BearingPoint launches new services to help organizations gain full software transparency and meet EU Cyber Resilience Act requirements ahead of the 2027 deadline
24.2.2026 10:00:00 EET | Business Wire | Press release
BearingPoint announces the launch of two new service offerings designed to address the growing complexity of software supply chains and the upcoming regulatory requirements under the EU Cyber Resilience Act (CRA): SBOM Management Services and CRA Compliance Services.
This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260224192962/en/
BearingPoint announces the launch of two new service offerings designed to address the growing complexity of software supply chains and the upcoming regulatory requirements under the EU Cyber Resilience Act (CRA): SBOM Management Services and CRA Compliance Services.
Modern software products often contain thousands of components, many of which are open source or sourced from third-party suppliers. As supply chain attacks become more frequent and regulations tighten, organizations need complete visibility into their software composition to manage risk effectively and meet compliance obligations. The EU Cyber Resilience Act, which comes into full effect in December 2027, mandates that manufacturers demonstrate exactly what is inside their products and how vulnerabilities are managed throughout the product lifecycle.
An integrated approach to software transparency and compliance
BearingPoint's SBOM Management Services deliver the foundational visibility that organizations require. The service covers the entire Software Bill of Materials (SBOM) lifecycle: strategy and readiness assessment, generation and integration into development workflows, quality assurance against industry standards such as CycloneDX and SPDX, vulnerability and license risk analytics, governance and policy implementation, supplier management, and audit-ready reporting.
Building on this foundation, BearingPoint's CRA Compliance Services ensure that software transparency translates into regulatory conformity. The service includes comprehensive OSS inventory and risk assessment, vulnerability management processes aligned with CRA reporting obligations, cybersecurity policy development, compliance documentation, and targeted training for engineering and compliance teams.
While the two services address distinct challenges, they are closely connected. SBOM management provides the structured, automated visibility that CRA compliance requires. Together, they enable organizations to understand their software composition, manage risks proactively, and demonstrate conformity to regulators and customers alike.
What sets BearingPoint apart
BearingPoint brings a distinctive combination of capabilities to these services. The firm offers an operational, end-to-end model that covers SBOM generation, quality assurance, policy enforcement, mitigation workflows, and audit support. The approach is vendor-agnostic and tool-neutral, adapting to each client's existing infrastructure rather than requiring specific technology choices.
With deep experience in open source license governance and compliance, BearingPoint is uniquely positioned to unify license, security, and compliance risk into a single SBOM-driven model. Both services are aligned with current and emerging regulations, including the CRA, NIS2, and U.S. Executive Order 14028.
Organizations can engage flexibly: starting with a pilot program, scaling to a full operating model, or fully outsourcing ongoing SBOM management to BearingPoint.
Industry perspectives
“The world around us is becoming increasingly digital, and every device we use today is built on software. Open source is everywhere and a key driver of innovation. At the same time, the risk of cyberattacks and incompliance is growing, and the need for real cyber resilience is becoming critical. With regulations such as the EU Cyber Resilience Act, this responsibility will soon be mandatory rather than optional. This is exactly where our new outcome‑based service comes in: we combine best‑of‑breed software with deep expert capabilities and take end‑to‑end responsibility for ensuring software compliance and security for our clients. Not as a one‑off effort, but as a measurable, sustainable outcome,” says Frank Duscheck, Partner at BearingPoint.
“Once SBOMs become fully enforceable by the CRA, SBOM management is no longer a ‘nice to have’. In the light of the CRA’s lifecycle security and accountability requirements, SBOM management becomes the foundation for security by design, not just a compliance checkbox. Companies that invest early turn regulatory pressure into a competitive advantage. Our new CRA Compliance and SBOM Management services are a powerful instrument for companies of any size to make their CRA compliance journey smooth, efficient, and sustainable,” adds Claus-Peter Wiedemann, Director Software Services, at BearingPoint.
BearingPoint's SBOM Management Services and CRA Compliance Services are available now. To learn more or schedule a consultation, visit:
SBOM Management Services: https://bearingpoint.services/foss/en/our-services/sbom-management-services/
CRA Compliance Services : https://bearingpoint.services/foss/en/our-services/cyber-resilience-act-cra-compliance-services/
About BearingPoint
BearingPoint is an independent management and technology consultancy with European roots and a global reach. We help businesses transform by combining deep industry expertise with strong capabilities in strategy, operations, and technology. Dedicated SAP and Microsoft transformation units, a strong focus on AI, and outcome-based products enable us to provide tailored, innovative solutions that create measurable and sustainable value.
In addition to our core consulting operations, we run two joint ventures. Arcwide, our joint venture with IFS, specializes in business transformation enabled by IFS technology. BearingPoint North America, our joint venture with ABeam Consulting, focuses on consulting excellence and business transformation built on SAP.
BearingPoint works with many of the world’s leading companies and public-sector organizations. Together with its strategic alliance partner ABeam Consulting, the firm brings together more than 15,000 professionals and serves clients in over 70 countries, delivering seamless business transformation, strengthening performance, and driving sustainable impact.
BearingPoint is recognized among TIME World’s Best Companies and Forbes World’s Best Employers. The firm is also a certified B Corporation, committed to responsible business and creating long-term value for organizations, people, and society.
