ForgeCRA writing
Notes on the CRA and supplier evidence.
What the Cyber Resilience Act actually requires, what makes an SBOM usable, and why supplier evidence is a cross-company problem.
All posts
01
2026-08-13
Full CRA obligations are still 2027 — start the supplier work anyway
Reporting obligations begin September 2026 and are event-triggered. The expensive problem sits under the December 2027 date and continues after it.
2026-07-16
Publish once, or fill in five portals
Suppliers are about to be asked for SBOMs by every manufacturer they sell into, each with its own format, portal and idea of complete. That does not scale on either side.
2026-06-18
Why the hard part of CRA is not generating an SBOM
Binary analysis turns a firmware image into an SBOM, and does it well. It cannot make a reluctant supplier send you better data next month, and it cannot produce an attestation that the supplier stands behind.