Global regulatory intelligence

Map global software supply chain obligations

As cybersecurity threats continue to rise, governments and organizations worldwide are implementing strict SBOM regulations to strengthen software supply chain security. These regulations are designed to enhance transparency, reduce vulnerabilities, and ensure that businesses take proactive measures to secure their software ecosystems.To remain compliant, companies must adhere to these evolving standards, which help mitigate security risks, prevent potential cyberattacks, and avoid costly legal consequences.This page provides a comprehensive breakdown of the most critical global regulations, detailing their specific requirements, impact on businesses, and the role of SBOM in ensuring compliance. With a clear and structured format, this guide simplifies complex regulatory frameworks, making it easier for organizations to understand and implement the necessary security measures.

Track SBOM, vulnerability disclosure, incident reporting, and software transparency obligations by region, industry, and enforcement stage.

101 regulations tracked
0 explicit SBOM signals
0 dated deadlines

101 matching obligations

Need to map these obligations to your products? Turn global SBOM, vulnerability, and software supply chain requirements into a concrete evidence workflow with Exodos.

Taiwan Cyber Security Management Act

Asia-Pacific · Taiwan · Government & Public Sector, Critical Infrastructure · effective

effective

Taiwan cybersecurity law governing government agencies and specific non-government agencies, including security maintenance and incident reporting.

Primary provision Taiwan Cyber Security Management Act Cyber Security Management Act
Critical Infrastructure Incident Reporting Governance Risk Management Evidence implicit SBOM relevance Regulation

US FY2027 NDAA Artificial Intelligence Functional Bill of Materials (AIBOM)

North America · United States · Government & Public Sector, AI & Data, Software & Digital Services · proposed

proposed

Proposed FY2027 NDAA Section 1652 would require DFARS updates barring DoD contracts for goods or services that use AI unless the contractor submits an AIBOM before award, renewal, or extension and maintains it for updates to DoD components within 48 hours.

Primary provision S. 4784 RS, FY2027 NDAA, Section 1652(a)-(d), Artificial Intelligence Functional Bill of Materials include details related to the software, data, and hardware
AIBOM SBOM AI Supply Chain Model Transparency Dataset Transparency Hardware Transparency Procurement Security Secure Sharing Evidence Contractual Reporting explicit SBOM relevance Bill / Proposal

CISA/G7 Software Bill of Materials for AI Minimum Elements

Global · G7 / United States / European Union / Japan / United Kingdom / Canada · AI & Data, Software & Digital Services, Critical Infrastructure · guidance

guidance

Joint CISA and G7 guidance defining supplemental minimum elements for SBOMs used with AI systems, including model, dataset, infrastructure, security, and system-level transparency.

Primary provision CISA/G7 Software Bill of Materials for AI - Minimum Elements AI systems are software systems
AIBOM AI SBOM SBOM Model Transparency Dataset Transparency AI Supply Chain Evidence explicit SBOM relevance Guidance

US CIRCIA Cyber Incident Reporting

North America · United States · Critical Infrastructure, Healthcare & Life Sciences, Financial Services · proposed

proposed

US critical infrastructure incident reporting law requiring CISA to finalize rules for covered cyber incident and ransom payment reporting by covered entities.

Primary provision CIRCIA covered cyber incident and ransom payment reporting report covered cyber incidents to CISA
Incident Reporting Ransomware Reporting Evidence Critical Infrastructure Governance adjacent SBOM relevance Regulation

US FCC Cyber Trust Mark

North America · United States · Connected Products & IoT · guidance

guidance

Voluntary US cybersecurity labeling program for consumer IoT products, built around conformance testing, label authorization, registry information, and NIST technical criteria.

Primary provision FCC IoT cybersecurity labeling program, Report and Order FCC 24-26 U.S. Cyber Trust Mark
IoT Labeling Product Security Vulnerability Management Secure Updates Technical Documentation adjacent SBOM relevance Certification

UK Network and Information Systems Regulations

Europe · United Kingdom · Critical Infrastructure, Software & Digital Services · effective

effective

UK framework for network and information system security in operators of essential services and relevant digital service providers, with security and incident reporting duties.

Risk Management Incident Reporting Operational Resilience Evidence Governance implicit SBOM relevance Regulation

UK PRA Operational Incident and Third-Party Reporting

Europe · United Kingdom · Financial Services · upcoming

upcoming

PRA policy for more consistent reporting of operational incidents and material third-party arrangements by regulated financial firms.

