Glossary A–ZLetter S
SBOM (software bill of materials)
An SBOM (software bill of materials) is a machine-readable list of the components a piece of software is made of, above all the libraries it includes, with name and version.
Common formats are SPDX and CycloneDX.
If a vulnerability becomes known in a widely used library, the manufacturer can use the bill of materials to check quickly which of its products and versions are affected. A media player typically contains an operating system, playback components and libraries for video, networking and encryption; any of them may be affected. The Cyber Resilience Act requires manufacturers to draw up an SBOM covering at least the top-level dependencies, as part of the technical documentation.
The regulation does not oblige manufacturers to publish the bill of materials, but market surveillance authorities can request it. An SBOM is only useful if it is updated with every version and regularly checked against databases of known vulnerabilities. It says what is inside a piece of software, not whether the software is secure. Operators can ask their supplier how it tracks vulnerabilities in third-party components.