<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Software Supply Chain on OpenChain KWG</title><link>https://OpenChain-Project.github.io/OpenChain-KWG/en/tags/software-supply-chain/</link><description>Recent content in Software Supply Chain on OpenChain KWG</description><generator>Hugo</generator><language>en</language><lastBuildDate>Mon, 10 Aug 2026 11:20:08 +0900</lastBuildDate><atom:link href="https://OpenChain-Project.github.io/OpenChain-KWG/en/tags/software-supply-chain/index.xml" rel="self" type="application/rss+xml"/><item><title>CISA 2026 SBOM Minimum Elements: What to Prepare and Which Tools Fill the Gaps</title><link>https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2026/08/09/cisa-sbom-minimum-elements/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2026/08/09/cisa-sbom-minimum-elements/</guid><description>&lt;div class="alert alert-info" role="alert"&gt;
&lt;p&gt;This article was written with Claude Code, and the key facts cited here were cross-checked against primary sources.&lt;/p&gt;
&lt;/div&gt;
&lt;h2 id="summary"&gt;Summary&lt;/h2&gt;
&lt;p&gt;On July 29, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) and 17 other agencies published a revised set of minimum elements for a Software Bill of Materials (SBOM)&lt;a id="a2-ref-1"&gt;&lt;/a&gt;&lt;a href="https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2026/08/09/cisa-sbom-minimum-elements/#a2"&gt;A2&lt;/a&gt;. The document states plainly that it replaces, rather than amends, the baseline established in 2021 by the National Telecommunications and Information Administration (NTIA).&lt;/p&gt;</description></item><item><title>EU Cyber Resilience Act (CRA) Vulnerability Reporting Obligations — A Research Report for the 2026-09-11 Compliance Date</title><link>https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2026/05/18/eu-cra/</link><pubDate>Mon, 18 May 2026 00:00:00 +0000</pubDate><guid>https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2026/05/18/eu-cra/</guid><description>&lt;div class="alert alert-info" role="alert"&gt;
&lt;p&gt;This article was written with Claude Code, and the key facts cited here were cross-checked against primary sources.&lt;/p&gt;
&lt;/div&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Summary&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The EU Cyber Resilience Act (Cyber Resilience Act, CRA — Regulation (EU) 2024/2847) is the EU&amp;rsquo;s first comprehensive product security regulation, imposing horizontal cybersecurity obligations on every &amp;ldquo;product with digital elements&amp;rdquo; (PDE) placed on the EU market. The regulation entered into force on December 10, 2024, and applies in phases. From September 11, 2026, the Article 14 reporting obligations take effect, requiring manufacturers, importers, and distributors to notify ENISA (the European Union Agency for Cybersecurity) and Member State CSIRTs of actively exploited vulnerabilities and severe incidents within a staged 24-hour, 72-hour, and 14-day window. Companies that have not stood up a reporting workflow by this date face fines of up to €15 million or 2.5% of worldwide annual turnover, and Korean companies that place products on the EU market are subject to the obligation immediately. &lt;a id="a1-ref-1"&gt;&lt;/a&gt;&lt;a href="https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2026/05/18/eu-cra/#a1"&gt;A1&lt;/a&gt;, &lt;a id="b1-ref-1"&gt;&lt;/a&gt;&lt;a href="https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2026/05/18/eu-cra/#b1"&gt;B1&lt;/a&gt;, &lt;a id="e1-ref-1"&gt;&lt;/a&gt;&lt;a href="https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2026/05/18/eu-cra/#e1"&gt;E1&lt;/a&gt;&lt;/p&gt;</description></item></channel></rss>