SBOM basics
What an SBOM is, what it contains and which types and formats exist.
- What is SBOM?
An SBOM (Software Bill of Materials) is a machine-readable record of the components that a piece of software consists of. It is used for vulnerability management, licence checks and compliance, and becomes a legal requirement in the EU through the CRA.
- Why do we need SBOMs?
Vulnerabilities such as Log4Shell and Heartbleed showed how hard it is to answer whether you are affected when you do not know which components your software contains. That is the question an SBOM answers.
- Why is SBOM important for industry?
A product contains in-house code, open source and components from suppliers. SBOM gives manufacturers, customers and authorities a shared format for describing the content.
- What is in an SBOM?
An SBOM contains information about each component, such as name, version, supplier, identifier, licence and checksum, plus how the components depend on each other and who created the SBOM.
- What are Minimum Elements?
The SBOM Minimum Elements from NTIA in the United States state which data fields, which automation support and which practices an SBOM must meet at a minimum. CISA published a draft update in 2025.
- Different types of SBOMs
An SBOM can be created from a design, from source code, in the build, from a finished artefact or from a running system. CISA has defined six types, and they give different answers to what the software contains.
- SBOM formats and standards
CycloneDX and SPDX are the two standard formats for SBOMs. Both are open, machine-readable and supported by most tools. This page covers the background, the differences and what decides the choice.
- SBOM and SCA, what is the difference?
SCA (Software Composition Analysis) tools analyse which third-party components a piece of software contains. An SBOM is the result in a standard format that can be stored and shared.
- Other attestations than SBOM: SLSA
SLSA (Supply chain Levels for Software Artifacts) is a framework for attesting where, how and by whom software was built. It complements the SBOM, which describes the content.
- Common questions about SBOMs
What is an SBOM, is it a legal requirement, which format should you choose and how often should it be updated? Short answers to common questions about SBOMs.