Independent information resource Product security · EU CRA
CRA software supply chain / 14

Software Provenance and CRA Compliance

How software provenance supports CRA component due diligence, SBOM accuracy, dependency trust, build integrity and vulnerability response.

IN BRIEF

A trustworthy dependency inventory needs more than package names. Provenance records should connect the component source, exact release or commit, retrieval channel, build or package artifact and the product release that used it.

01 / 08

Provenance Supports CRA Due Diligence

Article 13 requires due diligence for third-party components. Knowing the actual source and release of a dependency helps teams determine whether they assessed the same component that later entered the product build.

02 / 08

Record Where the Component Came From

Capture the repository, package registry, supplier or build source used to obtain the component. This reduces ambiguity where similarly named or unofficial packages exist.

03 / 08

Record Exact Version or Commit Identity

Version numbers, commit hashes or equivalent release identifiers help tie vulnerability and support information to the exact component included in the product.

04 / 08

Connect Source to Build Artifact

Where feasible, preserve the relationship between assessed source and the binary, package or firmware artifact used in the build. This is especially important for precompiled or supplier-generated components.

05 / 08

Use Integrity and Signature Evidence Where Available

Checksums, signatures and authenticated distribution channels can strengthen confidence that the retrieved component has not been substituted or altered unexpectedly. The appropriate mechanism depends on the ecosystem and risk.

06 / 08

Feed Provenance Into the SBOM

SBOM data becomes more useful when component identity is stable and traceable to a known source. Provenance data can help resolve duplicate or ambiguous packages and improve vulnerability matching.

07 / 08

Preserve Provenance Across Releases

Store component provenance with release records so historical product versions can be reconstructed even after upstream repositories or package locations change.

08 / 08

Treat Provenance as Supporting Evidence, Not Proof of Security

A well-provenanced component can still contain vulnerabilities. Provenance establishes origin and identity; security assessment, monitoring and remediation remain separate responsibilities.

REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.