# SBOM Guide > A guide to SBOMs, software supply chains and the CRA The SBOM Guide is a knowledge site about SBOMs (Software Bill of Materials): what an SBOM is, how it is used in vulnerability management and what regulations such as the Cyber Resilience Act (CRA) require. - Every page is available as markdown: append `.md` to the page URL. The start page is https://sbom.se/en/index.md. - The full content in one file: https://sbom.se/en/llms-full.txt - In Swedish: https://sbom.se/llms.txt ## Cyber Resilience Act - [Cyber Resilience Act](https://sbom.se/en/cra.md): What the EU Cyber Resilience Act requires, with a focus on SBOM and vulnerability reporting. - [The CRA in brief](https://sbom.se/en/cra/overview.md): The CRA has applied in part since 11 September 2026 and applies in full from 11 December 2027. This page covers which products are in scope, the dates, what manufacturers must do and the penalties. - [SBOM requirements in the CRA](https://sbom.se/en/cra/sbom-requirements.md): The CRA requires manufacturers to draw up an SBOM for every product with digital elements. This page covers what the regulation requires, what it leaves open, and how to prepare before 11 December 2027. - [Vulnerability reporting under the CRA](https://sbom.se/en/cra/vulnerability-reporting.md): Manufacturers must report actively exploited vulnerabilities and severe incidents within 24 hours through ENISA's Single Reporting Platform. This page covers what to report, the deadlines and what you need in place. ## SBOM basics - [SBOM basics](https://sbom.se/en/sbom.md): What an SBOM is, what it contains and which types and formats exist. - [What is SBOM?](https://sbom.se/en/sbom/what-is-sbom.md): An SBOM (Software Bill of Materials) is a machine-readable record of the components that a piece of software consists of. It is used for vulnerability management, licence checks and compliance, and becomes a legal requirement in the EU through the CRA. - [Why do we need SBOMs?](https://sbom.se/en/sbom/why-sbom.md): Vulnerabilities such as Log4Shell and Heartbleed showed how hard it is to answer whether you are affected when you do not know which components your software contains. That is the question an SBOM answers. - [Why is SBOM important for industry?](https://sbom.se/en/sbom/sbom-for-industry.md): A product contains in-house code, open source and components from suppliers. SBOM gives manufacturers, customers and authorities a shared format for describing the content. - [What is in an SBOM?](https://sbom.se/en/sbom/sbom-contents.md): An SBOM contains information about each component, such as name, version, supplier, identifier, licence and checksum, plus how the components depend on each other and who created the SBOM. - [What are Minimum Elements?](https://sbom.se/en/sbom/minimum-elements.md): The SBOM Minimum Elements from NTIA in the United States state which data fields, which automation support and which practices an SBOM must meet at a minimum. CISA published a draft update in 2025. - [Different types of SBOMs](https://sbom.se/en/sbom/sbom-types.md): An SBOM can be created from a design, from source code, in the build, from a finished artefact or from a running system. CISA has defined six types, and they give different answers to what the software contains. - [SBOM formats and standards](https://sbom.se/en/sbom/formats-and-standards.md): CycloneDX and SPDX are the two standard formats for SBOMs. Both are open, machine-readable and supported by most tools. This page covers the background, the differences and what decides the choice. - [SBOM and SCA, what is the difference?](https://sbom.se/en/sbom/sbom-and-sca.md): SCA (Software Composition Analysis) tools analyse which third-party components a piece of software contains. An SBOM is the result in a standard format that can be stored and shared. - [Other attestations than SBOM: SLSA](https://sbom.se/en/sbom/slsa.md): SLSA (Supply chain Levels for Software Artifacts) is a framework for attesting where, how and by whom software was built. It complements the SBOM, which describes the content. - [Common questions about SBOMs](https://sbom.se/en/sbom/faq.md): What is an SBOM, is it a legal requirement, which format should you choose and how often should it be updated? Short answers to common questions about SBOMs. ## Vulnerabilities and VEX - [Vulnerabilities and VEX](https://sbom.se/en/vulnerabilities.md): How vulnerabilities are assessed and prioritised, and how VEX states which ones affect a product. - [What is a vulnerability?](https://sbom.se/en/vulnerabilities/what-is-a-vulnerability.md): A vulnerability is a weakness in a system that can be exploited by attackers. This article explains what vulnerabilities are, how they are assessed with CVSS and EPSS, common types of vulnerabilities, and the importance of patch management and prioritisation based on SBOMs. - [What is VEX?](https://sbom.se/en/vulnerabilities/what-is-vex.md): A vulnerability scan against an SBOM often returns findings that cannot be exploited in the product at hand. With VEX the supplier states a status for each vulnerability, so that the recipient can prioritise correctly. - [SBOM