SBOM Guide
SBOM basics

What is SBOM?

A list of ingredients for software

An SBOM (Software Bill of Materials) is a record of the components that a piece of software consists of. It is often compared to a list of ingredients: it shows which libraries, modules, frameworks and other dependencies were used to build an application, with name, version and supplier.

An SBOM is machine-readable. It is created by one tool and read by others, which compare its content against databases of known vulnerabilities and licences.

What an SBOM looks like

An SBOM is a file, usually JSON. This is a shortened example in the CycloneDX format with a single component:

{
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "components": [
    {
      "type": "library",
      "name": "log4j-core",
      "version": "2.14.1",
      "purl": "pkg:maven/org.apache.logging.log4j/log4j-core@2.14.1"
    }
  ]
}

A real SBOM often contains hundreds or thousands of components and also describes how they depend on each other. What is in an SBOM? goes through the fields.

What an SBOM is used for

  • Vulnerability management. When a vulnerability becomes known in a library, the SBOMs show which products and versions contain it. Without SBOMs, the question is answered by going through each system by hand.
  • Licences. The SBOM shows which licences the components have, so that terms that cannot be combined with the product are found before delivery.
  • Procurement and supplier follow-up. An SBOM from the supplier shows what purchased software contains, even when the source code is not available.
  • Compliance. The Cyber Resilience Act (CRA) requires manufacturers to draw up an SBOM from 11 December 2027.

Background

Bills of materials have long been used in manufacturing to keep track of the parts a product consists of. For software, the work was driven from 2018 by the US agency NTIA together with industry. After Executive Order 14028, NTIA published a baseline in 2021 for what an SBOM must contain, the SBOM Minimum Elements.

In the EU, the CRA is the first regulation that makes the SBOM a legal requirement.

Formats

The two formats in practical use are CycloneDX and SPDX. Both are open standards. SBOM formats and standards describes the differences.

SBOMs at different stages

An SBOM can be created at different points in time, and the content differs. An SBOM from the source code lists the dependencies that are declared. An SBOM from the build lists the components that were actually included. An SBOM from a running system lists what is installed and running. Different types of SBOMs describes the six types.

Other types of BOM

The same idea is used for other things than software components. CycloneDX defines the following, among others:

TypeAbbreviationDescribes
Software Bill of MaterialsSBOMSoftware components: libraries, modules, frameworks and other dependencies
Hardware Bill of MaterialsHBOMPhysical components and hardware devices in a product
Cryptography Bill of MaterialsCBOMCryptographic assets, such as algorithms, keys and certificates
AI/Machine Learning Bill of MaterialsAI/ML-BOMModels, training data and frameworks in an AI solution
Software as a Service Bill of MaterialsSaaSBOMServices, endpoints and data flows in a cloud service

VEX is not a bill of materials but a companion to one: a document that states whether a product is affected by a specific vulnerability.

References

  • OWASP CycloneDX: Authorative Guide to SBOM

    En överskådlig introduktion till CycloneDX, ett av de mest populära formaten för SBOM:ar (Software Bill of Materials). Guiden tar upp allt från grundläggande principer till exempel på hur du kan implementera CycloneDX i praktiken.

    PDF, cyclonedx.org
  • CISA HBOM Framework - 2023

    A Hardware Bill of Materials (HBOM) Framework for Supply Chain Risk Management

    PDF, cisa.gov
  • OWASP CycloneDX: Authorative Guide to CBOM

    En lättillgänglig genomgång av hur CycloneDX kan användas för att skapa CBOM:ar (Cryptography Bill of Materials). Guiden förklarar de viktigaste principerna för kryptografihantering och visar praktiska exempel på hur du kan använda CBOM.

    PDF, cyclonedx.org
  • CycloneDX BOM examples

    Examples of what CycloneDX SBOMs look like in practice. Other types of BOM files, such as HBOM and CBOM, are included.

    github.com
  • SPDX SBOM examples

    Examples of what SPDX SBOMs look like in practice.

    github.com
  • SBOM Analyzer

    Gratis webbverktyg från Bytesafe som visar antal komponenter, sårbarheter och licenser i en SBOM.

    bytesafe.dev

On this page