---
title: EU Cyber Resilience Act (CRA) Clears Penultimate Step
description: The EU Cyber Resilience Act (CRA) is one step from official adoption. Supply chain security, SBOMs and vulnerability management are priorities.
image: https://blog.adolus.com/hubfs/flags%20and%20binary.png
---

[![aDolus Logo](https://adolus.com/images/adolus-white-new60px.webp)](https://adolus.com/) [Blog](https://blog.adolus.com/)

Product

- ##### Fact Platform
- [Overview](https://adolus.com/fact/overview/)
- [Benefits](https://adolus.com/fact/benefits/)
- [Technical Details](https://adolus.com/fact/technical/)

- ##### Fact Features
- [Software Validation & Scoring](https://adolus.com/product/software-validation-scoring/)
- [SBOM Creation](https://adolus.com/product/sbom/)
- [VEX Documents](https://adolus.com/product/vex-documents/)
- [Malware Detection](https://adolus.com/product/malware-detection/)
- [Certificate Validation](https://adolus.com/product/certificate-validation/)
- [Software Supplier Discovery](https://adolus.com/product/software-supplier-discovery/)

Solutions

- ##### By use case
- [Vulnerability Management](https://adolus.com/solutions/vulnerability-management/)
- [Compliance](https://adolus.com/solutions/compliance/)
- [Risk Management](https://adolus.com/solutions/risk-management/)
- [Operational Insights](https://adolus.com/solutions/operational-insights/)

- ##### By job function
- [Product Managers](https://adolus.com/solutions/product-managers/)
- [Security Managers](https://adolus.com/solutions/security-managers/)
- [Engineering Managers](https://adolus.com/solutions/engineering-managers/)
- [Procurement Managers](https://adolus.com/solutions/procurement-managers/)

- ##### By role in the supply chain
- [Vendors & OEMs](https://adolus.com/solutions/vendors-oems/)
- [Asset Owners](https://adolus.com/solutions/asset-owners/)

Resources

- ##### A Deeper Dive
- [Blog](https://blog.adolus.com/)
- [Videos & Podcasts](https://adolus.com/resources/video-podcasts/)
- [Infographics](https://adolus.com/resources/infographics/)
- [FAQ](https://adolus.com/resources/faq/)
- [Document Library](https://adolus.com/resources/document-library/)

- ##### Educational Tools
- [Executive Order 14028 Timeline](https://info.adolus.com/eo14028-timeline)
- [Log4j Resources](https://adolus.com/vulnerabilities/log4j/)

Company

- [About Us](https://adolus.com/company/about/)
- [Our Partners](https://adolus.com/company/partners/)
- [News](https://adolus.com/company/news/)
- [Careers](https://adolus.com/company/careers/)
- [Contact aDolus](https://adolus.com/company/contact/)

[Get a Demo](https://info.adolus.com/schedule-a-fact-demo-3)

[Supply Chain Management](https://blog.adolus.com/tag/supply-chain) [SBOM](https://blog.adolus.com/tag/sbom) [Legislation](https://blog.adolus.com/tag/legislation)

# EU Cyber Resilience Act (CRA) Clears Penultimate Step

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on December, 8 2023

[Back](https://blog.adolus.com)

EU Cyber Resilience Act (CRA) Clears Penultimate Step

Share

<https://twitter.com/intent/tweet?text=&url=https://blog.adolus.com/eu-cra-clears-penultimate-step> <http://www.facebook.com/share.php?u=https://blog.adolus.com/eu-cra-clears-penultimate-step> <http://www.linkedin.com/shareArticle?mini=true&url=https://blog.adolus.com/eu-cra-clears-penultimate-step> [mailto:?subject=Check%20out%20https://blog.adolus.com/eu-cra-clears-penultimate-step%20&body=Check%20out%20https://blog.adolus.com/eu-cra-clears-penultimate-step&media=https://6687498.fs1.hubspotusercontent-na1.net/hubfs/6687498/flags%20and%20binary.png](mailto:?subject=Check%20out%20https://blog.adolus.com/eu-cra-clears-penultimate-step%20&body=Check%20out%20https://blog.adolus.com/eu-cra-clears-penultimate-step&media=https://6687498.fs1.hubspotusercontent-na1.net/hubfs/6687498/flags%20and%20binary.png)

