Keysight Technologies launched SBOM Manager on March 18, 2026, delivering a platform that unifies software bill of materials generation, continuous vulnerability intelligence, and secure sharing in a single solution designed for organizations preparing to meet the EU Cyber Resilience Act’s transparency requirements.

The CRA, which takes effect in 2026, requires manufacturers of connected digital products to maintain SBOMs and report actively exploited vulnerabilities within 24 hours. Similar mandates are emerging through U.S. Executive Order 14028, FDA cybersecurity requirements for medical devices, and regulatory frameworks in India, Japan, and South Korea.

SBOM Manager analyzes binary software, firmware, containers, and packaged components to generate accurate bills of materials. It correlates those SBOMs with multiple vulnerability sources and supports Vulnerability Exploitability eXchange filtering to help teams distinguish between theoretical exposure and exploitable risk in their specific deployment contexts.

Keysight VP of Network Test and Security Ram Periakaruppan positioned the tool within the regulatory convergence: “SBOMs are becoming a prerequisite for doing business globally. This solution helps organizations meet requirements with confidence.” The platform includes role based access control, version tracking, SBOM validation against evolving standards, and consumer side visibility enabling downstream organizations to map component risk into their operational environments.