SBOM and SCA, what is the difference?
SCA is an analysis, an SBOM is a document
SCA (Software Composition Analysis) and SBOM (Software Bill of Materials) are often mentioned together, and they overlap. The difference is that SCA is something you do, while an SBOM is something you have.
SCA: the analysis
An SCA tool analyses a piece of software to find out which third-party components and dependencies it contains, and which known vulnerabilities and licences belong to them. The analysis is usually done on the source code during development, but it can also be done on a finished binary or container.
Most SCA tools can save the result as an SBOM in CycloneDX or SPDX.
SBOM: the document
An SBOM is a record of the components in a standard format. It is not tied to the tool that created it, and it can be analysed by someone who does not have access to the source code.
When the SBOM is needed
- Purchased software. The buyer has no source code to run an SCA tool on. An SBOM from the supplier gives the same insight.
- History. When a vulnerability becomes known, the question is often how long it has been in the product and which delivered versions are affected. Searching stored SBOMs is easier than re-analysing old versions of the source code.
- Requirements from customers and regulations. The Cyber Resilience Act (CRA) requires an SBOM, not a particular tool.
How they are used together
In development, the SCA tool finds problems early, before the code ships. In the build, an SBOM is created for every release and stored. After delivery, the stored SBOMs are monitored against new vulnerabilities, without the source code having to be analysed again.
How to create an SBOM lists tools.