What must an SBOM contain for the Cyber Resilience Act?
An SBOM (software bill of materials) is the list of parts your software is built from: the libraries, their versions and where they come from. The Cyber Resilience Act (Regulation (EU) 2024/2847) asks manufacturers to identify and document the vulnerabilities and components in their product, including by drawing up an SBOM in a commonly used and machine-readable format that covers at the very least the top-level dependencies (Annex I, Part II). The SBOM is also part of the technical documentation (Annex VII).
The Regulation does not name a format or a checklist. In practice people use CycloneDX or SPDX, and they use the NTIA minimum elements as a checklist.
The NTIA minimum elements
For each component, the data fields are the supplier name, the component name, the version, other unique identifiers (a package URL is the usual one) and the dependency relationships. For the document, the author of the SBOM data and a timestamp. The SBOM checker runs these checks on a CycloneDX or SPDX JSON file in your browser, and says which are missing.
German practice also looks at the stricter BSI TR-03183-2. A pass on the NTIA elements is not a statement of compliance.
Produce one
CycloneDX generators exist for most ecosystems:
npx @cyclonedx/cyclonedx-npm --output-file bom.json # npm projects
pip install cyclonedx-bom && cyclonedx-py environment > bom.json # Python environment
cargo install cargo-cyclonedx && cargo cyclonedx # Rust
go install github.com/CycloneDX/cyclonedx-gomod/cmd/cyclonedx-gomod@latest && cyclonedx-gomod app -json -output bom.json # Go
Generate it in your build, so it describes the artefact you ship and is attached to every release.
Check it
npx @ambolt/cra sbom bom.json --min 7
npx @ambolt/cra sbom bom.json --osv --fail-on-vulns # known vulnerabilities, via osv.dev
The --osv option sends package URLs (names and versions) to the public OSV database and nothing else; without it nothing leaves your machine. The CRA also expects you to follow vulnerabilities in your components, which is what a daily watch of the SBOM is for.
From SBOM to notices
The same file gives you a licence overview and a THIRD-PARTY-NOTICES text: licence notices. Rules of thumb on licence names, not legal advice.
Information only; check the Regulation for your product.
More from the blog
- Live SSL, domain and vulnerability badges for your README
- Check an npm or PyPI package for known vulnerabilities before you install
- Audit your sitemap and robots.txt in one call
- Check your GitHub repository for Cyber Resilience Act readiness in ten seconds
- All tools and prices
- Guides
Data and prices change; every API response states its source and date. Informational only, not financial, legal or tax advice.