Incident Reporting Third-Party Risk Operational Resilience Supplier Risk Evidence adjacent SBOM relevance Regulation

UK Software Security Code of Practice

Europe · United Kingdom · Software & Digital Services, General Enterprise, Government & Public Sector · guidance

guidance

UK government software vendor guidance designed to reduce software supply chain attacks and resilience incidents through secure design, development, deployment, communication, and procurement practices.

Primary provision UK Software Security Code of Practice and NCSC implementation guidance, Theme 1 reducing the likelihood and impact of software supply chain attacks
SBOM Secure Development Supplier Risk Vulnerability Management Software Transparency Evidence explicit SBOM relevance Guidance

Australia Cyber Security Act 2024

Asia-Pacific · Australia · General Enterprise, Critical Infrastructure, Software & Digital Services · effective

effective

Australian cyber reform package introducing ransomware and cyber extortion payment reporting and broader cyber incident coordination mechanisms.

Primary provision Cyber Security Act 2024, ransomware payment reporting ransomware payment and cyber extortion payment reporting
Ransomware Reporting Incident Reporting Evidence Governance Critical Infrastructure adjacent SBOM relevance Regulation

Australia Security Standards for Smart Devices

Asia-Pacific · Australia · Connected Products & IoT, Software & Digital Services · effective

effective

Australian rules introducing mandatory cyber security standards for most consumer smart devices, with obligations that create a need for product software inventory, update, and vulnerability evidence.

Primary provision Cyber Security (Security Standards for Smart Device) Rules 2025 mandatory cyber security standards
Product Security Secure Updates Vulnerability Management Conformity Evidence Software Transparency implicit SBOM relevance Regulation

Australia Security of Critical Infrastructure Act

Asia-Pacific · Australia · Critical Infrastructure, Healthcare & Life Sciences · effective

effective

Critical infrastructure security framework with mandatory cyber incident reporting and risk management obligations for covered assets.

Incident Reporting Critical Infrastructure Risk Management Supplier Risk Evidence implicit SBOM relevance Regulation

Canada Critical Cyber Systems Protection Act

North America · Canada · Critical Infrastructure, Financial Services, Software & Digital Services · effective

effective

Canadian cyber security law establishing a framework to protect critical cyber systems, including operator obligations for cyber security programs, incident reporting, supply chain risk, and third-party dependencies.

Primary provision Bill C-8, Critical Cyber Systems Protection Act protect critical cyber systems
Supply Chain Security Third-Party Risk Incident Reporting Cybersecurity Program Evidence implicit SBOM relevance Regulation

Canadian Centre for Cyber Security Software Supply Chain Guidance

North America · Canada · Critical Infrastructure, Government & Public Sector, Software & Digital Services · guidance

guidance

Canadian guidance for protecting organizations from software supply chain threats, including supplier assessment and software component inventory/SBOM considerations.

SBOM Supplier Risk Supply Chain Security Vulnerability Management Risk Management explicit SBOM relevance Guidance

Japan Cyber Infrastructure Provider Guidelines

Asia-Pacific · Japan · Software & Digital Services · proposed

proposed

Draft METI and NCO guidelines describing expected roles for providers that develop, supply, and operate software and cyber infrastructure.

Secure Development Supplier Risk Vulnerability Management Governance Evidence implicit SBOM relevance Regulation

China Cybersecurity Law

Asia-Pacific · China · Critical Infrastructure, General Enterprise · effective

effective

Foundational Chinese cybersecurity law covering network operator security duties, critical information infrastructure protections, security incidents, and network product obligations.

Risk Management Incident Response Critical Infrastructure Product Security Vulnerability Management Evidence implicit SBOM relevance Regulation

Korea Act on Protection of Information and Communications Infrastructure

Asia-Pacific · South Korea · Critical Infrastructure, Government & Public Sector, Software & Digital Services · effective

effective

Korean framework for protecting major information and communications infrastructure against electronic intrusion and disruption.

Critical Infrastructure Risk Management Incident Response Evidence Governance implicit SBOM relevance Regulation

Korea KISA IoT Security Certification

Asia-Pacific · South Korea · Connected Products & IoT · guidance

guidance

KISA IoT security certification evaluates connected devices across authentication, data protection, cryptography, software security, updates, technical support, OS, network, and hardware security.

