# What is SBOM?

A list of ingredients for software

> An SBOM (Software Bill of Materials) is a machine-readable record of the components that a piece of software consists of. It is used for vulnerability management, licence checks and compliance, and becomes a legal requirement in the EU through the CRA.

Updated: 5 October 2026  
URL: https://sbom.se/en/sbom/what-is-sbom

An SBOM (*Software Bill of Materials*) is a record of the components that a piece of software consists of. It is often compared to a list of ingredients: it shows which libraries, modules, frameworks and other dependencies were used to build an application, with name, version and supplier.

An SBOM is machine-readable. It is created by one tool and read by others, which compare its content against databases of known vulnerabilities and licences.

## What an SBOM looks like

An SBOM is a file, usually JSON. This is a shortened example in the CycloneDX format with a single component:

```json
{
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "components": [
    {
      "type": "library",
      "name": "log4j-core",
      "version": "2.14.1",
      "purl": "pkg:maven/org.apache.logging.log4j/log4j-core@2.14.1"
    }
  ]
}
```

A real SBOM often contains hundreds or thousands of components and also describes how they depend on each other. [What is in an SBOM?](https://sbom.se/en/sbom/sbom-contents) goes through the fields.

## What an SBOM is used for

* **Vulnerability management.** When a vulnerability becomes known in a library, the SBOMs show which products and versions contain it. Without SBOMs, the question is answered by going through each system by hand.
* **Licences.** The SBOM shows which licences the components have, so that terms that cannot be combined with the product are found before delivery.
* **Procurement and supplier follow-up.** An SBOM from the supplier shows what purchased software contains, even when the source code is not available.
* **Compliance.** The [Cyber Resilience Act (CRA)](https://sbom.se/en/cra/sbom-requirements) requires manufacturers to draw up an SBOM from 11 December 2027.

## Background

Bills of materials have long been used in manufacturing to keep track of the parts a product consists of. For software, the work was driven from 2018 by the US agency NTIA together with industry. After Executive Order 14028, NTIA published a baseline in 2021 for what an SBOM must contain, the [SBOM Minimum Elements](https://sbom.se/en/sbom/minimum-elements).

In the EU, the CRA is the first regulation that makes the SBOM a legal requirement.

## Formats

The two formats in practical use are CycloneDX and SPDX. Both are open standards. [SBOM formats and standards](https://sbom.se/en/sbom/formats-and-standards) describes the differences.

## SBOMs at different stages

An SBOM can be created at different points in time, and the content differs. An SBOM from the source code lists the dependencies that are declared. An SBOM from the build lists the components that were actually included. An SBOM from a running system lists what is installed and running. [Different types of SBOMs](https://sbom.se/en/sbom/sbom-types) describes the six types.

## Other types of BOM

The same idea is used for other things than software components. CycloneDX defines the following, among others:

| Type                                    | Abbreviation | Describes                                                                  |
| --------------------------------------- | ------------ | -------------------------------------------------------------------------- |
| Software Bill of Materials              | SBOM         | Software components: libraries, modules, frameworks and other dependencies |
| Hardware Bill of Materials              | HBOM         | Physical components and hardware devices in a product                      |
| Cryptography Bill of Materials          | CBOM         | Cryptographic assets, such as algorithms, keys and certificates            |
| AI/Machine Learning Bill of Materials   | AI/ML-BOM    | Models, training data and frameworks in an AI solution                     |
| Software as a Service Bill of Materials | SaaSBOM      | Services, endpoints and data flows in a cloud service                      |

[VEX](https://sbom.se/en/vulnerabilities/what-is-vex) is not a bill of materials but a companion to one: a document that states whether a product is affected by a specific vulnerability.

## References

- [OWASP CycloneDX: Authorative Guide to SBOM](https://cyclonedx.org/guides/OWASP_CycloneDX-Authoritative-Guide-to-SBOM-en.pdf): En överskådlig introduktion till CycloneDX, ett av de mest populära formaten för SBOM:ar (Software Bill of Materials). Guiden tar upp allt från grundläggande principer till exempel på hur du kan implementera CycloneDX i praktiken.
- [CISA HBOM Framework - 2023](https://www.cisa.gov/sites/default/files/2023-09/A%20Hardware%20Bill%20of%20Materials%20Framework%20for%20Supply%20Chain%20Risk%20Management%20%28508%29.pdf): A Hardware Bill of Materials (HBOM) Framework for Supply Chain Risk Management
- [OWASP CycloneDX: Authorative Guide to CBOM](https://cyclonedx.org/guides/OWASP_CycloneDX-Authoritative-Guide-to-CBOM-en.pdf): En lättillgänglig genomgång av hur CycloneDX kan användas för att skapa CBOM:ar (Cryptography Bill of Materials). Guiden förklarar de viktigaste principerna för kryptografihantering och visar praktiska exempel på hur du kan använda CBOM.
- [CycloneDX BOM examples](https://github.com/CycloneDX/bom-examples): Examples of what CycloneDX SBOMs look like in practice. Other types of BOM files, such as HBOM and CBOM, are included.
- [SPDX SBOM examples](https://github.com/spdx/spdx-examples/tree/master/software): Examples of what SPDX SBOMs look like in practice.
- [SBOM Analyzer](https://bytesafe.dev/observer/sbom-analyzer): Gratis webbverktyg från Bytesafe som visar antal komponenter, sårbarheter och licenser i en SBOM.