[Back to main blog](https://blog.adolus.com)

Share

<https://twitter.com/intent/tweet?text=&url=https://blog.adolus.com/eu-cra-clears-penultimate-step> <http://www.facebook.com/share.php?u=https://blog.adolus.com/eu-cra-clears-penultimate-step> <http://www.linkedin.com/shareArticle?mini=true&url=https://blog.adolus.com/eu-cra-clears-penultimate-step> [mailto:?subject=Check%20out%20https://blog.adolus.com/eu-cra-clears-penultimate-step%20&body=Check%20out%20https://blog.adolus.com/eu-cra-clears-penultimate-step&media=https://6687498.fs1.hubspotusercontent-na1.net/hubfs/6687498/flags%20and%20binary.png](mailto:?subject=Check%20out%20https://blog.adolus.com/eu-cra-clears-penultimate-step%20&body=Check%20out%20https://blog.adolus.com/eu-cra-clears-penultimate-step&media=https://6687498.fs1.hubspotusercontent-na1.net/hubfs/6687498/flags%20and%20binary.png)

On December 3rd, the EU's new [Cyber Resilience Act](https://digital-strategy.ec.europa.eu/en/library/cyber-resilience-act) (CRA) got a big step closer to being adopted when the European Parliament and the EU Council reached an agreement on the legislation. It is now only one step away from being officially adopted. Unless lobby groups manage to derail final approval by the European Parliament and the Council, it will likely enter into force sometime before summer. Organizations affected by the CRA will then have 36 months (and in some cases just 24 months) to adapt to the new requirements.

First proposed by the EU Commission in September 2022, the CRA has been controversial due to its massive sector-agnostic scope. It will introduce stringent security requirements for all "connected device manufacturers" selling “products with digital elements” in the EU, which means it will impact almost every major company that sells OT, IoT, or IIoT products. 

Securing the software supply chain and addressing device vulnerabilities are two of the major goals of the CRA. To help our readers understand this regulation, I thought I’d highlight a few of the key clauses pertaining to software supply chain security.

## SBOMs Appear Throughout the EU CRA

Just as it featured heavily in recent US cybersecurity legislation, “software bill of materials” recurs frequently in the EU CRA. SBOMs are cited primarily in the context of facilitating vulnerability analysis. One of the first mentions of SBOMs states:

> *In order to facilitate vulnerability analysis, manufacturers should identify and document components contained in the products with digital elements, including by drawing up a software bill of materials. A software bill of materials can provide those who manufacture, purchase, and operate software with information that enhances their understanding of the supply chain, which has multiple benefits, most notably it helps manufacturers and users to track known newly emerged vulnerabilities and risks. It is of particular importance for manufacturers to ensure that their products do not contain vulnerable components developed by third parties.*

The EU has correctly recognized that identifying risks — particularly those associated with vulnerabilities — requires transparency into all the components comprising a “product with digital elements” (which I’ll just call “product” herein for brevity). [SBOMs](https://adolus.com/product/sbom/) provide that transparency. Manufacturers in the EU will now need to provide SBOMs for the products they sell, and they should be able to obtain SBOMs for the components that go into those products.

Judging from what we’ve seen here in North America, manufacturers have historically been hesitant to produce SBOMs — due either to fear of exposing their IP or reluctance to incur additional cost when no one knew exactly how SBOMs were to be put to practical use. (To learn more about the early days of SBOMs in the US, read our blog on [The Minimum Components of an SBOM](https://blog.adolus.com/ntia-publishes-minimum-components-of-an-sbom).) But SBOMs have long since emerged from the academic discussion stage and are now actively being produced and consumed, not just to satisfy regulators but to satisfy a growing appetite for them in the marketplace. I expect to see a similar pattern in the EU.

## But What Kind of SBOMs?

It’s not 100% clear in the Act what level of depth manufacturers are responsible for with respect to product components. In the Vulnerability Handling Requirements section of Annex 1, the Act states that Manufacturers shall: 

> …*identify and document vulnerabilities and components contained in the product, including by drawing up a software bill of materials in a commonly used and machine-readable format covering at the very least the top-level dependencies of the product;*

“Top-level” dependencies seems like a low bar. Our own research has uncovered plenty of serious vulnerabilities buried far deeper than the top level. But the EU Commission may share the philosophy of Dr. Allan Friedman: “not letting the perfect be the enemy of the good.” (Dr. Friedman from CISA is SBOM’s biggest proponent in North America.) Knowing the top-level dependencies is better than knowing nothing. The rest will follow.

The Act also specifies that the EU Commission retains the power to:

> …*specify the format or elements of the reporting obligations and of the software bill of material*s. 

I’m not sure if this will result in yet another SBOM format in addition to SPDX, CycloneDX, and SWID. (Let’s hope not. The SBOM initiative is too important to get overly bogged down by a format war.) In our global economy, it doesn’t make sense to have regional formats. But the phrase “commonly used and machine-readable format*”* is encouraging and suggests the EU isn’t looking to start from scratch on their own bespoke format.

## Other Clauses of Interest

The Act specifies that products must be accompanied by:

> * …the correct identification of the type, batch, version or serial number or other element allowing the identification of the product*.

Like an iceberg with 90% of its mass hidden below the surface, this requirement appears straightforward but is actually extremely challenging. There isn’t currently a standard for uniquely identifying these kinds of products, and likely for now, this will need to be done on a company by company basis. Subscribe to our blog and we’ll dive into the challenges in a future post as this is a big topic.

The Act also states that some of the obligations of manufacturers are to:

> *include a cybersecurity risk assessment in the technical documentation… *

and

> *exercise due diligence when integrating components sourced from third parties in products with digital elements. They shall ensure that such components do not compromise the security of the product with digital elements.*

Producing a “cybersecurity risk assessment” isn’t well defined in the Act but one important thing to note is that an SBOM does ***not*** provide a risk assessment. An SBOM is simply a list of ingredients: the components and subcomponents that make up the product. To perform a risk assessment, you also need to know the specific risk associated with each subcomponent.

Our FACT platform performs exactly that kind of analysis. Armed with an SBOM that it produces via binary code analysis, FACT hunts for a wide range of risk factors, including (but not limited to) vulnerabilities. Our visibility reports provide detailed cybersecurity risk assessments with a high degree of granularity. They offer [easy-to-use risk scores](https://adolus.com/product/software-validation-scoring/) on a component by component basis as well as on a product by product basis. So if a component is harboring vulnerabilities — *or* malware *or* a compromised certificate chain *or* some other risk factor — FACT will score it accordingly, and that score will also bubble up to all the products containing that component.

I wouldn’t want to say FACT’s cybersecurity risk assessment reports are a silver bullet for fulfilling this requirement… but manufacturers who sell products in the EU may want to give us a call. 🙂

[![Book a Demo](https://no-cache.hubspot.com/cta/default/6687498/1ab3838b-33d4-4d36-a60b-3952add74c33.png)](https://cta-redirect.hubspot.com/cta/redirect/6687498/1ab3838b-33d4-4d36-a60b-3952add74c33)

There is another requirement in the Act that FACT addresses that eliminates a lot of burdensome manual research. With respect to [vulnerability handling](https://adolus.com/solutions/vulnerability-management/), manufacturers will need to:

> *…apply effective and regular tests and reviews of the security of the product with digital elements.*

While they don’t explicitly define “regular,” FACT’s continuous monitoring of public vulnerability databases, vendor websites, and other sources would meet and most likely exceed this requirement. And this capability is useful not just for checking a regulatory box — continuous monitoring ensures that manufacturers and operators are alerted to critical vulnerabilities and can take remedial action before attackers exploit them.