and vulnerability management](https://sbom.se/en/vulnerabilities/vulnerability-management.md): An SBOM makes it possible to answer which products are affected by a vulnerability. This page goes through the workflow: match against vulnerability data, prioritise with CVSS, EPSS and KEV, and filter out what does not affect you with VEX. - [What is VDR?](https://sbom.se/en/vulnerabilities/what-is-vdr.md): A VDR is the supplier's account of which vulnerabilities affect a product and its components, how they affect the product and what is being done about them. The term comes from NIST SP 800-161. ## SBOM in practice - [SBOM in practice](https://sbom.se/en/guides.md): Create an SBOM, build it into the pipeline, share it in the supply chain and require it in procurement. - [How to create an SBOM](https://sbom.se/en/guides/create-an-sbom.md): An SBOM is created by a tool that reads source code, build output or a container image. This page lists open-source tools, example commands and how to review the result. - [Why is SBOM quality important?](https://sbom.se/en/guides/sbom-quality.md): An SBOM that lacks versions, identifiers or transitive dependencies leads to vulnerability analyses that miss real problems. These are the most common gaps and how to check for them. - [SBOM and DevOps](https://sbom.se/en/guides/devops.md): An SBOM created automatically in the build pipeline is always current and costs no extra work per release. These are the steps: create, check, store and monitor. - [SBOM in software supply chains](https://sbom.se/en/guides/supply-chains.md): Software is built from components from many suppliers, which in turn build on components from others. This page covers why the supply chain is attacked, what needs to be shared between the links and how that works in practice. - [SBOM in public procurement](https://sbom.se/en/guides/public-procurement.md): An SBOM requirement in a procurement needs to state format, content, delivery and updates to be possible to follow up. This page covers what the requirement should contain, with example wording. ## Regulations - [Regulations](https://sbom.se/en/regulations.md): NIS2 and the Swedish Cybersecurity Act, DORA and an overview of which regulations require an SBOM. - [Regulations that require an SBOM](https://sbom.se/en/regulations/overview.md): The CRA requires an SBOM from manufacturers from 11 December 2027. NIS2 and DORA do not mention SBOM but set requirements that an SBOM is used for. An overview of the regulations in the EU and the US. - [NIS2 and the Swedish Cybersecurity Act](https://sbom.se/en/regulations/nis2.md): The NIS2 Directive is implemented in Sweden through the Cybersecurity Act, in force since 15 January 2026. This page covers who is in scope, what the act requires and how SBOM relates to the requirements. - [DORA](https://sbom.se/en/regulations/dora.md): DORA has applied since January 2025 and covers most firms supervised by the Swedish financial supervisory authority. This page covers what the regulation governs and how SBOM relates to the requirements. - [Cybersecurity certification](https://sbom.se/en/regulations/cybersecurity-certification.md): In November 2024 the Swedish Defence Materiel Administration (FMV) held an information meeting on cybersecurity certification of IT products and IT services. The presentation is listed under References. ## Resources - [Resources](https://sbom.se/en/resources.md): Scale SBOM, SBOM Observer, authorities and links to sources. - [Scale SBOM](https://sbom.se/en/resources/scale-sbom.md): Scale SBOM is an open framework that defines how organisations can operationally work with SBOM, VEX and VDR in digital supply chains, with an operational model, content requirements, and a self-assessment tool. - [SBOM Observer](https://sbom.se/en/resources/sbom-observer.md): SBOM Observer collects SBOMs from build pipelines and suppliers, monitors the components against vulnerability and licence data and checks every release against your rules. - [ENISA](https://sbom.se/en/resources/enisa.md): ENISA operates the Single Reporting Platform for the CRA and the European Vulnerability Database (EUVD), and publishes guidance on supply chain security. - [Cybersecurity in Sweden](https://sbom.se/en/resources/cybersecurity-in-sweden.md): The report Cybersecurity in Sweden 2024 from the Swedish National Cyber Security Centre (NCSC) covers risks in the supply chain, dependencies on suppliers and gaps in requirements. - [External links](https://sbom.se/en/resources/external-links.md): Links to authorities, standards bodies and vulnerability databases in the EU and the US, and to reports from companies and industry organisations. ## About the SBOM Guide - [SBOM Guide](https://sbom.se/en/index.md): A guide to SBOMs, software supply chains and the CRA - [About us](https://sbom.se/en/about.md): The SBOM Guide is run by Bytesafe, made by Bitfront AB in Stockholm. - [Contact us](https://sbom.se/en/contact.md): Questions about the content on sbom.se or about the Bytesafe products? Write to us. - [Cookie policy](https://sbom.se/en/privacy-policy.md): Which cookies sbom.se uses and how to change your choice.