For more information, please visit:
Homepage: www.bearingpoint.com
LinkedIn: www.linkedin.com/company/bearingpoint
View source version on businesswire.com: https://www.businesswire.com/news/home/20260224192962/en/
Contacts
Press contact
Alexander Bock
Global Senior Manager Communications
Telephone: +49 89 540338029
Email: alexander.bock@bearingpoint.com
About Business Wire
For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.
www.businesswire.com

Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
From Network Automation to Agentic NetOps: NetBrain Sets the Standard for Deploying AI in Network Operations29.5.2026 16:00:00 EEST | Press release
NetBrain Technologies, Inc. today announced major new platform features that advance Agentic NetOps from an emerging category to operational reality. NetBrain's clients are already deploying agents that are diagnosing and remediating issues across complex multi-vendor enterprise networks. These new features further extend the platform with new agent tooling, cross-domain context, and open interfaces for the broader agentic enterprise. Early customer outcomes show the magnitude of the shift: A leading health insurer used NetBrain's Deep Diagnosis agent to diagnose and resolve a weeks old VPN connectivity issue in under five minutes. A large manufacturer resolved a critical device issue with a single prompt, isolating the root cause across the network path in under 20 minutes, saving hundreds of hours of engineer time, shrinking MTTR by more than 95%. A global telecommunications firm found NetBrain's context-grounded agents outperformed a stand-alone frontier LLM on a persistent firewall
Adtran resolves long-running patent litigation, reinforcing commitment to defend innovation29.5.2026 15:00:00 EEST | Press release
Adtran today announced it has resolved a patent litigation matter, resulting in a full settlement and dismissal of all claims with prejudice. The case, initiated in 2020 by a non-practicing entity asserting five patents, was transferred to the US District Court for the Northern District of Alabama in 2021 following a successful motion by Adtran. Adtran subsequently filed counterclaims, including bad-faith patent assertion under Alabama statutory law. The settlement includes payment to Adtran to resolve its counterclaims. Terms of the agreement remain confidential. “This outcome reflects a disciplined and consistent approach to protecting our innovation and our customers,” said Justin Ferguson, SVP and general counsel at Adtran. “We take all claims seriously, but we will not hesitate to defend ourselves when assertions lack merit. Situations like this place unnecessary strain on technology providers and divert resources from advancing networks and services. By advancing our counterclaim
Meiji Seika Pharma Invests in GHIC’s Global Health Security Fund29.5.2026 14:00:00 EEST | Press release
Meiji Seika Pharma Co., Ltd. (Headquarters: Tokyo, Japan; President and Representative Director: Toshiaki Nagasato) today announced that it has committed to invest in the Global Health Security Fund (GHSF), which is sponsored by Global Health Investment Corporation (GHIC), a New York-based nonprofit organization. Through this investment, Meiji Seika Pharma will support the acceleration of innovations addressing critical global health challenges, including pandemic preparedness and antimicrobial resistance (AMR). GHIC is a mission‑driven nonprofit organization that deploys private investment strategies to generate both global health impact and financial returns. GHIC recently closed its second fund in GHSF. With more than a decade of experience investing in the field of infectious disease, GHIC has contributed to addressing major global health challenges. Its portfolio companies have successfully commercialized more than a dozen products, collectively reaching over 600 million people wo
IFF Enters Into Agreement to Sell Its Food Ingredients Business to CVC29.5.2026 13:50:00 EEST | Press release
IFF (NYSE: IFF), a global leader in flavors, fragrances, food ingredients, and health and biosciences, today announced that it has entered into an agreement to sell its Food Ingredients business to funds advised by CVC Capital Partners, a leading global private markets manager, in a transaction that values the business at approximately $4.3 billion, representing an enterprise value-to-EBITDA multiple of approximately 10x. As part of the transaction, IFF has chosen to retain an approximately 10% minority equity interest in the business, or approximately $200 million, permitting continued collaboration and cooperation between IFF and Food Ingredients and allowing IFF and its shareholders to participate in future value creation under its new ownership. The transaction marks a significant step in IFF’s portfolio transformation and is expected to strengthen the company’s focus on its innovation-driven businesses: Taste, Scent, and Health & Biosciences. Following the transaction, IFF will be
BeOne Medicines Establishes Standard for Long-Term Disease Control in CLL with BRUKINSA 78-Month Data at ASCO 202629.5.2026 13:00:00 EEST | Press release
BeOne Medicines Ltd. (Nasdaq: ONC; HKEX: 06160; SSE: 688235), a global oncology company, is advancing the treatment paradigm in chronic lymphocytic leukemia (CLL) at the 2026 American Society of Clinical Oncology (ASCO) Annual Meeting. With extensive long-term follow-up, the SEQUOIA study of BRUKINSA® (zanubrutinib) reinforces its role as the foundational BTK inhibitor, showing sustained disease control over years of therapy. These findings are further supported by real-world evidence across three large analyses encompassing more than 250,000 patients, underscoring consistent effectiveness and safety in clinical practice. Additionally, BEQALZI™ (sonrotoclax), which was recently approved by the U.S. Food and Drug Administration, and its development in combination with BRUKINSA (ZS) highlight the potential for next-generation, time-limited treatment approaches in CLL. Amit Agarwal, M.D., Ph.D., Chief Medical Officer, Hematology, BeOne Medicines, said: “CLL is a disease patients live with
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom