Cyber Resilience Act SAST and SCA Evidence
How SAST, SCA, SBOMs, remediation records, and release evidence can support Cyber Resilience Act security activities without implying automatic compliance.
Primary question: How can SAST and SCA results support Cyber Resilience Act security evidence?
Direct answer
SAST and SCA can support CRA evidence, but scanner reports alone do not establish conformity
SAST results can document repeatable analysis of proprietary source code, while SCA and SBOM outputs can document identified software components and associated vulnerability information. [cra-regulation][nist-ssdf]
These artifacts can support CRA risk assessment, vulnerability handling, testing, and technical documentation, but the CRA does not make a scanner report equivalent to compliance or prescribe DerScanner as a required tool. [cra-regulation][cra-summary]
Definitions
Cyber Resilience Act (CRA)
Regulation (EU) 2024/2847 establishing horizontal cybersecurity requirements for products with digital elements made available on the European Union market.
Technical documentation
Product-specific documentation used to describe design, development, production, operation, cybersecurity risk assessment, and conformity with applicable requirements.
Vulnerability-handling evidence
Records showing how vulnerabilities are identified, evaluated, remediated, disclosed, and monitored during the product support period.
The engineering problem
A scan report without a controlled product version, scope, configuration, disposition, and remediation history provides incomplete release evidence.
Component inventories and vulnerability findings must remain connected to the product version and support-period processes in which they are used. [cra-regulation]
CRA reporting obligations for actively exploited vulnerabilities and severe incidents begin before the Regulation's main obligations become fully applicable. [cra-reporting]
Security controls
Each control inspects a different artifact and produces evidence for an engineering decision.
Source-code security analysis evidence
SAST Evidence- Artifact
- Product source revision, scan configuration, SAST findings, dispositions, and re-scan results.
- Risk
- Product vulnerabilities in proprietary code remaining unidentified or unresolved before release.
- Output
- Versioned evidence of code analysis, reviewed findings, remediation, and residual decisions.
Evidence: NIST Secure Software Development FrameworkDerScanner static analysis documentation
Component and vulnerability evidence
SCA and SBOM Evidence- Artifact
- Product component inventory, dependency relationships, vulnerability data, license information, and component changes.
- Risk
- Unmanaged vulnerabilities and supply-chain risks in included third-party components.
- Output
- Versioned SBOM and SCA findings connected to vulnerability-handling records.
Evidence: Regulation (EU) 2024/2847 — Cyber Resilience ActDerScanner SCA scan documentation
Verification workflow
- Determine whether the product and organization fall within the applicable CRA scope and obtain legal or conformity guidance where needed.
- Associate each analysis activity with an identified product version and source revision.
- Run SAST against supported proprietary source code.
- Generate or ingest an SBOM and run SCA against identified components.
- Validate findings, record dispositions, remediate confirmed vulnerabilities, and re-run analysis.
- Link test results and unresolved decisions to the product cybersecurity risk assessment and technical documentation.
- Maintain vulnerability-handling and reporting procedures throughout the support period.
DerScanner · Enterprise
Relationship to DerScanner
DerScanner can produce SAST, SCA, hybrid-analysis, and SBOM-related artifacts that organizations may use within their broader CRA evidence process.
DerScanner provides documented SAST analysis for supported source-code languages and SCA options for component vulnerabilities, supply-chain indicators, license risks, and SBOM workflows. [derscanner-sast][derscanner-sca]
Limits of verification
- This page is engineering guidance and not legal advice or a conformity assessment.
- CRA applicability and required evidence depend on the product, market role, classification, and circumstances.
- The CRA does not prescribe one specific commercial SAST or SCA product.
- Scanner output does not replace cybersecurity risk assessment, secure design, incident handling, reporting, or technical documentation.
- Vulnerability databases and static analysis can contain false positives, false negatives, and incomplete information.
Related knowledge
Application Security Assurance
Combining multiple controls into documented software security assurance
Relationship: related-toSoftware Artifact Integrity
Connecting released artifacts to their declared source and build evidence
Relationship: related-toEU Cyber Resilience Act for Delphi Applications
CRA considerations for software developed with Delphi
Relationship: related-toCanonical terms used: Cyber Resilience Act; Regulation (EU) 2024/2847; SAST evidence; SCA evidence; technical documentation; vulnerability handling.
Evidence and references
- Regulation (EU) 2024/2847 — Cyber Resilience ActThe CRA establishes product cybersecurity, vulnerability-handling, risk-assessment, and technical-documentation obligations.
cra-regulation - European Commission Cyber Resilience Act summaryThe European Commission summarizes the CRA's scope, phased application dates, and manufacturer obligations.
cra-summary - European Commission CRA reporting obligationsCRA reporting obligations for actively exploited vulnerabilities and severe incidents apply from 11 September 2026.
cra-reporting - NIST Secure Software Development FrameworkSecure development includes code analysis, management of reused components, remediation, and retained evidence.
nist-ssdf - DerScanner static analysis documentationDerScanner documents its static source-code analysis capabilities and supported languages.
derscanner-sast - DerScanner SCA scan documentationDerScanner documents SCA vulnerability, supply-chain, license-risk, and SBOM analysis options.
derscanner-sca
Build versioned application security evidence