<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">
CRA SBOM ESCROW

SBOM escrow for CRA-ready records.

The CRA now demands a software component inventory as a compliance record, or you face regulatory penalties. Codekeeper’s SBOM escrow generates your software bill of materials, keeps it current alongside your escrowed assets, and verifies it is complete.

Machine-readable, verified, and retained for ten years.
By December 11, 2027 you must hold a current, machine-readable SBOM for ten years, or face fines. Codekeeper's SBOM Escrow is built from your escrow deposit and keeps it current as your product evolves, so you're never in danger of misrepresenting information in an audit.
badge-cra CRA
solutions_badge_dora DORA
badge-nis2 NIS2
badge-iso-27001-v2 ISO 27001
solutions-ffiec FFIEC
One SBOM that satisfies the component-inventory requirements of the CRA, NIS2, DORA, and more.
The old way

An outdated SBOM is a CRA compliance liability.

Usually you generate an SBOM and store it until someone asks to see it. But development isn't static. Every release adds code and dependencies, leaving it outdated. Regulators saw that gap, so the CRA now demands 24 hours to flag an exploited vulnerability, 72 hours to detail it, and14 days after a fix is available to file the final report.

Those windows are tight. A stale SBOM can’t trace what was exploited in time. A missed report or incomplete SBOM breaches an essential CRA requirement —carrying fines up to €15 million or 2.5% of turnover, plus €5 million for inaccurate information.

The SBOM on file
sbom-v3.1.json PDF
Signed · 14 Mar 2024
Not tested
Generated once, never regenerated — so it no longer matches what you ship.
cra-sbom-escrow-team-meeting-800
Why we built it

Don’t be caught with an incomplete SBOM.

Codekeeper has spent over a decade running software escrow, storing and rebuilding entire development environments. It has shown us exactly which components a recovery, and an SBOM, needs. Trust us to turn your SBOM into a complete, verified record of your software for CRA compliance.
10+
years managing escrow
3 500+
companies protected
ISO 27001
certified
24 hrs
to go live

Everything the CRA needs from your SBOM, in one place

Each capability closes a gap a generation tool leaves open. Together, they make up the complete, current SBOM the CRA calls for.

Stored with your code

Your SBOM is kept in the same vault as the source code, build instructions, and configurations it describes, so you meet the CRA’s resilience and retention duties in one place.

Synced with your repository

Codekeeper integrates with your repository to generate your SBOM and regenerate it on a schedule, so the inventory stays up to date with every release.

Verified against a rebuild

Verification rebuilds can surface missing critical components that file-based SBOM generators overlook.

Delivered in a CRA-accepted format

Codekeeper generates your SBOM in a commonly used, machine-readable format, the standard a market surveillance authority requires.

Ten-year retention, tamper-proof

Your SBOM stays in an immutable, timestamped vault for the full CRA retention window under Article 13(13).

A Software Resilience Certificate

Codekeeper issues a Software Resilience Certificate as proof that every critical component a recovery needs is documented.

How it works

How SBOM escrow works.

Setup is live in 24 hours. From there, your SBOM custody is kept accurate and current to aid with CRA retention and reporting compliance.

Connected sources 50+ integrations
GitHub
Bitbucket
AWS
Microsoft Azure
Google Cloud
Stripe

1. Connect your repositories and cloud platforms.

Point Codekeeper at the repositories and cloud platforms where your code and dependencies live, across 50+ integrations.

SBOM generation
Scheduled · weekly · last run today
Verified
Component inventory · 1,284 CycloneDX
openssl 3.2.1 OK
log4j-core 2.24.3 NEW
libcurl 8.9.1 OK
zlib 1.3.1 OK
Rebuild check · inventory complete

2. We automate and verify your SBOM.

Codekeeper updates your SBOM on a regular schedule, verifies the inventory is complete and accurate, and stores it with your escrow deposits.