IoT Labeling Product Security Secure Updates Vulnerability Management Conformity Evidence adjacent SBOM relevance Certification

Saudi NCA Essential Cybersecurity Controls

Middle East · Saudi Arabia · Government & Public Sector, Critical Infrastructure, General Enterprise · effective

effective

Minimum cybersecurity requirements for Saudi government organizations and critical national infrastructure operators, covering governance, defense, resilience, cloud, third parties, and ICS.

Governance Risk Management Third-Party Risk Cloud Security Industrial Control Systems Evidence implicit SBOM relevance Framework

Saudi NCA Critical Systems Cybersecurity Controls

Middle East · Saudi Arabia · Government & Public Sector, Critical Infrastructure · effective

effective

Saudi critical systems controls extending the ECC for national critical systems across governance, defense, resilience, and third-party/cloud cybersecurity.

Critical Infrastructure Third-Party Risk Cloud Security Resilience Evidence implicit SBOM relevance Framework

UNECE UN Regulation No. 155 Cybersecurity Management System

Global · UNECE Contracting Parties · Automotive & Mobility · effective

effective

Vehicle type approval regulation requiring cybersecurity management systems and risk controls across vehicle lifecycle and supply chain.

Primary provision UN Regulation No. 155, cybersecurity management system Cyber Security Management System
Secure Development Supply Chain Security Vulnerability Management Risk Management Evidence Audit Trail implicit SBOM relevance Regulation

UNECE UN Regulation No. 156 Software Update Management System

Global · UNECE Contracting Parties · Automotive & Mobility · effective

effective

Vehicle type approval regulation for software update management systems, including safe and secure software update processes and update documentation.

Primary provision UN Regulation No. 156, software update management system Software Update Management System
Secure Updates Change Management Technical Documentation Evidence Audit Trail implicit SBOM relevance Regulation

Auto-ISAC SBOM Best Practices

Global · International · Automotive & Mobility · guidance

guidance

Automotive industry guidance on SBOM program design, supplier exchange, vulnerability operations, confidentiality, and automation across OEM and multi-tier supplier ecosystems.

Primary provision Auto-ISAC SBOM Informational Report, automotive SBOM use automation is essential to SBOM adoption
SBOM Supplier Risk Vulnerability Management Software Transparency Secure Sharing Evidence explicit SBOM relevance Guidance

IMDRF SBOM for Medical Device Cybersecurity

Global · IMDRF Members · Healthcare & Life Sciences · guidance

guidance

International regulator guidance on SBOM principles and practices for medical device cybersecurity across manufacturers, healthcare providers, and other stakeholders.

Primary provision IMDRF N73 SBOM principles and practices for medical device cybersecurity Software Bill of Materials for Medical Device Cybersecurity
SBOM Vulnerability Management Software Transparency Post-Market Monitoring Evidence explicit SBOM relevance Guidance

CISA and International Partners Shared Vision for SBOM

Global · International · Software & Digital Services, Critical Infrastructure, Government & Public Sector · guidance

guidance

Joint international guidance setting a shared vision for SBOM as a core tool for vulnerability management, secure-by-design development, and software supply chain transparency.

Primary provision CISA and international partners shared vision for SBOM Software Bill of Materials
SBOM Software Transparency Vulnerability Management Secure Development Supply Chain Security explicit SBOM relevance Guidance

IEC 62443-4-1 Secure Product Development Lifecycle

Global · International · Industrial & Manufacturing, Critical Infrastructure · effective

effective

Industrial automation and control system standard defining secure product development lifecycle practices for component suppliers.

Primary provision IEC 62443-4-1, secure product development lifecycle requirements Secure product development lifecycle requirements
Secure Development Vulnerability Management Secure Updates Technical Documentation Evidence explicit SBOM relevance Standard

IEC 62443-4-2 Technical Security Requirements for IACS Components

Global · International · Industrial & Manufacturing, Critical Infrastructure · effective

effective

Component-level security standard for industrial control system products, covering embedded devices, host devices, network devices, and software applications.

Primary provision IEC 62443-4-2, IACS component technical security requirements Technical security requirements for IACS components
Product Security Secure Development Vulnerability Management Technical Documentation Evidence implicit SBOM relevance Standard

IEC 62443-2-1 IACS Security Program Requirements

Global · International · Industrial & Manufacturing, Critical Infrastructure · effective

effective

Program-level industrial automation security management standard for asset owners operating control systems and OT environments.

