According to Verizon's 2025 Data Breach Investigations Report, 30% of breaches involved a third party — double the 15% of the previous year, the sharpest year-over-year shift in the report's history.
A software supply chain compromise costs an average of $4.91 million and takes an average of 267 days to identify and contain — the longest detection time of any attack vector tracked.
The SBOM: from best practice to regulatory obligation
Europe's Cyber Resilience Act already imposes, since September 2026, a vulnerability notification obligation, with full compliance — SBOM, technical documentation, CE marking — required by December 2027.
The CRA applies to any company placing a digital product on the European market, regardless of where it is headquartered.
Signing and provenance: guaranteeing the integrity of deployed code
Every artifact produced by the CI/CD pipeline should be cryptographically signed, with a provenance attestation documenting how it was built.
No unsigned artifact, or one with unverified provenance, should be able to reach a production environment.
Key takeaways
- Maintain an up-to-date SBOM for every critical application
- Run software composition analysis (SCA) automatically on every build
- Sign every deployed artifact and verify its signature before execution
- Automate dependency security updates
- Know whether the organization falls within the scope of the Cyber Resilience Act



