As the Cyber Resilience Act approaches enforcement, software teams are focusing on compliance. This article explores what the Cyber Resilience Act means for software trust in practice, and why continuous, evidence-based assurance is essential for modern software supply chains.