This is the multi-page printable view of this section. Click here to print.

Return to the regular view of this page.

Regulatory Trends

Summarizes the regulatory standing of SBOM across jurisdictions, and the US executive order and federal procurement pathway.

The regulatory standing of SBOM differs by jurisdiction. The United States takes an executive-order pathway that leverages federal procurement, the European Union takes a directly effective legislative pathway, and most other countries remain at the stage of advisory guidelines. This section covers the United States first, followed by the EU Cyber Resilience Act and other jurisdictions such as India and Korea.

Regulatory Standing by Jurisdiction at a Glance

JurisdictionDocument/LegislationStandingSBOM Requirement
United StatesExecutive Order 14028 (2021), CISA minimum elementsFederal procurement recommendationSBOM provision for software delivered to the federal government
European UnionCyber Resilience Act, Regulation (EU) 2024/2847Legal obligation (with fines)Annex I Part II, top-level dependencies, machine-readable
IndiaCERT-In Technical Guidelines (2024)Voluntary recommendationBest practices for government and essential services
KoreaSoftware Supply Chain Security Guideline 1.0 (2024)Administrative recommendationRecommended SBOM generation and review procedures

Table 1. SBOM regulatory standing in major jurisdictions (source: primary source for each item; collected June 14, 2026)

United States: Leveraging Federal Procurement

US SBOM policy originates from an executive order. On May 12, 2021, shortly after the SolarWinds incident, Executive Order 14028 (“Improving the Nation’s Cybersecurity”) was signed and published in the Federal Register as 86 FR 26633. Section 10(j) of the order defined SBOM as “a formal record containing the details and supply chain relationships of various components used in building software,” and Section 4(f) directed the Secretary of Commerce, working with NTIA, to publish minimum elements for an SBOM within 60 days. This was the moment SBOM was elevated from a recommendation of the research community to a candidate requirement for federal procurement.

Under this mandate, NTIA published the minimum elements in July 2021, and responsibility for the work subsequently moved to CISA. Under Office of Management and Budget (OMB) Memorandum M-22-18, CISA holds the authority to update the NTIA minimum elements and has focused on tooling and operationalization. The results are the 2024 Framing Software Component Transparency, Third Edition, and the 2025 draft revision of the minimum elements. Changes in the data fields between the two documents are covered in Minimum Elements.

It is important to understand the exact nature of the US pathway. Executive Order 14028 is the basis for guidance requiring vendors that supply software to the federal government to provide an SBOM; it is not a general statute that applies to all software. CISA’s two documents themselves state that they do not create new federal requirements. The normative standing remains that of a procurement criterion and technical reference. Nonetheless, because the vast federal procurement market operates on this basis, it functions as a de facto requirement for companies that supply software to the US government.

The lineage of US SBOM policy, starting from Executive Order 14028 and the NTIA minimum elements in 2021, transferring to CISA, and branching into the 2024 Framing Third Edition and the 2025 draft revision of the minimum elements

Figure 1. Lineage of US SBOM policy documents (source: Executive Order 14028, NTIA 2021, CISA 2024 and 2025; collected June 14, 2026)

Sources

The White House (2021). Executive Order 14028 — Improving the Nation’s Cybersecurity, 86 FR 26633. https://www.federalregister.gov/documents/2021/05/17/2021-10460/improving-the-nations-cybersecurity. OMB (2022). M-22-18. https://www.whitehouse.gov/wp-content/uploads/2022/09/M-22-18.pdf. CISA SBOM Resource Hub https://www.cisa.gov/sbom. (all accessed: June 14, 2026)

1 - EU Cyber Resilience Act (CRA)

Summarizes the SBOM requirements and implementation timeline of the EU Cyber Resilience Act, the first major legislation to establish SBOM as a legal obligation.

The first major piece of legislation to establish SBOM as an explicit legal obligation is the EU Cyber Resilience Act (CRA, Regulation (EU) 2024/2847). Whereas the United States effectively mandates SBOM through the market of federal procurement, the CRA is a directly effective law that applies horizontally across products with digital elements.

In the CRA, the SBOM obligation appears in Annex I, Part II (vulnerability handling requirements), point (1). Manufacturers must identify and document the vulnerabilities and components contained in a product, and as a means of doing so, the CRA specifies that they must “draw up a software bill of materials, in a commonly used and machine-readable format, covering at the very least the top-level dependencies of the product.”

Two points that matter in practice differ from the US pathway.

  • The scope of the obligation is top-level dependencies: There is no obligation to expand the entire dependency tree; covering at least the top-level dependencies is sufficient. That said, going deeper than this is clearly the recommended direction.
  • It is an obligation to retain and submit, not to disclose: There is no obligation to disclose the SBOM to the general public. It is sufficient to retain it so that it can be submitted when a market surveillance authority makes a reasoned request.

