
Software bills of materials (SBOMs) have become an increasingly common feature of software development, driven by supply chain attacks, regulatory pressure and growing demand for greater transparency. Once considered a niche security practice, they are now required under regulations such as the EU’s Cyber Resilience Act, which places greater emphasis on understanding the components that make up modern software.
An SBOM is essentially an inventory of the libraries, packages and third-party components used to build an application. When a vulnerability is discovered, such as Log4Shell, it allows organisations to identify affected software much more quickly than relying on manual investigations.
As the Financial Times recently reported, however, many organisations are generating SBOMs to meet customer or regulatory requirements without making them part of their wider security processes. Producing an inventory is one thing; keeping it accurate, up to date and integrated with vulnerability management is another.
That distinction matters because software supply chains continue to grow in complexity. Most applications now rely on hundreds, if not thousands, of open-source and third-party components. Without visibility into those dependencies, identifying affected systems after a newly disclosed vulnerability can become a lengthy process.
The Cyber Resilience Act is expected to accelerate adoption further by requiring manufacturers to maintain software inventories throughout a product’s lifecycle rather than treating them as one-off documents. At the same time, researchers continue to highlight inconsistencies in automatically generated SBOMs, suggesting that the quality of the data remains just as important as its existence.
The value of an SBOM ultimately depends on how it is used. Organisations that integrate software inventories with asset management and vulnerability scanning are likely to respond to new threats more quickly than those treating them purely as compliance paperwork. As regulatory expectations continue to evolve, the focus is shifting from simply producing SBOMs to ensuring they remain accurate, accessible and useful when they are needed most.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543