Regulatory context
CRA, SOC 2, ISO 27001, and the license disclosure gap
Security and product-compliance programs rarely produce maintained third-party license disclosure on their own.
Last updated: July 2, 2026
Regulatory topics
CRA, security certifications, SBOM programs, and the license disclosure gap that remains.
- Cyber Resilience ActCRA component documentation vs. the maintained license disclosure diligence still expects.Read CRA guide
- SOC 2 & ISO 27001Security certification gaps, and missing maintained third-party license disclosure.Read SOC 2 / ISO guide
- SBOM vs. license pageWhy a component list is not the same as reviewed license disclosure.Compare SBOM and disclosure
- Vendor questionnairesAnswering license sections in security and procurement questionnaires.Read questionnaire guide
Common questions
Does CRA compliance mean we have a license page?
Not necessarily. CRA focuses on product security and component documentation. License notice and full text are separate duties that procurement still asks for.
We passed SOC 2. Do we still need license disclosure?
Often yes. Security certification and third-party license pages answer different questionnaire sections.
Is an SBOM enough for procurement?
Usually no. Questionnaires ask for reviewed disclosure with full license text, not just component identifiers.
Continue reading
Related topics
One idea per page: Follow the path that matches your next question.