Software Bill of Materials (SBOM)
A formal, machine-readable inventory of the components, libraries and dependencies that make up a piece of software, with details such as supplier, version and relationships, used to manage vulnerability and supply-chain risk.
An SBOM lists each component in a software product, typically with its name, version, supplier, unique identifiers such as package URLs or CPE names, and its dependency relationships. The two most widely used formats are SPDX, a Linux Foundation project published as the international standard ISO/IEC 5962, and CycloneDX, an OWASP project also standardised by Ecma International. SBOMs are usually generated automatically by build tools or software composition analysis.
When a new vulnerability is disclosed, SBOMs let software producers and their customers quickly determine which products contain the affected component. US Executive Order 14028 of 2021 brought SBOMs to prominence in federal software procurement, and the EU Cyber Resilience Act requires manufacturers of products with digital elements to draw up an SBOM covering at least top-level dependencies. Medical and industrial device makers increasingly share SBOMs with customers.
An SBOM is only useful if it is accurate, updated with each release and matched against current vulnerability data. Depth varies from top-level dependencies to full transitive trees, and some components, especially in firmware, are hard to identify. VEX documents complement SBOMs by stating whether a listed vulnerability actually affects the product, and the NTIA minimum elements for an SBOM remain a widely cited baseline.
Key points
- A machine-readable list of software components and their relationships.
- SPDX (ISO/IEC 5962) and CycloneDX are the main formats.
- The EU Cyber Resilience Act requires manufacturers to draw up an SBOM.
- Speeds up impact analysis when a new vulnerability is disclosed.
Where AiVibe comes in
AiVibe is ISO/IEC 27001:2022 certified, and its security services include vulnerability assessment and penetration testing, code security analysis (SAST, DAST, IAST, SCA), compliance gap analysis and 24/7 monitoring; AiVedha.ai runs more than 170 automated website security checks.
Related terms
- Software Composition Analysis (SCA)Cybersecurity & Compliance
- Cyber Resilience Act (CRA)Cybersecurity & Compliance
- Software Supply Chain AttackCybersecurity & Compliance
- Common Vulnerabilities and Exposures (CVE)Cybersecurity & Compliance
- Vulnerability ManagementCybersecurity & Compliance
- IEC 62443 (ISA/IEC 62443)OT & Industrial Cybersecurity