# Regulations that require an SBOM

Where an SBOM is an explicit requirement and where it is a means

> The CRA requires an SBOM from manufacturers from 11 December 2027. NIS2 and DORA do not mention SBOM but set requirements that an SBOM is used for. An overview of the regulations in the EU and the US.

Updated: 5 October 2026  
URL: https://sbom.se/en/regulations/overview

Regulations relate to SBOM in two ways. Some require explicitly that an SBOM is produced. Others set requirements for vulnerability handling and supply chain security without mentioning SBOM, and an SBOM is then one way of meeting them.

## Overview

| Regulation                             | Applies to                                      | Requires an SBOM explicitly | Applies since                                                    |
| -------------------------------------- | ----------------------------------------------- | --------------------------- | ---------------------------------------------------------------- |
| Cyber Resilience Act (CRA)             | Products with digital elements on the EU market | Yes                         | Reporting 11 September 2026, other requirements 11 December 2027 |
| NIS2 and the Swedish Cybersecurity Act | Organisations in 18 sectors                     | No                          | 15 January 2026 in Sweden                                        |
| DORA                                   | The financial sector                            | No                          | January 2025                                                     |
| FDA (US)                               | Medical devices with software                   | Yes                         | 2023                                                             |

## EU

### Cyber Resilience Act (CRA)

The CRA is the first EU regulation that makes the SBOM a legal requirement. Manufacturers must draw up an SBOM in a commonly used and machine-readable format that covers at least the top-level dependencies of the product. The SBOM does not have to be published, but a market surveillance authority can request it. Read more in [Cyber Resilience Act (CRA)](https://sbom.se/en/cra/overview) and [SBOM requirements in the CRA](https://sbom.se/en/cra/sbom-requirements).

### NIS2 and the Swedish Cybersecurity Act

NIS2 sets requirements for organisations, not for products. The directive does not mention SBOM, but it requires supply chain security and vulnerability handling, among other things. Read more in [NIS2 and the Swedish Cybersecurity Act](https://sbom.se/en/regulations/nis2).

### DORA

DORA applies to the financial sector and governs ICT risk management, incident reporting, testing and third-party risk. The regulation does not mention SBOM. Read more in [DORA](https://sbom.se/en/regulations/dora).

### German guidance: BSI TR-03183

The German Federal Office for Information Security (BSI) has published technical guideline TR-03183, where part 2 specifies the content and format of an SBOM for CRA purposes. It is not binding outside Germany, but manufacturers in other countries use it as a reference too.

## United States

### Executive Order 14028

The executive order of May 2021 on improving the nation's cybersecurity tasked NTIA with defining what an SBOM must contain at a minimum. The result, the [SBOM Minimum Elements](https://sbom.se/en/sbom/minimum-elements), was published in July 2021 and is still the most common baseline. CISA published a draft update in August 2025.

### FDA and medical devices

Since 2023 the US Food and Drug Administration (FDA) has required an SBOM in premarket submissions for medical devices that contain software and can connect to the internet.

## Requirements in contracts and procurement

Beyond legislation, SBOM requirements are increasingly written into contracts between customer and supplier. [SBOM in public procurement](https://sbom.se/en/guides/public-procurement) describes how such requirements can be worded.