![Eric Byres](https://blog.adolus.com/hubfs/Eric-Byres.png)

###### Eric Byres

 Eric is widely recognized as one of the world’s leading experts in the field of OT, IT and IoT software supply chain security. He is the inventor of the Tofino Security technology – the most widely deployed OT-specific firewall in the world. When not setting the product vision, or speaking at a conference, Eric can be found cranking away on his gravel bike.

<https://adolus.com> <https://www.facebook.com/aDolus.Inc/> <https://www.linkedin.com/in/ericbyres/> <https://twitter.com/ICS_Secure>

[Previous Post](https://blog.adolus.com/the-wretched-state-of-ot-firmware-patching) [View All](https://blog.adolus.com) [Next Post](https://blog.adolus.com/evolving-threats-and-regulations-in-software-supply-chain-security)

##### Stay up to date

##### Browse Posts

 Popular

 Recent

 Archive

[![What is VEX and What Does it Have to Do with SBOMs?](https://blog.adolus.com/hubfs/VEX-SBOM-main-image.png)](https://blog.adolus.com/what-is-vex-and-what-does-it-have-to-do-with-sboms)

[What is VEX and What Does it Have to Do with SBOMs?](https://blog.adolus.com/what-is-vex-and-what-does-it-have-to-do-with-sboms)

[![Sniffing Out Fakes: From Saffron in Marrakech to Digital Certificates](https://blog.adolus.com/hubfs/Imported_Blog_Media/Eric-on-Camel-small-1024x769.png)](https://blog.adolus.com/2019/10/08/sniffing-out-fakes-from-saffron-in-marrakech-to-digital-certificates)

[Sniffing Out Fakes: From Saffron in Marrakech to Digital Certificates](https://blog.adolus.com/2019/10/08/sniffing-out-fakes-from-saffron-in-marrakech-to-digital-certificates)

[![A Deeper Dive into VEX Documents](https://blog.adolus.com/hubfs/Anatomy%20of%20VEX%20Documents2.png)](https://blog.adolus.com/a-deeper-dive-into-vex-documents)

[A Deeper Dive into VEX Documents](https://blog.adolus.com/a-deeper-dive-into-vex-documents)

[![Three Things the SolarWinds Supply Chain Attack Can Teach Us](https://blog.adolus.com/hubfs/SolarWinds%20Attack%20Infographic.png)](https://blog.adolus.com/three-things-the-solarwinds-supply-chain-attack-can-teach-us)

[Three Things the SolarWinds Supply Chain Attack Can Teach Us](https://blog.adolus.com/three-things-the-solarwinds-supply-chain-attack-can-teach-us)

[![Rod Campbell Joins aDolus as CEO](https://blog.adolus.com/hubfs/Rod-Campbell-CEO.png)](https://blog.adolus.com/rod-campbell-joins-adolus-as-ceo)

[Rod Campbell Joins aDolus as CEO](https://blog.adolus.com/rod-campbell-joins-adolus-as-ceo)

[![Harnessing FACT for Swift Cyberthreat Response](https://blog.adolus.com/hubfs/XZ%20Backdoor%20thumbnail-aspect-corrected.png)](https://blog.adolus.com/harnessing-fact-for-swift-threat-response)

[Harnessing FACT for Swift Cyberthreat Response](https://blog.adolus.com/harnessing-fact-for-swift-threat-response)

[![Evolving Threats and Regulations in Software Supply Chain Security](https://blog.adolus.com/hubfs/laptop-gavel.png)](https://blog.adolus.com/evolving-threats-and-regulations-in-software-supply-chain-security)

[Evolving Threats and Regulations in Software Supply Chain Security](https://blog.adolus.com/evolving-threats-and-regulations-in-software-supply-chain-security)