Primary provision IEC 62443-2-1, IACS security program IACS security program
Risk Management Governance Vulnerability Management Supplier Risk Evidence implicit SBOM relevance Standard

IEC 62443-3-3 System Security Requirements and Security Levels

Global · International · Industrial & Manufacturing, Critical Infrastructure · effective

effective

Industrial control system security standard defining system security requirements and target security levels for zones and conduits.

Primary provision IEC 62443-3-3, system security requirements and security levels System security requirements and security levels
Risk Management Product Security Access Control Monitoring Evidence adjacent SBOM relevance Standard

ISO/IEC 27001 Information Security Management Systems

Global · International · General Enterprise, Software & Digital Services · effective

effective

International information security management system standard used as a baseline for governance, risk treatment, supplier controls, and audit evidence.

Primary provision ISO/IEC 27001:2022, information security management systems information security management systems
Governance Risk Management Supplier Risk Evidence Audit Trail adjacent SBOM relevance Standard

ISO/IEC 27002 Information Security Controls

Global · International · General Enterprise, Software & Digital Services · effective

effective

Reference control catalogue for information security controls, including supplier relationships, secure development, vulnerability management, and asset management.

Primary provision ISO/IEC 27002:2022, information security controls information security controls
Risk Management Supplier Risk Secure Development Vulnerability Management Evidence adjacent SBOM relevance Standard

ISO/IEC 27036 Supplier Relationship Security

Global · International · General Enterprise, Software & Digital Services · effective

effective

Supplier relationship security standard family covering information security risks in ICT supplier and acquirer relationships.

Primary provision ISO/IEC 27036 supplier relationships information security for supplier relationships
Supplier Risk Third-Party Risk Procurement Security Evidence Governance implicit SBOM relevance Standard

ISO/IEC 27034 Application Security

Global · International · Software & Digital Services · effective

effective

Application security standard family for integrating security controls into application lifecycle and organizational governance.

Primary provision ISO/IEC 27034 application security application security
Secure Development Risk Management Technical Documentation Evidence adjacent SBOM relevance Standard

ISO/IEC 42001 AI Management System

Global · International · AI & Data, Software & Digital Services · effective

effective

AI management system standard for organizations providing or using AI systems, supporting governance, risk controls, and lifecycle evidence.

Primary provision ISO/IEC 42001, artificial intelligence management system artificial intelligence management system
AI Governance Risk Management Technical Documentation Monitoring Evidence adjacent SBOM relevance Standard

NIST SP 800-218 Secure Software Development Framework

North America · United States · Government & Public Sector, Software & Digital Services · guidance

guidance

US secure software development framework used by federal software supply chain policy and procurement assurance programs.

Primary provision NIST SP 800-218, PO.1.3 and PS/PW/RV practice groups Secure Software Development Framework
Secure Development SBOM Vulnerability Management Evidence Attestation explicit SBOM relevance Guidance

NIST SP 800-161 Rev. 1 Cybersecurity Supply Chain Risk Management

North America · United States · Government & Public Sector, Critical Infrastructure, Software & Digital Services · guidance

guidance

Cybersecurity supply chain risk management guidance for federal systems and organizations, covering suppliers, products, services, and system components.

Primary provision NIST SP 800-161 Rev. 1, C-SCRM controls and practices Cybersecurity Supply Chain Risk Management Practices
Supplier Risk Supply Chain Security SBOM Risk Management Evidence explicit SBOM relevance Guidance

NIST Cybersecurity Framework 2.0

Global · International · General Enterprise, Critical Infrastructure · guidance

guidance

Cybersecurity risk management framework organized around govern, identify, protect, detect, respond, and recover outcomes.

Primary provision NIST CSF 2.0, GV.SC cybersecurity supply chain risk management cybersecurity supply chain risk management
Governance Risk Management Supplier Risk Vulnerability Management Evidence implicit SBOM relevance Framework

NIST SP 800-53 Rev. 5 System and Services Acquisition Controls

North America · United States · Government & Public Sector, Software & Digital Services · guidance

guidance

Federal security and privacy control catalogue with acquisition, supply chain, developer testing, and flaw remediation controls.

