SBOM Guide
Resources

External links

Official sources for SBOM, VEX, VDR and vulnerability management

EU and Sweden

European Commission

ENISA

Swedish National Cyber Security Centre (NCSC)

Swedish Civil Defence and Resilience Agency (MCF)

BSI (Germany)

  • TR-03183, technical guideline with SBOM requirements for the CRA

United States

National Telecommunications and Information Administration (NTIA)

Cybersecurity and Infrastructure Security Agency (CISA)

National Institute of Standards and Technology (NIST)

National Security Agency (NSA)

Standards and formats

  • CycloneDX, SBOM format from OWASP (ECMA-424)
  • SPDX, SBOM format from the Linux Foundation (ISO/IEC 5962:2021)
  • OpenVEX, VEX format from OpenSSF
  • SLSA, framework for attesting how software was built
  • Scale SBOM, framework for working with SBOM, VEX and VDR

Vulnerability databases

  • CVE, identifiers for known vulnerabilities
  • NVD, the US National Vulnerability Database
  • EUVD, the European Vulnerability Database
  • OSV, vulnerabilities in open source
  • GitHub Advisory Database

Open-source tools

Articles, reports and presentations

MITRE

Schneider Electric

Automotive Information Sharing and Analysis Center (Auto-ISAC)

On this page