[![EU Cyber Resilience Act (CRA) Clears Penultimate Step](https://blog.adolus.com/hubfs/flags%20and%20binary.png)](https://blog.adolus.com/eu-cra-clears-penultimate-step)

[EU Cyber Resilience Act (CRA) Clears Penultimate Step](https://blog.adolus.com/eu-cra-clears-penultimate-step)

[![The Wretched State of OT Firmware Patching](https://blog.adolus.com/hubfs/negelct.png)](https://blog.adolus.com/the-wretched-state-of-ot-firmware-patching)

[The Wretched State of OT Firmware Patching](https://blog.adolus.com/the-wretched-state-of-ot-firmware-patching)

[![Microsoft Digital Defense Report: Behind the Scenes Creating OT Vulnerabilities](https://blog.adolus.com/hubfs/MDDR2-backstage-pass-featureimage.png)](https://blog.adolus.com/microsoft-digital-defense-report-behind-the-scenes-creating-ot-vulnerabilities)

[Microsoft Digital Defense Report: Behind the Scenes Creating OT Vulnerabilities](https://blog.adolus.com/microsoft-digital-defense-report-behind-the-scenes-creating-ot-vulnerabilities)

- [May 2024](https://blog.adolus.com/archive/2024/05)
- [February 2024](https://blog.adolus.com/archive/2024/02)
- [December 2023](https://blog.adolus.com/archive/2023/12)
- [October 2023](https://blog.adolus.com/archive/2023/10)
- [April 2023](https://blog.adolus.com/archive/2023/04)
- [March 2023](https://blog.adolus.com/archive/2023/03)
- [February 2023](https://blog.adolus.com/archive/2023/02)
- [October 2022](https://blog.adolus.com/archive/2022/10)
- [April 2022](https://blog.adolus.com/archive/2022/04)
- [February 2022](https://blog.adolus.com/archive/2022/02)
- [December 2021](https://blog.adolus.com/archive/2021/12)
- [November 2021](https://blog.adolus.com/archive/2021/11)
- [August 2021](https://blog.adolus.com/archive/2021/08)
- [July 2021](https://blog.adolus.com/archive/2021/07)
- [June 2021](https://blog.adolus.com/archive/2021/06)
- [May 2021](https://blog.adolus.com/archive/2021/05)
- [February 2021](https://blog.adolus.com/archive/2021/02)
- [January 2021](https://blog.adolus.com/archive/2021/01)
- [December 2020](https://blog.adolus.com/archive/2020/12)
- [September 2020](https://blog.adolus.com/archive/2020/09)
- [August 2020](https://blog.adolus.com/archive/2020/08)
- [July 2020](https://blog.adolus.com/archive/2020/07)
- [May 2020](https://blog.adolus.com/archive/2020/05)
- [April 2020](https://blog.adolus.com/archive/2020/04)
- [January 2020](https://blog.adolus.com/archive/2020/01)
- [October 2019](https://blog.adolus.com/archive/2019/10)
- [September 2019](https://blog.adolus.com/archive/2019/09)
- [November 2018](https://blog.adolus.com/archive/2018/11)
- [September 2018](https://blog.adolus.com/archive/2018/09)
- [May 2018](https://blog.adolus.com/archive/2018/05)

