Increasingly, legal requirements require software developers and users to develop, procure, and operate software solutions with security in mind. Requirements for risk assessment, the creation of software bills of materials, and the publication and use of security advisories present many with procedural, organizational, and technological challenges. We present options and frameworks for preparing for current legal requirements and thus ensuring the long-term quality and security of applications.