This is one of 4902 IT projects that we have successfully completed with our customers.
How can we support you?

Weißes Quadrat mit umrandeten Seiten rechts oben

Automated SBOM generation for compliance with the Cyber Resilience Act

This IT project is part of our digitalization and optimization of our customers’ IT landscape. Through targeted measures, we promote technological progress, optimize cross-system processes and create a sustainable basis for future developments. Our IT reference projects serve as a basis for orientation. They support the reusability of tried and tested concepts as part of project implementation.

Brief description

The Cyber Resilience Act (CRA, Regulation (EU) 2024/2847) requires manufacturers of products with digital elements to document the components contained in their products and to maintain a software bill of materials (SBOM). For a manufacturer of laboratory equipment, PTA analyzes the regulatory requirements and implements the automated generation of the SBOM for control software consisting of multiple installation packages. The SBOM is generated with every build in the pipeline, validated against the official schema, and provided as a readable overview. This gives the customer a constantly up-to-date and verifiable basis for vulnerability and license management, as well as for providing evidence to regulatory authorities and end customers. PTA handles the research, design, implementation, documentation, and coordination with the customer.

Supplement

CycloneDX 1.6 in JSON format is used as the SBOM format, supplemented by the specifications in BSI TR-03183-2. A PowerShell generator identifies the dependencies of the .NET projects (NuGet) and the Angular interfaces (npm). Tools based on Node.js consolidate the partial results and supplement them with manually maintained third-party software such as databases and runtime environments, curated license information, and SHA-512 checksums of the built files. They then validate the result against the official schema and generate an HTML view. Each of the twelve installation packages receives its own product SBOM. A parent system SBOM links these via BOM links. The individual steps are integrated into the setup and nightly pipelines in Azure DevOps as a reusable YAML template. A consolidation pipeline makes all SBOMs available as a single archive. The versions are automatically retrieved from the build, eliminating the need for manual maintenance. The implementation is AI-powered using Claude Code.

Subject description

The CRA requires manufacturers to document the components contained in their products in a standard, machine-readable format, to address vulnerabilities, and, starting in September 2026, to report vulnerabilities that are being actively exploited. The regulation will take full effect in December 2027. Implementation is based on research conducted exclusively from official sources (EUR-Lex, BSI, ENISA, CISA, and NIST). From this, a requirements matrix is created, and decisions regarding format, level of detail, and structure are derived. For each release, the SBOM shows which open-source and commercial components are included, along with their versions and licenses. It also identifies end-of-life runtime environments and unresolved licenses, which are resolved in collaboration with the customer. Presentation materials, demo instructions, and a rollout plan enable the customer to implement the process independently.

Customers who trust us

Have we sparked your interest ?

Portrait Herr Knudsen, Mann im Anzug

Ole Knudsen

Key Account Manager

Contact now

We provide information on the handling of the data collected here in our privacy policy.

Contact now

We provide information on the handling of the data collected here in our privacy policy.

Download file

We provide information on the handling of the data collected here in our privacy policy.