Regulatory Trends
Summarizes the regulatory standing of SBOM across jurisdictions, and the US executive order and federal procurement pathway.
The regulatory standing of SBOM differs by jurisdiction. The United States takes an executive-order
pathway that leverages federal procurement, the European Union takes a directly effective
legislative pathway, and most other countries remain at the stage of advisory guidelines. This
section covers the United States first, followed by the
EU Cyber Resilience Act and
other jurisdictions such as India and Korea.
Regulatory Standing by Jurisdiction at a Glance
| Jurisdiction | Document/Legislation | Standing | SBOM Requirement |
|---|
| United States | Executive Order 14028 (2021), CISA minimum elements | Federal procurement recommendation | SBOM provision for software delivered to the federal government |
| European Union | Cyber Resilience Act, Regulation (EU) 2024/2847 | Legal obligation (with fines) | Annex I Part II, top-level dependencies, machine-readable |
| India | CERT-In Technical Guidelines (2024) | Voluntary recommendation | Best practices for government and essential services |
| Korea | Software Supply Chain Security Guideline 1.0 (2024) | Administrative recommendation | Recommended SBOM generation and review procedures |
Table 1. SBOM regulatory standing in major jurisdictions (source: primary source for each
item; collected June 14, 2026)
United States: Leveraging Federal Procurement
US SBOM policy originates from an executive order. On May 12, 2021, shortly after the SolarWinds
incident, Executive Order 14028 (“Improving the Nation’s Cybersecurity”) was signed and published
in the Federal Register as 86 FR 26633. Section 10(j) of the order defined SBOM as “a formal record
containing the details and supply chain relationships of various components used in building
software,” and Section 4(f) directed the Secretary of Commerce, working with NTIA, to publish
minimum elements for an SBOM within 60 days. This was the moment SBOM was elevated from a
recommendation of the research community to a candidate requirement for federal procurement.
Under this mandate, NTIA published the minimum elements in July 2021, and responsibility for the
work subsequently moved to CISA. Under Office of Management and Budget (OMB) Memorandum M-22-18,
CISA holds the authority to update the NTIA minimum elements and has focused on tooling and
operationalization. The results are the 2024 Framing Software Component Transparency, Third
Edition, and the 2025 draft revision of the minimum elements. Changes in the data fields between
the two documents are covered in Minimum Elements.
It is important to understand the exact nature of the US pathway. Executive Order 14028 is the
basis for guidance requiring vendors that supply software to the federal government to provide an
SBOM; it is not a general statute that applies to all software. CISA’s two documents themselves
state that they do not create new federal requirements. The normative standing remains that of a
procurement criterion and technical reference. Nonetheless, because the vast federal procurement
market operates on this basis, it functions as a de facto requirement for companies that supply
software to the US government.

Figure 1. Lineage of US SBOM policy documents (source: Executive Order 14028, NTIA 2021, CISA
2024 and 2025; collected June 14, 2026)
Sources
The White House (2021). Executive Order 14028 — Improving the Nation’s Cybersecurity, 86 FR
26633.
https://www.federalregister.gov/documents/2021/05/17/2021-10460/improving-the-nations-cybersecurity.
OMB (2022). M-22-18.
https://www.whitehouse.gov/wp-content/uploads/2022/09/M-22-18.pdf. CISA SBOM Resource Hub
https://www.cisa.gov/sbom. (all accessed: June 14, 2026)
1 - EU Cyber Resilience Act (CRA)
Summarizes the SBOM requirements and implementation timeline of the EU Cyber Resilience Act, the first major legislation to establish SBOM as a legal obligation.
The first major piece of legislation to establish SBOM as an explicit legal obligation is the EU
Cyber Resilience Act (CRA, Regulation (EU) 2024/2847). Whereas the United States effectively
mandates SBOM through the market of federal procurement, the CRA is a directly effective law that
applies horizontally across products with digital elements.
Legal Basis of the SBOM Obligation
In the CRA, the SBOM obligation appears in Annex I, Part II (vulnerability handling requirements),
point (1). Manufacturers must identify and document the vulnerabilities and components contained
in a product, and as a means of doing so, the CRA specifies that they must “draw up a software
bill of materials, in a commonly used and machine-readable format, covering at the very least the
top-level dependencies of the product.”
Two points that matter in practice differ from the US pathway.
- The scope of the obligation is top-level dependencies: There is no obligation to expand the
entire dependency tree; covering at least the top-level dependencies is sufficient. That said,
going deeper than this is clearly the recommended direction.
- It is an obligation to retain and submit, not to disclose: There is no obligation to disclose the
SBOM to the general public. It is sufficient to retain it so that it can be submitted when a
market surveillance authority makes a reasoned request.
