External links
Official sources for SBOM, VEX, VDR and vulnerability management
EU and Sweden
European Commission
- Cyber Resilience Act, the Commission's overview page with guidance and FAQ
- Regulation (EU) 2024/2847, the CRA in the Official Journal of the European Union
ENISA
- ENISA, the European Union Agency for Cybersecurity
- Single Reporting Platform (SRP), the reporting platform for the CRA
- EUVD, the European Vulnerability Database
Swedish National Cyber Security Centre (NCSC)
Swedish Civil Defence and Resilience Agency (MCF)
- mcf.se, formerly MSB
BSI (Germany)
- TR-03183, technical guideline with SBOM requirements for the CRA
United States
National Telecommunications and Information Administration (NTIA)
- NTIA SBOM Resources, including the SBOM Minimum Elements
Cybersecurity and Infrastructure Security Agency (CISA)
National Institute of Standards and Technology (NIST)
National Security Agency (NSA)
Standards and formats
- CycloneDX, SBOM format from OWASP (ECMA-424)
- SPDX, SBOM format from the Linux Foundation (ISO/IEC 5962:2021)
- OpenVEX, VEX format from OpenSSF
- SLSA, framework for attesting how software was built
- Scale SBOM, framework for working with SBOM, VEX and VDR
Vulnerability databases
- CVE, identifiers for known vulnerabilities
- NVD, the US National Vulnerability Database
- EUVD, the European Vulnerability Database
- OSV, vulnerabilities in open source
- GitHub Advisory Database
Open-source tools
- Syft and Grype, create SBOMs and scan for vulnerabilities
- Trivy, create SBOMs and scan for vulnerabilities
- cdxgen, creates CycloneDX SBOMs
- Dependency-Track, platform for analysing SBOMs
- Observer CLI, creates SBOMs
Articles, reports and presentations
MITRE
- Data Normalization Challenges and Mitigations in Software Bill of Materials Processing, October 2024
Schneider Electric
- SBOMs - The Missing Link, March 2024
- SBOMs: Building customer trust through software transparency, February 2025