Book an Appointment

SBOM Management for the Software Supply Chain

How to generate, distribute and operationalize software bills of materials (SBOMs) in a standards-compliant way – from format selection and build integration to continuous vulnerability correlation.

Last updated: July 2026 · Valeri Milke, ISO 27001 & ISO 42001 Lead Auditor

2open formats dominate in practice: CycloneDX and SPDX
3categories in the 2021 NTIA Minimum Elements
2026CISA Elements supersede the NTIA version (July 2026)
2027CRA main obligations apply from 11 December 2027

A Software Bill of Materials (SBOM) is a machine-readable inventory of all components of a piece of software – analogous to the bill of materials in manufacturing. At the latest since incidents like Log4Shell, it has become clear that organizations without component transparency cannot answer whether and where they are affected by a new vulnerability. With the Cyber Resilience Act, the SBOM becomes a legal requirement in the EU for products with digital elements for the first time; in parallel, CISA and international partners redefined the minimum contents of an SBOM in July 2026. SBOM management involves more than generating a file once: it is an ongoing process of generation, distribution, enrichment and analysis across the entire product lifecycle.

From format standard to legal obligation

Tap a milestone to reveal the details.

The Essentials at a Glance

Six topic blocks — tap to expand.

SBOM management in four views

From format selection to regulatory obligations — pick a tab for details.

ECMA-424 / ISO/IEC 5962
  • CycloneDX originates from the OWASP community and is standardized through Ecma committee TC54 — version 1.7 was published in December 2025 as ECMA-424 (2nd edition), with extended modeling for cryptographic artifacts and ML models, among other things.
  • SPDX is developed under the umbrella of the Linux Foundation; ISO/IEC 5962:2021 standardizes version 2.2.1, while the current specification 3.0.1 is going through the ISO process as ISO/IEC DIS 5962.
  • SPDX has its roots in license compliance, whereas CycloneDX is more strongly geared toward security use cases — both satisfy the CRA requirement of a commonly used and machine-readable format.
CycloneDXSPDXECMA-424ISO/IEC 5962TC54Linux Foundation

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

Ecma International · 2025

ECMA-424: CycloneDX Bill of Materials Specification, 2nd Edition

International standard for CycloneDX v1.7 (adopted December 2025); the 1st edition of June 2024 standardized version 1.6.

ISO/IEC · 2021

ISO/IEC 5962:2021 – SPDX Specification V2.2.1

ISO standardization of the SPDX format in version 2.2.1; the current SPDX specification 3.0.1 is going through the ISO process as ISO/IEC DIS 5962.

CISA / NSA / FBI und internationale Partner · 2026

2026 Minimum Elements for a Software Bill of Materials (SBOM)

Supersedes the 2021 NTIA Minimum Elements; adds, among others, component hashes, licenses, generation tool and generation context as minimum fields.

Amtsblatt der EU / EUR-Lex · 2024

Verordnung (EU) 2024/2847 (Cyber Resilience Act)

Annex I Part II requires an SBOM in a commonly used, machine-readable format covering at least the top-level dependencies; main obligations from 11 Dec 2027.

Bundesamt für Sicherheit in der Informationstechnik (BSI) · 2025

BSI TR-03183 Teil 2: Software Bill of Materials (SBOM), Version 2.1.0

Formal and subject-matter SBOM specifications as an entry aid to the CRA, including field mapping to SPDX and CycloneDX (as of August 2025).

OWASP Foundation · 2026

Dependency-Track Documentation

Documents the platform's core capabilities: consumption/production of CycloneDX SBOM and VEX, vulnerability sources, policy engine and API-first design.

Implementing the CRA's SBOM obligations in a structured way?

We support you with format selection, build integration and setting up ongoing SBOM operations – from gap analysis to toolchain. Contact us for a no-obligation initial consultation.