SBOM: Software Bill of Materials in Cybersecurity

Application Security
ByDecipherU Editorial
How is it pronounced?
ESS-bom/ˈɛs.bɒm/

Software Bill of Materials; 'S' letter plus 'bom'.

SBOM stands for Software Bill of Materials. A Software Bill of Materials is a formal inventory of all components, libraries, and dependencies in a software product. SBOMs use standardized formats like SPDX or CycloneDX to document component names, versions, and supplier relationships.

Why this matters in 2026

SolarWinds shipped malicious signed updates to ~18,000 customers in 2020 because no SBOM existed at the build-environment level. Executive Order 14028 cited this directly. SBOM consumption (machine-readable, programmatically validated) is now mandatory in NIST CSF, FedRAMP, and CMMC under negotiation.

Read the related Decipher File

How SBOM Is Used in Cybersecurity

Security engineers generate SBOMs during the build process and monitor them for newly disclosed vulnerabilities in third-party components. GRC analysts audit SBOM completeness to meet supply chain security requirements under frameworks like NIST SSDF and Executive Order 14028. Security architects define SBOM policies that govern which components are approved for use.

Read the full glossary entry: SBOM in Cybersecurity

Cybersecurity Roles That Work with SBOM

Related Cybersecurity Acronyms

Frequently asked questions

What does SBOM stand for?

SBOM stands for Software Bill of Materials. A Software Bill of Materials is a formal inventory of all components, libraries, and dependencies in a software product. SBOMs use standardized formats like SPDX or CycloneDX to document component names, versions, and supplier relationships.

What is SBOM used for in cybersecurity?

Security engineers generate SBOMs during the build process and monitor them for newly disclosed vulnerabilities in third-party components. GRC analysts audit SBOM completeness to meet supply chain security requirements under frameworks like NIST SSDF and Executive Order 14028. Security architects define SBOM policies that govern which components are approved for use.

Last verified: April 2026?Report an inaccuracy