##### Browse by topics

- [Supply Chain Management (16)](https://blog.adolus.com/tag/supply-chain)
- [SBOM (15)](https://blog.adolus.com/tag/sbom)
- [Vulnerability Tracking (15)](https://blog.adolus.com/tag/vulnerability-tracking)
- [#supplychainsecurity (10)](https://blog.adolus.com/tag/supplychainsecurity)
- [Regulatory Requirements (10)](https://blog.adolus.com/tag/regulatory-requirements)
- [VEX (8)](https://blog.adolus.com/tag/vex)
- [EO14028 (6)](https://blog.adolus.com/tag/eo14028)
- [ICS/IoT Upgrade Management (6)](https://blog.adolus.com/tag/upgrades)
- [malware (6)](https://blog.adolus.com/tag/malware)
- [ICS (5)](https://blog.adolus.com/tag/ics)
- [vulnerability disclosure (5)](https://blog.adolus.com/tag/vulnerability-disclosure)
- [3rd Party Components (4)](https://blog.adolus.com/tag/3rd-party-components)
- [Partnership (4)](https://blog.adolus.com/tag/partnership)
- [Press-release (4)](https://blog.adolus.com/tag/press-release)
- [#S4 (3)](https://blog.adolus.com/tag/s4)
- [Software Validation (3)](https://blog.adolus.com/tag/sw-validation)
- [hacking (3)](https://blog.adolus.com/tag/hacking)
- [industrial control system (3)](https://blog.adolus.com/tag/industrial-control-system)
- [Code Signing (2)](https://blog.adolus.com/tag/code-signing)
- [Legislation (2)](https://blog.adolus.com/tag/legislation)
- [chain of trust (2)](https://blog.adolus.com/tag/chain-of-trust)
- [#nvbc2020 (1)](https://blog.adolus.com/tag/nvbc2020)
- [DoD CMMC (1)](https://blog.adolus.com/tag/dod-cmmc)
- [Dragonfly (1)](https://blog.adolus.com/tag/dragonfly)
- [Havex (1)](https://blog.adolus.com/tag/havex)
- [Log4Shell (1)](https://blog.adolus.com/tag/log4shell)
- [Log4j (1)](https://blog.adolus.com/tag/log4j)
- [Trojan (1)](https://blog.adolus.com/tag/trojan)
- [USB (1)](https://blog.adolus.com/tag/usb)
- [Uncategorized (1)](https://blog.adolus.com/tag/uncategorized)
- [energy (1)](https://blog.adolus.com/tag/energy)
- [medical (1)](https://blog.adolus.com/tag/medical)
- [password strength (1)](https://blog.adolus.com/tag/password-strength)
- [pharmaceutical (1)](https://blog.adolus.com/tag/pharmaceutical)

Sidebar

### Related Posts

[![How Russia Might Come After the West](https://blog.adolus.com/hubfs/russian-gas-pump-cyberattack-900x525.png)](https://blog.adolus.com/how-russia-might-come-after-the-west)

 2 min read

##### [How Russia Might Come After the West](https://blog.adolus.com/how-russia-might-come-after-the-west)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on February 25, 2022

The DDoS attack surge that began last week against Ukrainian government agencies and banks was a bad sign. I was...

[Continue Reading](https://blog.adolus.com/how-russia-might-come-after-the-west)

[![3 Month Reprieve for Utilities on Cybersecurity Supply Chain Standards](https://blog.adolus.com/hubfs/Imported_Blog_Media/NERC-CIPC-Training-Session-1024x451.jpeg)](https://blog.adolus.com/2020/04/21/3-month-reprieve-for-utilities-on-cybersecurity-supply-chain-standards)

 3 min read

##### [3 Month Reprieve for Utilities on Cybersecurity Supply Chain Standards](https://blog.adolus.com/2020/04/21/3-month-reprieve-for-utilities-on-cybersecurity-supply-chain-standards)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on April 21, 2020

Earlier this month, as the coronavirus accelerated its alarming sprint across North America, NERC requested that...

[Continue Reading](https://blog.adolus.com/2020/04/21/3-month-reprieve-for-utilities-on-cybersecurity-supply-chain-standards)

[![Podcast: Where Do Your Bits Really Come From?](https://blog.adolus.com/hubfs/Imported_Blog_Media/Dragonfly-Compromise-Stages_cropped-768x454.png)](https://blog.adolus.com/2019/09/26/podcast-where-do-your-bits-really-come-from)

 3 min read

##### [Podcast: Where Do Your Bits Really Come From?](https://blog.adolus.com/2019/09/26/podcast-where-do-your-bits-really-come-from)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on September 26, 2019

Earlier this year I attended the Public Safety Canada Industrial Control System Security symposium in Charlottetown,...

