Sommer
Tanja Sommer
TablE of contents

READY TO UPGRADE YOUR RISK MANAGEMENT?

Make cybersecurity and compliance efficient and effective with ONEKEY.

See it in Action
  • ‍CEO Jan Wendenburg: “German industry is on the right track when it comes to the Cyber Resilience Act, but there is still work to be done on implementation.”
  • “As AI is increasingly used in cyberattacks, industrial machinery and equipment could become a growing target.”

Düsseldorf, October 7, 2026 — The software bill of materials (SBOM), essentially a parts list for software, is a key tool for vulnerability management and helps manufacturers meet the requirements of the EU Cyber Resilience Act (CRA). That is one of the central findings of the new “IoT & OT Cybersecurity Report 2026,” published by Düsseldorf-based cybersecurity company ONEKEY. The report is based on a survey of 200 German industrial companies.

An SBOM provides transparency into which software components and dependencies a digital device contains. When a vulnerability is discovered, manufacturers can use it to quickly determine which product versions are affected, what risks exist, and where an update is needed. It also provides an essential foundation for the vulnerability handling and technical documentation required under the CRA.

“A complete and up-to-date software bill of materials is an essential foundation for manufacturers of products with digital components to meet the requirements of the Cyber Resilience Act,” said Jan Wendenburg, CEO of ONEKEY.

Billions of Connected Devices Affected

The regulation covers an extremely broad range of hardware and software products with digital elements, from connected devices and machines to industrial control systems and software. Under the EU Cyber Resilience Act, the software used in these products must be fully inventoried and checked for potential vulnerabilities that could serve as entry points for cyberattacks. Product units already in use are generally grandfathered even without CRA compliance, provided they are not substantially modified. However, as of December 11 next year, no new digital products that fail to meet CRA requirements may be placed on the market in the European Union. As of this fall, manufacturers are also required to report actively exploited vulnerabilities and serious security incidents. In Germany alone, industry estimates suggest that the regulation affects tens of thousands of manufacturers, importers, and distributors of devices, machines, and equipment with digital components.

Yet, as the “IoT & OT Cybersecurity Report 2026” shows, SBOMs are not yet widely established in practice. According to the survey, only 18 percent of industrial companies have already created an SBOM for all of their affected products. Another 39 percent have at least partially inventoried the software used in their devices, machines, and equipment. Nearly a quarter (24 percent) said they have not created an SBOM at all.

SBOMs Must Be Complete and Up to Date

But it is not just about having an SBOM — its quality and timeliness matter just as much. The CRA requires an SBOM in a commonly used, machine-readable format that covers, at the very least, the product’s top-level dependencies. In addition, manufacturers must identify and document the vulnerabilities and components contained in their products. The ONEKEY survey also examined how far German industry has progressed in this regard — and the results show considerable room for improvement. Asked whether their SBOMs include the following components, 34 percent of respondents said yes for “programs,” 26 percent for “version numbers for unique identification,” 21 percent for “frameworks,” 18 percent for “libraries,” and 17 percent for “dependencies.” Supplementary information is also rather sparse: known vulnerabilities (13 percent), license information (30 percent), and authorship information (19 percent).

ONEKEY CEO Jan Wendenburg explains: “The biggest challenge with an SBOM is capturing all of the software components actually contained in a device in a way that is complete, unambiguous, and up to date. Many programs rely on numerous libraries, third-party components, and other dependencies that can change during development or through updates. On top of that, supplier information is often incomplete, and documentation formats vary. That is why an SBOM has to be re-verified for every product version and continuously updated. Otherwise, it quickly becomes outdated and can no longer reliably help identify affected products when new vulnerabilities are discovered.”

A complete overview of all software used in a company’s own products is therefore an essential prerequisite for CRA compliance — and clearly, there is still a lot of work to be done.

Share

About Onekey

ONEKEY is the leading European specialist in Product Cybersecurity & Compliance Management and part of the investment portfolio of PricewaterhouseCoopers Germany (PwC). The unique combination of the automated ONEKEY Product Cybersecurity & Compliance Platform (OCP) with expert knowledge and consulting services provides fast and comprehensive analysis, support, and management to improve product cybersecurity and compliance from product purchasing, design, development, production to end-of-life.

CONTACT:
Sara Fortmann

Senior Marketing Manager
sara.fortmann@onekey.com

euromarcom public relations GmbH
team@euromarcom.de

Make cybersecurity and compliance efficient and effective with ONEKEY.