The core of the CRA is that producing an SBOM is not a recommendation but a legal obligation backed
by a system of fines.
Implementation Timeline

Figure 1. Phased implementation timeline of the EU CRA (source: Regulation (EU) 2024/2847;
collected June 14, 2026)
The CRA was published in the Official Journal on November 20, 2024, and entered into force on
December 10, 2024. Its application is staged: the Article 14 obligation to report exploited
vulnerabilities and severe incidents applies from September 11, 2026, and full application of the
essential cybersecurity requirements, including SBOM, begins on December 11, 2027.
As of June 2026, no official CRA-level implementing rule for SBOM format has been published. This
means there is not yet a document that establishes, as an EU-wide binding norm, which schema and
fields must be used to conform to the CRA.
The current practical reference point is Technical Guideline TR-03183-2 v2.1.0, published in
August 2025 by Germany’s Federal Office for Information Security (Bundesamt für Sicherheit in der
Informationstechnik, BSI). This document provides specific field mappings for CRA-conformant SBOM
for both CycloneDX and SPDX. Note, however, that this is a German guideline, not an EU-wide binding
norm.
Considerations for Open Source
The CRA uses commercial activity as its applicability criterion, and in principle excludes
non-commercial open source that is distributed free of charge without commercial activity. This is
a mechanism to avoid imposing manufacturer-level obligations directly on open source maintainers.
However, the obligations still apply in full to manufacturers who integrate open source into a
product and supply it commercially, so obtaining and managing SBOMs for open source components
remains the manufacturer’s responsibility.
Sources
European Parliament and Council (2024). Regulation (EU) 2024/2847 — Cyber Resilience Act. OJ L,
2024/2847, 20.11.2024. https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng. European Commission,
DG CNECT. Cyber Resilience Act.
https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act. BSI. Technical Guideline
TR-03183-2. (all accessed: June 14, 2026)
2 - India, Korea, and Other Jurisdictions
Summarizes SBOM recommendation guidelines from India’s CERT-In and other jurisdictions, including Korea.
Jurisdictions outside the United States and the European Union are generally at the recommendation
stage. There is no legal enforcement or sanction, but these function as best practices that
influence procurement and contracting practices.
India: CERT-In Technical Guidelines
The Indian Computer Emergency Response Team (CERT-In) published the Technical Guidelines on
Software Bill of Materials (SBOM). This is a voluntary guideline aimed at government agencies,
the public sector, essential services, and software producing and service companies, covering the
value of SBOMs, best practices, minimum elements, and vulnerability tracking procedures. It has no
legal force, but it influences government procurement and contracting practices.
In July 2025, CERT-In expanded this guideline to also cover Quantum BOM (QBOM), Cryptography BOM
(CBOM), AI BOM (AIBOM), and Hardware BOM (HBOM). This is an example of how the bill of materials
concept is spreading beyond software into cryptography, AI, and hardware. The expansion into AI
BOM is covered further in 5. Tools and Automation and in the separate
AI SBOM Compliance Guide.
The first edition of this guide began as a Korean translation of this CERT-In document. The
current edition updates that skeleton with current primary sources from the United States and the
European Union, and broadens it to a general practitioner’s perspective.
Korea: Software Supply Chain Security Guidelines
In Korea, the Ministry of Science and ICT, the National Intelligence Service, and the Korea
Internet & Security Agency (KISA), among others, published the Software Supply Chain Security
Guidelines 1.0 in May 2024. It recommends SBOM generation and vulnerability inspection procedures,
and the use of the National Institute of Standards and Technology (NIST) Secure Software
Development Framework (SSDF).
However, this is only an administrative guideline, and Korea’s current legal system does not yet
have legislation that imposes a mandatory reporting obligation at the product level, as the EU
Cyber Resilience Act does. Even so, Korean companies exporting software to the EU and the United
States must directly meet the requirements of those markets, so building SBOM capability is a
practical necessity regardless of domestic regulation.
Practical Implications
The legal standing differs by jurisdiction, but the skeleton of the data required converges. A
well-built SBOM system, built once, can satisfy the requirements of multiple jurisdictions at the
same time. If the system is designed around the strictest requirement among your export markets
(currently the EU CRA), the recommendations of other jurisdictions are largely subsumed within it.
Sources
Indian Computer Emergency Response Team (CERT-In). Technical Guidelines on Software Bill of
Materials (SBOM), CIGU-2024-0002. https://www.cert-in.org.in/. Ministry of Science and ICT,
National Intelligence Service, Korea Internet & Security Agency (2024). Software Supply Chain
Security Guidelines 1.0. https://www.kisa.or.kr/. (all accessed: June 14, 2026)