Skip to content

Software Bill of Materials (SBOM)

Definition

A structured, machine-readable inventory of the software components in a product or system. Captures component names, versions, licences, and dependency relationships. Standard formats include SPDX (ISO/IEC 5962:2021) and CycloneDX. US Executive Order 14028 (2021) mandated SBOMs for federal software suppliers.

Full form
Software Bill of Materials
Standard formats
SPDX (ISO/IEC 5962:2021), CycloneDX
US mandate
Executive Order 14028 (2021)
Content captured
Component names, versions, licences, dependencies

Common questions

Why did a US Executive Order specifically push SBOM adoption?+

EO 14028 followed high-profile supply-chain incidents and aimed to give federal agencies visibility into what software components, including open-source dependencies, sit inside the products they procure, so vulnerabilities in those components can be identified and tracked.

How does an SBOM help during a newly disclosed vulnerability?+

When a vulnerability is disclosed in a specific library or version, an organisation with SBOMs on file can search them to immediately identify which products and deployments include that exact component, rather than manually auditing source trees under time pressure.

Is SPDX or CycloneDX the mandated single format?+

No single format is universally mandated. Both are widely recognised machine-readable standards, SPDX carrying ISO/IEC 5962:2021 status, and organisations or regulations may accept either or specify one depending on context.

Related terms

Dependency Confusion
An attack technique in which an attacker publishes a public package with the same name as an organisation's internal private package at...
NIST SP 800-161R1
The US National Institute of Standards and Technology publication 'Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations' (Revision 1, 2022)....
Software Composition Analysis (SCA)
A category of security tooling that scans source code, build manifests, and container images to identify open-source and third-party components, match them...
Transitive Dependency
A software library that an application does not import directly but is pulled in automatically because a direct dependency requires it. Transitive...
Vendor Due Diligence
The pre-procurement and ongoing process of assessing a supplier's security practices before and during a commercial relationship. In supply-chain risk management, due...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.