The programme ended. The obligation did not.
A grant-funded readiness programme delivers an assessment and a document set inside a project window. The CRA obligation is a decade of maintained SBOMs, live vulnerability monitoring, VEX history and retained evidence.
Those are different jobs. The programme is funded to do the first one and it does it well. Nobody is funded to do the second one for you.
Bring what you already have
Import CycloneDX and SPDX SBOMs, VEX and CSAF documents, and the assessment and documentation output of the free and grant-funded tooling in the market. It gets mapped onto a product record rather than sitting in a folder.
See what has already gone stale
Staleness is computed, not asserted. Your imported SBOM is re-matched against current feed data, so you find out which components have picked up vulnerabilities since the artifact was generated, which have gone end-of-life, and which documents no longer reflect your current release.
In a market where 621,909 electronic components were discontinued or declared obsolete in 2025, and 52% reached end-of-life with no product change notification at all, an SBOM from six months ago is a historical document.
No lock-in, stated plainly
CycloneDX, SPDX, VEX and OASIS formats in and out, at any time, including after you cancel. Using a grant programme and this product together is a perfectly sensible thing to do, and the interop stance is what makes that safe.
See the prices