Why it matters
Modern software is mostly assembled from open source and third party components. When a serious flaw appears in a widely used library, as happened with Log4Shell in December 2021, the first question is which products contain it. Without an SBOM, answering takes days or weeks; with one, it is a search.
What it contains
For each component: its name, version, supplier, unique identifiers, licence and relationship to other components. The two main standard formats are SPDX and CycloneDX. SBOMs are usually generated automatically during the build process and updated with each release.
Regulation
The EU Cyber Resilience Act requires manufacturers of products with digital elements to draw up an SBOM as part of their technical documentation. In the US, a 2021 executive order made SBOMs a reference practice for software sold to federal agencies. CISA publishes guidance on minimum elements and use.
How it is used
SBOMs feed software composition analysis tools, which match components against known CVEs and help prioritise vulnerabilities. For buyers, asking suppliers for an SBOM is becoming part of third party risk management.