[Continue Reading](https://blog.adolus.com/2019/09/26/podcast-where-do-your-bits-really-come-from)

[![Unpacking EO14028: Improving the Nation's Cybersecurity - Pt. 1](https://blog.adolus.com/hubfs/Timeline-thumbnail.png)](https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-1)

 4 min read

##### [Unpacking EO14028: Improving the Nation's Cybersecurity - Pt. 1](https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-1)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on May 14, 2021

Late Wednesday night President Biden signed the Executive Order on Improving the Nation’s Cybersecurity. Compared to...

[Continue Reading](https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-1)

[![Sorry Blackberry: You Are Part of the Supply Chain](https://blog.adolus.com/hubfs/Blackberry-SBOM-share-main-image.png)](https://blog.adolus.com/sorry-blackberry-you-are-part-of-the-supply-chain)

 2 min read

##### [Sorry Blackberry: You Are Part of the Supply Chain](https://blog.adolus.com/sorry-blackberry-you-are-part-of-the-supply-chain)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on November 2, 2021

Today, reporters Betsy Woodruff Swan and Eric Geller at Politico published a story: “BlackBerry resisted announcing...

[Continue Reading](https://blog.adolus.com/sorry-blackberry-you-are-part-of-the-supply-chain)

[![Harnessing FACT for Swift Cyberthreat Response](https://blog.adolus.com/hubfs/XZ%20Backdoor%20thumbnail-aspect-corrected.png)](https://blog.adolus.com/harnessing-fact-for-swift-threat-response)

 6 min read

##### [Harnessing FACT for Swift Cyberthreat Response](https://blog.adolus.com/harnessing-fact-for-swift-threat-response)

 By [Marcello Delcaro](https://blog.adolus.com/author/marcello-delcaro) on May 1, 2024

In the cybersecurity world, anticipation and rapid response are crucial in safeguarding against emerging threats....

[Continue Reading](https://blog.adolus.com/harnessing-fact-for-swift-threat-response)

[![Unpacking EO14028: Improving the Nation's Cybersecurity - Pt. 2](https://blog.adolus.com/hubfs/Timeline-thumbnail2.png)](https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-2)

 3 min read

##### [Unpacking EO14028: Improving the Nation's Cybersecurity - Pt. 2](https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-2)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on May 18, 2021

Removing Barriers to Sharing Threat Information On Friday we dissected Section 4: Enhancing Software Supply Chain...

[Continue Reading](https://blog.adolus.com/unpacking-eo-14028-improving-the-nations-cybersecurity-part-2)

[![The Wretched State of OT Firmware Patching](https://blog.adolus.com/hubfs/negelct.png)](https://blog.adolus.com/the-wretched-state-of-ot-firmware-patching)

 4 min read

##### [The Wretched State of OT Firmware Patching](https://blog.adolus.com/the-wretched-state-of-ot-firmware-patching)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on October 11, 2023

This blog is a follow-up to our first post on the 2023 Microsoft Digital Defense Report where I described our...

[Continue Reading](https://blog.adolus.com/the-wretched-state-of-ot-firmware-patching)

[![aDolus Welcomes Mark Weatherford to Board](https://blog.adolus.com/hubfs/Mark-Weatherford-Appointment.png)](https://blog.adolus.com/adolus-welcomes-mark-weatherford-to-board)

 2 min read

##### [aDolus Welcomes Mark Weatherford to Board](https://blog.adolus.com/adolus-welcomes-mark-weatherford-to-board)

 By [Norma Dowler](https://blog.adolus.com/author/norma-dowler) on June 23, 2021

Cybersecurity veteran tapped to accelerate growth of ICS supply chain security leader VICTORIA, BC, CANADA, June 23 -- ...

