Software Bill of Materials (SBOM)
Definition
A structured, machine-readable inventory of the software components in a product or system. Captures component names, versions, licences, and dependency relationships. Standard formats include SPDX (ISO/IEC 5962:2021) and CycloneDX. US Executive Order 14028 (2021) mandated SBOMs for federal software suppliers.
- Full form
- Software Bill of Materials
- Standard formats
- SPDX (ISO/IEC 5962:2021), CycloneDX
- US mandate
- Executive Order 14028 (2021)
- Content captured
- Component names, versions, licences, dependencies
Common questions
Why did a US Executive Order specifically push SBOM adoption?+
EO 14028 followed high-profile supply-chain incidents and aimed to give federal agencies visibility into what software components, including open-source dependencies, sit inside the products they procure, so vulnerabilities in those components can be identified and tracked.
How does an SBOM help during a newly disclosed vulnerability?+
When a vulnerability is disclosed in a specific library or version, an organisation with SBOMs on file can search them to immediately identify which products and deployments include that exact component, rather than manually auditing source trees under time pressure.
Is SPDX or CycloneDX the mandated single format?+
No single format is universally mandated. Both are widely recognised machine-readable standards, SPDX carrying ISO/IEC 5962:2021 status, and organisations or regulations may accept either or specify one depending on context.
Related terms
- Dependency Confusion
- An attack technique in which an attacker publishes a public package with the same name as an organisation's internal private package at...
- NIST SP 800-161R1
- The US National Institute of Standards and Technology publication 'Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations' (Revision 1, 2022)....
- Software Composition Analysis (SCA)
- A category of security tooling that scans source code, build manifests, and container images to identify open-source and third-party components, match them...
- Transitive Dependency
- A software library that an application does not import directly but is pulled in automatically because a direct dependency requires it. Transitive...
- Vendor Due Diligence
- The pre-procurement and ongoing process of assessing a supplier's security practices before and during a commercial relationship. In supply-chain risk management, due...