Browse guides

Reference

Framework evidence, SBOM and VEX

Generate evidence for review while keeping technical scope, legal applicability and disclosure decisions separate.

Guide type: Product guide

In this guide

Framework views

FDIE maps available technical checks to supported framework profiles. Confirm the applicable edition and product scope with a qualified reviewer. Scores weight assessed controls; unassessed and not-applicable checks are excluded from that score and remain visible in coverage. A raw pass rate and a weighted fleet score use different denominators.

ETSI EN 303 645 checklist with pass, fail and manual review filters
Control checklist · Sample product captureThe fleet's weighted score and the selected image's raw pass rate have different denominators. Use the individual evidence and assessment scope, rather than comparing these percentages directly.Select the image to view it at full size in a new tab.

Inventories and exports

Inventories and exports
ArtifactPurposeReview before sharing
CycloneDX / SPDX SBOMIdentified software and available dependency informationComponent identities, versions, licence evidence, analysis scope and feed context
CBOMIdentified cryptographic assetsAlgorithm / key evidence and incomplete recovery
VEXRecorded vulnerability applicability and dispositionsAnalyst rationale, affected product/release and unresolved uncertainty
Assessment / PDF reportsFindings and supporting technical checksAudience, sensitive content, selected framework and limitations
TARA / EMB3D reviewCandidate threat relationships from firmware evidenceAssets, trust boundaries, physical context and missing operational evidence

CRA disclosure review

Use the separate disclosure workflow to record investigation, awareness time, decisions and official submission references. A CVE match or KEV entry alone does not determine reportability. The responsible manufacturer must assess its legal duties and submit through the applicable official channel. FDIE does not notify a regulator simply because a record is created, and it does not issue CRA conformity grades or certificates.

Review the configured framework mappings

Explore compliance evidence

Prepare a recipient-ready evidence package

  • Confirm the product, release and intended assessment scope with the recipient.
  • Review the relevant framework version and individual check states, including manual, not-applicable and unassessed work.
  • Select the appropriate SBOM, CBOM, VEX or report output. Check that the format includes the information the recipient actually needs.
  • Validate each material applicability decision and its supporting reason before sharing VEX.
  • Review the exported file for sensitive content and retain its image identity and assessment context with the handover.

A customer export becomes a separate copy. Apply your own storage, access and retention rules after download, and regenerate the record when its underlying assessment or decision changes.