# External links

Official sources for SBOM, VEX, VDR and vulnerability management

> Links to authorities, standards bodies and vulnerability databases in the EU and the US, and to reports from companies and industry organisations.

Updated: 5 October 2026  
URL: https://sbom.se/en/resources/external-links

## EU and Sweden

### European Commission

* [Cyber Resilience Act](https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act), the Commission's overview page with guidance and FAQ
* [Regulation (EU) 2024/2847](https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng), the CRA in the Official Journal of the European Union

### ENISA

* [ENISA](https://www.enisa.europa.eu/), the European Union Agency for Cybersecurity
* [Single Reporting Platform (SRP)](https://www.enisa.europa.eu/topics/product-security/single-reporting-platform-srp), the reporting platform for the CRA
* [EUVD](https://euvd.enisa.europa.eu/), the European Vulnerability Database

### Swedish National Cyber Security Centre (NCSC)

* [The Cybersecurity Act (NIS2), in Swedish](https://www.ncsc.se/sv/radgivning-och-stod/cybersakerhetslagen-nis2/det-har-ar-cybersakerhetslagen/)

### Swedish Civil Defence and Resilience Agency (MCF)

* [mcf.se](https://www.mcf.se/en/), formerly MSB

### BSI (Germany)

* [TR-03183](https://www.bsi.bund.de/dok/TR-03183-en), technical guideline with SBOM requirements for the CRA

## United States

### National Telecommunications and Information Administration (NTIA)

* [NTIA SBOM Resources](https://www.ntia.gov/sbom), including the SBOM Minimum Elements

### Cybersecurity and Infrastructure Security Agency (CISA)

* [CISA SBOM Resources](https://www.cisa.gov/sbom)

### National Institute of Standards and Technology (NIST)

* [Software Security in Supply Chains: Software Bill of Materials (SBOM)](https://www.nist.gov/itl/executive-order-14028-improving-nations-cybersecurity/software-security-supply-chains-software-1)

### National Security Agency (NSA)

* [NSA Releases Recommendations to Mitigate Software Supply Chain Risks](https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/3617462/nsa-releases-recommendations-to-mitigate-software-supply-chain-risks/)

## Standards and formats

* [CycloneDX](https://cyclonedx.org/), SBOM format from OWASP (ECMA-424)
* [SPDX](https://spdx.dev/), SBOM format from the Linux Foundation (ISO/IEC 5962:2021)
* [OpenVEX](https://openssf.org/projects/openvex/), VEX format from OpenSSF
* [SLSA](https://slsa.dev/), framework for attesting how software was built
* [Scale SBOM](https://scalesbom.org), framework for working with SBOM, VEX and VDR

## Vulnerability databases

* [CVE](https://www.cve.org/), identifiers for known vulnerabilities
* [NVD](https://nvd.nist.gov/), the US National Vulnerability Database
* [EUVD](https://euvd.enisa.europa.eu/), the European Vulnerability Database
* [OSV](https://osv.dev/), vulnerabilities in open source
* [GitHub Advisory Database](https://github.com/advisories)

## Open-source tools

* [Syft](https://github.com/anchore/syft) and [Grype](https://github.com/anchore/grype), create SBOMs and scan for vulnerabilities
* [Trivy](https://github.com/aquasecurity/trivy), create SBOMs and scan for vulnerabilities
* [cdxgen](https://github.com/CycloneDX/cdxgen), creates CycloneDX SBOMs
* [Dependency-Track](https://dependencytrack.org/), platform for analysing SBOMs
* [Observer CLI](https://github.com/sbom-observer/observer-cli), creates SBOMs

## Articles, reports and presentations

### MITRE

* [Data Normalization Challenges and Mitigations in Software Bill of Materials Processing](https://www.mitre.org/sites/default/files/2024-10/PR-24-2647-Data-Normalization-Challenges-Mitigations-Software-Bill-Of-Materials-Processing.pdf), October 2024

### Schneider Electric

* [SBOMs - The Missing Link](https://www.first.org/resources/papers/vulncon2024/Schneider-Electric-SBOM-Program-VulnCon-March-2024-FINAL-24-March-TLP-CLEAR.pdf), March 2024
* [SBOMs: Building customer trust through software transparency](https://blog.se.com/digital-transformation/cybersecurity/2025/02/06/what-are-sboms-software-bill-of-materials/), February 2025

### Automotive Information Sharing and Analysis Center (Auto-ISAC)

* [Auto-ISAC Software Bill of Materials (SBOM) Informational Report](https://automotiveisac.com/sbom-reports), January 2025