Certified tier seal
Codekeeper Software Resilience Certificate
ProviderAcme Cloud Ltd
TierCertified
Recovery testPassed · 14 Jun 2026
Valid to14 Jun 2027
Authorized · Codekeeper
Verified

3. Produce your CRA evidence on demand.

Download your current SBOM and its Software Resilience Certificate whenever a customer, auditor, or authority asks.

Set up in a day. From there, the pack stays current on its own.

Book a demo

These companies’ systems are protected, compliant, and resilient.

They made the decision. They built their resilience. They have peace of mind. You can too.
icon-google
icon-g2
“We’ve had a great experience with CodeKeeper. The setup process was smooth, and the team made everything very straightforward. Knowing our critical software assets are securely protected gives us real peace of mind. Their support has been responsive and professional, and the overall service has been reliable and easy to work with. Highly recommended.”
testimonial-circle-j

Jordan Adler

“We worked with Codekeeper as our escrow provider for major enterprise deployments and found them to be extremely professional, responsive, and flexible throughout.
I'd highly recommend Codekeeper. They clearly understand the realities of working with growing tech businesses and enterprise customers alike.”
testimonial-circle-r

Ross Kilshaw

I found Codekeeper's solution excellent for what I need. I scheduled a demo to better understand the possibilities. Very easy! It was a clear and straightforward meeting, focused exactly on what I needed. Excellent service!
testimonial-circle-t

Thiago Mendes

Airbus partner logo in muted style
Bayer partner logo in muted style
EU Parliament partner logo in muted style
General Motors partner logo in muted style
Intuit partner logo in muted style
Nestle partner logo in muted style
Pepsico partner logo in muted style
Pfizer partner logo in muted style
Framework mapping

One SBOM deposit for every framework that requires a component inventory.

An SBOM is your evidence of what your software is built from: every component, library, and dependency, traceable to a version — the same asset-inventory evidence other frameworks demand. Compile it once, reuse it everywhere you are held to a component-inventory standard.
badge-cra
CRA — Annex I, Part II A machine-readable SBOM of your components, kept current and retained.
solutions-dora
DORA — Art. 8 & Art. 28 ICT asset inventory and the register of third-party contractual arrangements.
badge-nis2
NIS2 — Art. 21(2)(d) Supply-chain security evidence across your software suppliers.
badge-iso-27001-v2
ISO 27001 — A.5.9 An inventory of information and associated assets, kept current.
solutions-ffiec
FFIEC — IT Handbook An IT asset inventory of systems and components examiners expect to see.
Buying software instead of building it? Requiring an SBOM in escrow from your critical suppliers turns a one-time request into a maintained control your auditor can inspect.
What's at stake

An incomplete SBOM is the gap a regulator is trained to spot.

Without it (just a stored file)

  • A missing SBOM breaches an essential CRA requirement, carrying fines up to €15M or 2.5% of annual turnover.
  • An incomplete or misleading SBOM given to an authority adds a separate penalty of up to €5M or 1% of annual turnover.
  • Authorities can order corrective action, withdraw the product, recall units already sold, or bar it from the EU market.
  • A stale SBOM can't trace an exploit to its version, so you can't meet the CRA's 24-hour, 72-hour, and 14-day reporting deadlines.
CE marking — a product with digital elements cannot carry it, or sell in the EU, without complete technical documentation behind the conformity assessment. An incomplete SBOM puts the marking, and the sale, at risk.

With SBOM escrow

  • Your SBOM meets the CRA documentation requirement, kept current and retained across the full ten-year window for you.
  • A verified rebuild catches missing components early, before a recovery or an audit reaches them.
  • A current, version-tied SBOM lets you trace an exploited component fast and file inside the reporting windows.
  • Your SBOM and source code share one immutable vault, safe from a breach, ransomware, or corruption on your own systems.
Sample

Page through a real SBOM deposit report.

