Glossary · OT cybersecurity
Software bill of materials (SBOM)
Also known as: SBOM, Software BOM
German: Software-Stückliste (SBOM)
In software supply chain security, a software bill of materials (SBOM) is a formal, machine-readable inventory of the software components, libraries and their versions and suppliers contained in a software or firmware product, including dependency relationships. Common formats are SPDX and CycloneDX.
- OT security
In one sentence
A software bill of materials (SBOM) is a machine-readable list of the software components, versions and suppliers inside a software or firmware product.
Example
The SBOM for firmware version 3.2 of a gateway lists the Linux kernel version, the OpenSSL library version and the vendor's own OPC UA stack, each with a unique identifier.
Explained in context
Context cards connect this term with others to answer one question. Also in British English and German.
- The SBOM under BSI TR-03183-2: an inventory, not a vulnerability reportWhat does BSI TR-03183-2 require of a software bill of materials, and how does it relate to the CRA?UKDeutsch
- BSI guidance on the CRA: context-dependent, not contradictoryWhen two pieces of BSI guidance on the Cyber Resilience Act seem irreconcilable, is the guidance contradictory?UKDeutsch
- How the four SDK types interoperateWhere do developer, publishing, platform and hardware SDKs meet in practice?UKDeutsch
How it applies
- Product development: SBOMs are ideally generated automatically in the build pipeline, so that they match the released binary exactly. SPDX is standardized as ISO/IEC 5962; CycloneDX is published by OWASP and standardized by Ecma International.
- Compliance: The Cyber Resilience Act (CRA) requires manufacturers to identify and document components, including by drawing up an SBOM covering at least top-level dependencies, as part of the technical documentation.
- Operation: Operators use SBOMs together with their Asset inventory to find affected products when a vulnerability in a common component becomes known.
- Documentation: Treat the SBOM as a controlled, versioned document tied to one product release. Release notes, SBOM and open-source license notices draw on the same component data and should be generated from one source.
SBOM vs. open-source license notice
A license notice lists open-source components to meet license obligations and is written for humans. An SBOM lists all components, including proprietary ones, in a machine-readable format for security and supply chain analysis.