Skip to main content

Regulatory context

CRA, SOC 2, ISO 27001, and the license disclosure gap

Security and product-compliance programs rarely produce maintained third-party license disclosure on their own.

Last updated: July 2, 2026

Common questions

Does CRA compliance mean we have a license page?

Not necessarily. CRA focuses on product security and component documentation. License notice and full text are separate duties that procurement still asks for.

We passed SOC 2. Do we still need license disclosure?

Often yes. Security certification and third-party license pages answer different questionnaire sections.

Is an SBOM enough for procurement?

Usually no. Questionnaires ask for reviewed disclosure with full license text, not just component identifiers.

Continue reading

Related topics

One idea per page: Follow the path that matches your next question.

Cookies on sourcetrust.dev

We use essential cookies for security, including abuse prevention on our site scan and walkthrough request form. With your permission, we also use optional analytics and diagnostics (Google Tag Manager on this site, and the Sentry browser SDK on the SourceTrust application when configured). See our cookie policy.