Glossary Updates12 new terms added to the glossaries · October 2, 2026, 22:44 CEST
AI TechDocKnowledge

Glossary · OT cybersecurity

Software bill of materials (SBOM)

Also known as: SBOM, Software BOM

German: Software-Stückliste (SBOM)

In software supply chain security, a software bill of materials (SBOM) is a formal, machine-readable inventory of the software components, libraries and their versions and suppliers contained in a software or firmware product, including dependency relationships. Common formats are SPDX and CycloneDX.

  • OT security

In one sentence

A software bill of materials (SBOM) is a machine-readable list of the software components, versions and suppliers inside a software or firmware product.

Example

The SBOM for firmware version 3.2 of a gateway lists the Linux kernel version, the OpenSSL library version and the vendor's own OPC UA stack, each with a unique identifier.

Explained in context

Context cards connect this term with others to answer one question. Also in British English and German.

How it applies

  • Product development: SBOMs are ideally generated automatically in the build pipeline, so that they match the released binary exactly. SPDX is standardized as ISO/IEC 5962; CycloneDX is published by OWASP and standardized by Ecma International.
  • Compliance: The Cyber Resilience Act (CRA) requires manufacturers to identify and document components, including by drawing up an SBOM covering at least top-level dependencies, as part of the technical documentation.
  • Operation: Operators use SBOMs together with their Asset inventory to find affected products when a vulnerability in a common component becomes known.
  • Documentation: Treat the SBOM as a controlled, versioned document tied to one product release. Release notes, SBOM and open-source license notices draw on the same component data and should be generated from one source.

SBOM vs. open-source license notice

A license notice lists open-source components to meet license obligations and is written for humans. An SBOM lists all components, including proprietary ones, in a machine-readable format for security and supply chain analysis.

By knowledge.aitechdoc.world · Published September 26, 2026 · Last reviewed

Source: AI TechDoc Knowledge editorial definition, based on Regulation (EU) 2024/2847 (CRA), ISO/IEC 5962 (SPDX) and CycloneDX

Definitions follow the cited standards and specifications. Where a source is a copyrighted publication, such as an ISO, IEC or EN standard, the definition is a close paraphrase, not a verbatim quotation, so as not to infringe copyright. We recommend reading the original publication. The sections “How it applies” are editorial commentary by AI TechDoc Knowledge and are not part of any standard.

Seen a mistake? Send us a note!