Take a look at the component inventory and rebuild result, laid out the way a market surveillance authority receives them. It is the fastest way to see what a complete, verified SBOM looks like.
Component inventory
Verification result
Certified tier seal
Codekeeper Software Resilience Report
ProductAcme Cloud Ltd
TierCertified
SBOM verifiedComplete · 14 Jun 2026
Components1,284 · CycloneDX
Authorized · Codekeeper
Verified
Get the sample Software Resilience Report

We’ll email the sample SBOM deposit report to you.

Get your SBOM CRA-ready before the reporting clock starts.

When an exploited vulnerability triggers the CRA’s reporting deadlines, a current SBOM is what lets you trace the affected components and file in time. Codekeeper builds and verifies that SBOM inside your escrow deposit — have it in place before an incident tests it.

Frequently asked questions

What is SBOM escrow?
SBOM escrow is the secure, versioned storage of an SBOM with an independent third party, kept current and verified so a manufacturer can prove the SBOM is complete and recoverable. Codekeeper stores your SBOM in the same encrypted vault as the source code it describes, regenerates it on a schedule, and rebuilds the software to confirm the inventory is complete.
Does the Cyber Resilience Act require an SBOM?
Yes. The CRA SBOM requirements are set out in Annex I, Part II, point 1: you must draw up an SBOM in a commonly used, machine-readable format covering at least the top-level dependencies. The SBOM requirement applies from December 11, 2027, while vulnerability and incident reporting obligations apply earlier, from September 11, 2026.
What format does the CRA require for an SBOM?
The CRA requires an SBOM in a commonly used, machine-readable format, and does not name a specific standard. A PDF or spreadsheet does not meet the machine-readable requirement. Codekeeper generates your SBOM in a machine-readable format covering your top-level and transitive dependencies, the standard a market surveillance authority accepts.
Does the CRA SBOM have to be public?
No. The CRA does not require a manufacturer to publish the SBOM. Your SBOM forms part of your technical documentation and is provided to a market surveillance authority on a reasoned request, which is why secure, access-controlled custody matters more than publication.
How long must an SBOM be kept under the CRA?
Under the CRA, a manufacturer must retain technical documentation, including the SBOM it contains, for at least ten years after a product is placed on the market, or for the support period if that is longer (Article 13(13)). Codekeeper’s immutable vault covers the full retention window and holds a timestamped record of every deposit.
How is SBOM escrow different from an SBOM generation tool?
A generation tool produces the file, while SBOM escrow does that and keeps your SBOM current, tests it against a rebuild, retains it for the required period, and stores it with the source code it describes. Most manufacturers need both: a generation step to create the SBOM, and custody to keep it accurate, provable, and recoverable.
Can Codekeeper generate an SBOM for me?
Yes. Since generation runs on the same integrations that power your escrow deposit automation, Codekeeper can generate your SBOM from the repositories and cloud platforms you've connected in escrow, then regenerate it on a schedule to keep the inventory current.
Which regulations does SBOM escrow support?
SBOM escrow supports the CRA most directly, where a machine-readable SBOM is a stated requirement. The same record provides the component evidence other frameworks call for: NIS2 supply-chain security, the ICT asset inventory and third-party register under DORA, the asset inventory under ISO 27001, and the IT asset inventory FFIEC examiners expect.
Is SBOM escrow useful if I am the software buyer, not the manufacturer?
Yes. NIS2 and DORA make you accountable for the security of your suppliers and the ICT third parties your operations depend on. A supplier’s verified SBOM, held in escrow, gives you standing supply-chain evidence rather than a document you have to chase.
What happens if my SBOM is incomplete or inaccurate under the CRA?
An incomplete or inaccurate SBOM fails an essential requirement, which carries the top penalty tier of up to €15 million or 2.5% of worldwide annual turnover. Providing incorrect or misleading information to a market surveillance authority carries a further penalty of up to €5 million or 1%. A verification rebuild catches an incomplete SBOM early, so you correct the deposit before a regulator reviews it.