[Continue Reading](https://blog.adolus.com/adolus-welcomes-mark-weatherford-to-board)

[![NTIA Publishes Minimum Components of an SBOM](https://blog.adolus.com/hubfs/Main-SBOM-image.png)](https://blog.adolus.com/ntia-publishes-minimum-components-of-an-sbom)

 4 min read

##### [NTIA Publishes Minimum Components of an SBOM](https://blog.adolus.com/ntia-publishes-minimum-components-of-an-sbom)

 By [Derek Kruszewski](https://blog.adolus.com/author/derek-kruszewski) on July 15, 2021

In today’s blog post I’d like to recognize all the hard work done by NTIA (National Telecommunications and Information...

[Continue Reading](https://blog.adolus.com/ntia-publishes-minimum-components-of-an-sbom)

### Post a comment

### Stay up to date

 Subscribe to our blog

### Stay up to date

![aDolus Logo in blue](https://adolus.com/_next/image/?url=%2Fimages%2Fadolus-blue-60px.png&w=128&q=100)

 200 - 535 Yates Street  
 Victoria, BC  
 Canada  
 V8W 2Z6

[+1-866-423-6587](tel:18664236587) [info@adolus.com](mailto:info@adolus.com)

<https://www.linkedin.com/company/adolus/> <https://twitter.com/adolus_inc> <https://facebook.com/aDolus.Inc> <https://infosec.exchange/@aDolus>

#### Product

- FACT Platform
- [Overview](https://adolus.com/fact/overview/)
- [Benefits](https://adolus.com/fact/benefits/)
- [Technical Details](https://adolus.com/fact/technical/)
- FACT Features
- [Software Validation & Scoring](https://adolus.com/product/software-validation-scoring/)
- [SBOM Creation](https://adolus.com/product/sbom/)
- [VEX Documents](https://adolus.com/product/vex-documents/)
- [Malware Detection](https://adolus.com/product/malware-detection/)
- [Certificate Validation](https://adolus.com/product/certificate-validation/)
- [Software Supplier Discovery](https://adolus.com/product/software-supplier-discovery/)

#### Solutions

- By use case
- [Vulnerability Management](https://adolus.com/solutions/vulnerability-management/)
- [Compliance](https://adolus.com/solutions/compliance/)
- [Risk Management](https://adolus.com/solutions/risk-management/)
- [Operational Insights](https://adolus.com/solutions/operational-insights/)
- By job function
- [Product Managers](https://adolus.com/solutions/product-managers/)
- [Security Managers](https://adolus.com/solutions/security-managers/)
- [Engineering Managers](https://adolus.com/solutions/engineering-managers/)
- [Procurement Managers](https://adolus.com/solutions/procurement-managers/)
- By role in the supply chain
- [Vendors & OEMs](https://adolus.com/solutions/vendors-oems/)
- [Asset Owners](https://adolus.com/solutions/asset-owners/)
- [Integrators & Consultants](https://adolus.com/solutions/integrators-consultants/)
- [Security Providers & Partners](https://adolus.com/solutions/security-providers-partners/)

#### Resources

- [Blog](https://blog.adolus.com/)
- [Videos & Podcasts](https://adolus.com/resources/video-podcasts/)
- [Infographics](https://adolus.com/resources/infographics/)
- [FAQ](https://adolus.com/resources/faq/)
- [Document Library](https://adolus.com/resources/document-library/)
- Educational Tools
- [Executive Order #14028 Timeline](https://info.adolus.com/eo14028-timeline)
- [Log4j Resources](https://adolus.com/vulnerabilities/log4j/)

#### Company

- [About Us](https://adolus.com/company/about/)
- [Our Partners](https://adolus.com/company/partners/)
- [News](https://adolus.com/company/news/)
- [Careers](https://adolus.com/company/careers/)
- [Contact](https://adolus.com/company/contact/)

Copyright © 2024 aDolus Technology Inc

[Privacy Policy](https://adolus.com/legal/privacy-policy/) [Terms of Service](https://adolus.com/legal/terms-of-service/)