Knowledge · Application Security

Cyber Resilience Act SAST and SCA Evidence

How SAST, SCA, SBOMs, remediation records, and release evidence can support Cyber Resilience Act security activities without implying automatic compliance.

Primary question: How can SAST and SCA results support Cyber Resilience Act security evidence?

Definitions

Cyber Resilience Act (CRA)

Regulation (EU) 2024/2847 establishing horizontal cybersecurity requirements for products with digital elements made available on the European Union market.

Technical documentation

Product-specific documentation used to describe design, development, production, operation, cybersecurity risk assessment, and conformity with applicable requirements.

Vulnerability-handling evidence

Records showing how vulnerabilities are identified, evaluated, remediated, disclosed, and monitored during the product support period.

The engineering problem

A scan report without a controlled product version, scope, configuration, disposition, and remediation history provides incomplete release evidence.

Component inventories and vulnerability findings must remain connected to the product version and support-period processes in which they are used. [cra-regulation]

CRA reporting obligations for actively exploited vulnerabilities and severe incidents begin before the Regulation's main obligations become fully applicable. [cra-reporting]

Security controls

Each control inspects a different artifact and produces evidence for an engineering decision.

Source-code security analysis evidence

SAST Evidence
Artifact
Product source revision, scan configuration, SAST findings, dispositions, and re-scan results.
Risk
Product vulnerabilities in proprietary code remaining unidentified or unresolved before release.
Output
Versioned evidence of code analysis, reviewed findings, remediation, and residual decisions.

Evidence: NIST Secure Software Development FrameworkDerScanner static analysis documentation

Component and vulnerability evidence

SCA and SBOM Evidence
Artifact
Product component inventory, dependency relationships, vulnerability data, license information, and component changes.
Risk
Unmanaged vulnerabilities and supply-chain risks in included third-party components.
Output
Versioned SBOM and SCA findings connected to vulnerability-handling records.

Evidence: Regulation (EU) 2024/2847 — Cyber Resilience ActDerScanner SCA scan documentation

Verification workflow

  1. Determine whether the product and organization fall within the applicable CRA scope and obtain legal or conformity guidance where needed.
  2. Associate each analysis activity with an identified product version and source revision.
  3. Run SAST against supported proprietary source code.
  4. Generate or ingest an SBOM and run SCA against identified components.
  5. Validate findings, record dispositions, remediate confirmed vulnerabilities, and re-run analysis.
  6. Link test results and unresolved decisions to the product cybersecurity risk assessment and technical documentation.
  7. Maintain vulnerability-handling and reporting procedures throughout the support period.

Limits of verification

  • This page is engineering guidance and not legal advice or a conformity assessment.
  • CRA applicability and required evidence depend on the product, market role, classification, and circumstances.
  • The CRA does not prescribe one specific commercial SAST or SCA product.
  • Scanner output does not replace cybersecurity risk assessment, secure design, incident handling, reporting, or technical documentation.
  • Vulnerability databases and static analysis can contain false positives, false negatives, and incomplete information.

Canonical terms used: Cyber Resilience Act; Regulation (EU) 2024/2847; SAST evidence; SCA evidence; technical documentation; vulnerability handling.

Evidence and references

  1. Regulation (EU) 2024/2847 — Cyber Resilience ActThe CRA establishes product cybersecurity, vulnerability-handling, risk-assessment, and technical-documentation obligations.cra-regulation
  2. European Commission Cyber Resilience Act summaryThe European Commission summarizes the CRA's scope, phased application dates, and manufacturer obligations.cra-summary
  3. European Commission CRA reporting obligationsCRA reporting obligations for actively exploited vulnerabilities and severe incidents apply from 11 September 2026.cra-reporting
  4. NIST Secure Software Development FrameworkSecure development includes code analysis, management of reused components, remediation, and retained evidence.nist-ssdf
  5. DerScanner static analysis documentationDerScanner documents its static source-code analysis capabilities and supported languages.derscanner-sast
  6. DerScanner SCA scan documentationDerScanner documents SCA vulnerability, supply-chain, license-risk, and SBOM analysis options.derscanner-sca

Build versioned application security evidence

Connect SAST and SCA results to product risk and release records.

Share your product portfolio, development stack, and evidence requirements. The DerScanner team will help map analysis outputs to your engineering process.

Build versioned application security evidence

Discuss CRA-oriented security evidence

Tell us which products, languages, components, and release records you need to assess.

Engineering knowledge for building and operating trustworthy systems.

DerSecur Recognition · build b8de56f · 2026-08-13 08:15:43Z · system