Cyber Resilience Act: decide whether you place a product on the market, then build the SBOM, vulnerability handling, support period and reporting path