Why is SBOM important for industry?
Manufacturers, buyers and authorities need the same facts about the software
A software product rarely consists only of code developed in-house. It contains open source, commercial libraries and components from subcontractors, which in turn build on components from others. For industrial products the same is true of the embedded software in machines, vehicles and control systems.
SBOM gives every link in the chain a shared, machine-readable way to describe what a product contains.
For manufacturers
- Vulnerability management over the whole lifetime. Industrial products are often in use for many years. With an SBOM per version you can see which delivered versions are affected when a new vulnerability becomes known.
- Legal requirements. The Cyber Resilience Act (CRA) requires an SBOM for products with digital elements from 11 December 2027, and vulnerability handling during a support period of at least five years.
- Customer requirements. Customers in the financial sector and the public sector ask for SBOMs in procurements and contracts.
For buyers
- Insight without source code. An SBOM shows what a purchased product contains, even when the source code is not handed over.
- Your own monitoring. The buyer can monitor the SBOM against new vulnerabilities instead of waiting for word from the supplier.
- Comparing suppliers. Whether a supplier can deliver a complete SBOM says something about how well the supplier knows its own product.
In the supply chain
When a subcontractor delivers an SBOM, the manufacturer can bring the content into its own SBOM. The customer then gets a record that covers the whole product, not only the outermost layer. This requires every link to use the same format and fill in the same basic information, which is the purpose of the SBOM Minimum Elements.
SBOM in software supply chains describes how SBOMs are shared between supplier and customer.