The core of the CRA is that producing an SBOM is not a recommendation but a legal obligation backed by a system of fines.

Implementation Timeline

The phased EU CRA implementation timeline, running from publication and entry into force in 2024, through the reporting obligation in September 2026, to full application in December 2027

Figure 1. Phased implementation timeline of the EU CRA (source: Regulation (EU) 2024/2847; collected June 14, 2026)

The CRA was published in the Official Journal on November 20, 2024, and entered into force on December 10, 2024. Its application is staged: the Article 14 obligation to report exploited vulnerabilities and severe incidents applies from September 11, 2026, and full application of the essential cybersecurity requirements, including SBOM, begins on December 11, 2027.

Absence of Format Implementing Rules and a Practical Reference Point

As of June 2026, no official CRA-level implementing rule for SBOM format has been published. This means there is not yet a document that establishes, as an EU-wide binding norm, which schema and fields must be used to conform to the CRA.

The current practical reference point is Technical Guideline TR-03183-2 v2.1.0, published in August 2025 by Germany’s Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik, BSI). This document provides specific field mappings for CRA-conformant SBOM for both CycloneDX and SPDX. Note, however, that this is a German guideline, not an EU-wide binding norm.

Considerations for Open Source

The CRA uses commercial activity as its applicability criterion, and in principle excludes non-commercial open source that is distributed free of charge without commercial activity. This is a mechanism to avoid imposing manufacturer-level obligations directly on open source maintainers. However, the obligations still apply in full to manufacturers who integrate open source into a product and supply it commercially, so obtaining and managing SBOMs for open source components remains the manufacturer’s responsibility.

Sources

European Parliament and Council (2024). Regulation (EU) 2024/2847 — Cyber Resilience Act. OJ L, 2024/2847, 20.11.2024. https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng. European Commission, DG CNECT. Cyber Resilience Act. https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act. BSI. Technical Guideline TR-03183-2. (all accessed: June 14, 2026)

2 - India, Korea, and Other Jurisdictions

Summarizes SBOM recommendation guidelines from India’s CERT-In and other jurisdictions, including Korea.

Jurisdictions outside the United States and the European Union are generally at the recommendation stage. There is no legal enforcement or sanction, but these function as best practices that influence procurement and contracting practices.

India: CERT-In Technical Guidelines

The Indian Computer Emergency Response Team (CERT-In) published the Technical Guidelines on Software Bill of Materials (SBOM). This is a voluntary guideline aimed at government agencies, the public sector, essential services, and software producing and service companies, covering the value of SBOMs, best practices, minimum elements, and vulnerability tracking procedures. It has no legal force, but it influences government procurement and contracting practices.

In July 2025, CERT-In expanded this guideline to also cover Quantum BOM (QBOM), Cryptography BOM (CBOM), AI BOM (AIBOM), and Hardware BOM (HBOM). This is an example of how the bill of materials concept is spreading beyond software into cryptography, AI, and hardware. The expansion into AI BOM is covered further in 5. Tools and Automation and in the separate AI SBOM Compliance Guide.

The first edition of this guide began as a Korean translation of this CERT-In document. The current edition updates that skeleton with current primary sources from the United States and the European Union, and broadens it to a general practitioner’s perspective.

Korea: Software Supply Chain Security Guidelines

In Korea, the Ministry of Science and ICT, the National Intelligence Service, and the Korea Internet & Security Agency (KISA), among others, published the Software Supply Chain Security Guidelines 1.0 in May 2024. It recommends SBOM generation and vulnerability inspection procedures, and the use of the National Institute of Standards and Technology (NIST) Secure Software Development Framework (SSDF).

However, this is only an administrative guideline, and Korea’s current legal system does not yet have legislation that imposes a mandatory reporting obligation at the product level, as the EU Cyber Resilience Act does. Even so, Korean companies exporting software to the EU and the United States must directly meet the requirements of those markets, so building SBOM capability is a practical necessity regardless of domestic regulation.

Practical Implications

The legal standing differs by jurisdiction, but the skeleton of the data required converges. A well-built SBOM system, built once, can satisfy the requirements of multiple jurisdictions at the same time. If the system is designed around the strictest requirement among your export markets (currently the EU CRA), the recommendations of other jurisdictions are largely subsumed within it.

Sources

Indian Computer Emergency Response Team (CERT-In). Technical Guidelines on Software Bill of Materials (SBOM), CIGU-2024-0002. https://www.cert-in.org.in/. Ministry of Science and ICT, National Intelligence Service, Korea Internet & Security Agency (2024). Software Supply Chain Security Guidelines 1.0. https://www.kisa.or.kr/. (all accessed: June 14, 2026)