ambolt

What must an SBOM contain for the Cyber Resilience Act?

An SBOM (software bill of materials) is the list of parts your software is built from: the libraries, their versions and where they come from. The Cyber Resilience Act (Regulation (EU) 2024/2847) asks manufacturers to identify and document the vulnerabilities and components in their product, including by drawing up an SBOM in a commonly used and machine-readable format that covers at the very least the top-level dependencies (Annex I, Part II). The SBOM is also part of the technical documentation (Annex VII).

The Regulation does not name a format or a checklist. In practice people use CycloneDX or SPDX, and they use the NTIA minimum elements as a checklist.

The NTIA minimum elements

For each component, the data fields are the supplier name, the component name, the version, other unique identifiers (a package URL is the usual one) and the dependency relationships. For the document, the author of the SBOM data and a timestamp. The SBOM checker runs these checks on a CycloneDX or SPDX JSON file in your browser, and says which are missing.

German practice also looks at the stricter BSI TR-03183-2. A pass on the NTIA elements is not a statement of compliance.

Produce one

CycloneDX generators exist for most ecosystems:

npx @cyclonedx/cyclonedx-npm --output-file bom.json   # npm projects
pip install cyclonedx-bom && cyclonedx-py environment > bom.json   # Python environment
cargo install cargo-cyclonedx && cargo cyclonedx        # Rust
go install github.com/CycloneDX/cyclonedx-gomod/cmd/cyclonedx-gomod@latest && cyclonedx-gomod app -json -output bom.json   # Go

Generate it in your build, so it describes the artefact you ship and is attached to every release.

Check it

npx @ambolt/cra sbom bom.json --min 7
npx @ambolt/cra sbom bom.json --osv --fail-on-vulns   # known vulnerabilities, via osv.dev

The --osv option sends package URLs (names and versions) to the public OSV database and nothing else; without it nothing leaves your machine. The CRA also expects you to follow vulnerabilities in your components, which is what a daily watch of the SBOM is for.

From SBOM to notices

The same file gives you a licence overview and a THIRD-PARTY-NOTICES text: licence notices. Rules of thumb on licence names, not legal advice.

Information only; check the Regulation for your product.

Try it free: npm package vulnerability checker runs the same call in your browser (one free check per tool and IP address per day). API reference

More from the blog

Data and prices change; every API response states its source and date. Informational only, not financial, legal or tax advice.