Common questions about SBOMs
Short answers, with links to articles that go deeper
What is an SBOM?
An SBOM (Software Bill of Materials) is a machine-readable record of the components that a piece of software consists of: libraries, frameworks and other dependencies, with name, version and supplier. Read more in What is SBOM?
Is an SBOM a legal requirement?
Yes, for manufacturers of products with digital elements sold in the EU. The Cyber Resilience Act (CRA) requires an SBOM from 11 December 2027. NIS2 and DORA do not mention SBOM, but they set requirements for vulnerability handling and supply chain security. Read more in SBOM requirements in the CRA and Regulations that require an SBOM.
Does an SBOM have to be public?
No. The CRA does not require manufacturers to publish their SBOM. It is part of the technical documentation and a market surveillance authority can request it. Customers can require an SBOM in a contract.
What does an SBOM contain?
At least the name, version and supplier of each component, a unique identifier and the relationships between the components, plus who created the SBOM and when. Licences and checksums are often included too. Read more in What is in an SBOM? and What are Minimum Elements?
Does an SBOM contain vulnerabilities?
Normally not. An SBOM describes what the software consists of. Which vulnerabilities affect the components changes over time, and is worked out by comparing the SBOM against vulnerability databases. The assessment of whether a vulnerability actually affects the product is shared in a separate document, VEX.
Which format should I choose, CycloneDX or SPDX?
Both are open standards and both are accepted in most contexts. CycloneDX comes from OWASP and was designed for security analysis. SPDX comes from the Linux Foundation, started as a format for licence information and is an ISO standard. Choose the format that your tools and customers support. Read more in SBOM formats and standards.
How do you create an SBOM?
With a tool that reads source code, build output or container images, for example Syft, Trivy, cdxgen or Observer CLI. The SBOM should be created automatically in the build. Read more in How to create an SBOM.
How often should an SBOM be updated?
An SBOM describes one specific version of the software. Create a new one for every release and keep the old ones for as long as those versions are in use. Vulnerability monitoring, on the other hand, has to be continuous, because new vulnerabilities are found in components that have already shipped.
What is the difference between SBOM and SCA?
SCA (Software Composition Analysis) is a type of tool that analyses which open-source components a piece of software uses. An SBOM is a document in a standardised format that can be shared between organisations. Many SCA tools can create SBOMs. Read more in SBOM and SCA, what is the difference?
How do I get SBOMs from my suppliers?
Write it into the contract: the format, how often the SBOM is delivered and how. Read more in SBOM in public procurement and SBOM in software supply chains.
What do you do with all the SBOMs?
A single SBOM can be reviewed by hand. As the number grows you need a system that stores the SBOMs per release, monitors them against new vulnerabilities and shows which products are affected by a given component. SBOM Observer from Bytesafe, which runs this site, is one such tool. Dependency-Track is an open-source alternative.