Regulations that require an SBOM
Where an SBOM is an explicit requirement and where it is a means
Regulations relate to SBOM in two ways. Some require explicitly that an SBOM is produced. Others set requirements for vulnerability handling and supply chain security without mentioning SBOM, and an SBOM is then one way of meeting them.
Overview
| Regulation | Applies to | Requires an SBOM explicitly | Applies since |
|---|---|---|---|
| Cyber Resilience Act (CRA) | Products with digital elements on the EU market | Yes | Reporting 11 September 2026, other requirements 11 December 2027 |
| NIS2 and the Swedish Cybersecurity Act | Organisations in 18 sectors | No | 15 January 2026 in Sweden |
| DORA | The financial sector | No | January 2025 |
| FDA (US) | Medical devices with software | Yes | 2023 |
EU
Cyber Resilience Act (CRA)
The CRA is the first EU regulation that makes the SBOM a legal requirement. Manufacturers must draw up an SBOM in a commonly used and machine-readable format that covers at least the top-level dependencies of the product. The SBOM does not have to be published, but a market surveillance authority can request it. Read more in Cyber Resilience Act (CRA) and SBOM requirements in the CRA.
NIS2 and the Swedish Cybersecurity Act
NIS2 sets requirements for organisations, not for products. The directive does not mention SBOM, but it requires supply chain security and vulnerability handling, among other things. Read more in NIS2 and the Swedish Cybersecurity Act.
DORA
DORA applies to the financial sector and governs ICT risk management, incident reporting, testing and third-party risk. The regulation does not mention SBOM. Read more in DORA.
German guidance: BSI TR-03183
The German Federal Office for Information Security (BSI) has published technical guideline TR-03183, where part 2 specifies the content and format of an SBOM for CRA purposes. It is not binding outside Germany, but manufacturers in other countries use it as a reference too.
United States
Executive Order 14028
The executive order of May 2021 on improving the nation's cybersecurity tasked NTIA with defining what an SBOM must contain at a minimum. The result, the SBOM Minimum Elements, was published in July 2021 and is still the most common baseline. CISA published a draft update in August 2025.
FDA and medical devices
Since 2023 the US Food and Drug Administration (FDA) has required an SBOM in premarket submissions for medical devices that contain software and can connect to the internet.
Requirements in contracts and procurement
Beyond legislation, SBOM requirements are increasingly written into contracts between customer and supplier. SBOM in public procurement describes how such requirements can be worded.