Microsoft recently published an official blog post announcing revisions to the certification requirements of its Windows Hardware Compatibility Program (WHCP). Beginning in March 2027, every driver submitted for Windows 11 25H2/26H2, as well as Windows Server 2025 and subsequent releases, must accompany both a Software Bill of Materials (SBOM) and a Vulnerability Exploitability eXchange (VEX) statement. Drivers lacking these artifacts will be denied Microsoft’s signature.
Every Driver Must Submit Its Own SBOM and VEX
Under Microsoft’s newest policy, all drivers signed through HLK certification or the Attestation pathway must individually furnish both an SBOM and a VEX. The SBOM must adopt the SPDX 3.0 format. Moreover, it must enumerate every first-party and third-party component the driver employs, encompassing libraries, frameworks, tools, and transitive dependencies, alongside precise versions and package identifiers.
The VEX, meanwhile, clarifies whether publicly disclosed CVEs within those components genuinely affect the driver at hand. Suppose a dependency harbors a vulnerability that the driver never actually invokes. In that case, the OEM may designate it as inapplicable through the VEX. Consequently, this prevents a deluge of spurious vulnerability alerts derived solely from the SBOM.
Primarily Driven by EU Regulatory Demands
Microsoft has explicitly stated that this revision chiefly serves to satisfy the requirements of the EU Cyber Resilience Act (CRA). Therefore, it constitutes a mandatory policy rather than an optional certification. In short, the Cyber Resilience Act compels developers to understand the third-party components embedded within their products. Additionally, it obliges them to continuously address security vulnerabilities and supply-chain risks throughout each product’s lifecycle.
Furthermore, Microsoft intends to update the Windows Driver Kit in December 2026. This update will incorporate tools to generate and validate SBOMs and to craft VEX statements. OEMs may likewise employ alternative industry tools, provided the ultimate output conforms to the SPDX 3.0 specification.
Finally, drivers submitted before March 2027 will not be retroactively obligated to provide these materials. Certification rules for older Windows versions remain unchanged. Only newer Windows releases will fall under the new requirements.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!