Primary provision NIST SP 800-53 Rev. 5, SA and SR control families Security and Privacy Controls
Supplier Risk Secure Development Vulnerability Management Evidence Audit Trail implicit SBOM relevance Framework

CISA NTIA Minimum Elements for SBOM

Global · International · Software & Digital Services, Government & Public Sector · guidance

guidance

Baseline SBOM guidance defining minimum data fields, automation support, and practices for generating, sharing, and using SBOMs.

Primary provision NTIA minimum elements for SBOM minimum elements for a Software Bill of Materials
SBOM Software Transparency Supplier Risk Vulnerability Management Evidence explicit SBOM relevance Guidance

CISA 2025 Minimum Elements for SBOM

Global · United States / International · Software & Digital Services, Government & Public Sector, Critical Infrastructure · guidance

guidance

CISA update to the SBOM minimum elements baseline, reflecting the current state of maturity in software transparency and supply chain security and expanding expected SBOM capabilities.

Primary provision CISA 2025 Minimum Elements for a Software Bill of Materials current state of maturity
SBOM Software Transparency Vulnerability Management Supplier Risk Evidence explicit SBOM relevance Guidance

CISA Joint Coordinated Vulnerability Disclosure Program Guidance

Global · United States / International · Software & Digital Services, Connected Products & IoT, Critical Infrastructure · guidance

guidance

Joint CISA, NSA, JPCERT/CC, NCSC-NL, and NCSC-UK guidance for software suppliers and online service providers to establish coordinated vulnerability disclosure programs with clear reporting paths, researcher communication, triage, remediation, and disclosure processes.

Primary provision CISA joint guide, Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers Coordinated Vulnerability Disclosure Program
Vulnerability Disclosure Vulnerability Management CVE Assignment security.txt SSVC Safe Harbor Supplier Communication Evidence adjacent SBOM relevance Guidance

CISA Vulnerability Exploitability eXchange Status Justifications

Global · International · Software & Digital Services, Critical Infrastructure · guidance

guidance

Guidance for communicating whether a known vulnerability affects a product, reducing false positives in SBOM-driven vulnerability operations.

Primary provision CISA VEX status justifications Vulnerability Exploitability eXchange
VEX Vulnerability Management Software Transparency Evidence Supplier Communication explicit SBOM relevance Guidance

CISA Known Exploited Vulnerabilities Catalog

Global · International · Critical Infrastructure, Software & Digital Services, Government & Public Sector · guidance

guidance

Catalog of vulnerabilities known to be exploited in the wild, used for prioritized remediation and risk-based vulnerability management.

Primary provision CISA KEV catalog Known Exploited Vulnerabilities Catalog
Vulnerability Management Remediation Evidence Incident Response adjacent SBOM relevance Guidance

CISA Secure by Design Guidance

Global · International · Software & Digital Services, Connected Products & IoT · guidance

guidance

Secure by Design guidance urging technology manufacturers to make secure product development and vulnerability handling core business practices.

Primary provision CISA Secure by Design Secure by Design
Secure Development Vulnerability Disclosure Secure Defaults Evidence Governance implicit SBOM relevance Guidance

SLSA Supply-chain Levels for Software Artifacts

Global · International · Software & Digital Services · guidance

guidance

Open framework for improving build integrity and provenance across software supply chains, from source through build and distribution.

Primary provision SLSA v1.0 software supply chain integrity framework Supply-chain Levels for Software Artifacts
Build Provenance Secure Development Supply Chain Security Evidence Attestation adjacent SBOM relevance Framework

OpenSSF Scorecard

Global · International · Software & Digital Services · guidance

guidance

Open-source project health and security scoring tool used to evaluate dependency risk signals across source repositories.

Primary provision OpenSSF Scorecard project security checks automated security tool
Supplier Risk Open Source Risk Secure Development Evidence adjacent SBOM relevance Framework

OWASP Software Component Verification Standard

Global · International · Software & Digital Services · guidance

guidance

OWASP verification standard for software components and supply chain controls, including inventory, integrity, provenance, and vulnerability practices.

Primary provision OWASP Software Component Verification Standard Software Component Verification Standard
SBOM Supply Chain Security Secure Development Vulnerability Management Evidence explicit SBOM relevance Framework

CycloneDX SBOM Standard

Global · International · Software & Digital Services · guidance

guidance

Machine-readable bill of materials standard supporting SBOM, SaaSBOM, VEX, CBOM, and other software supply chain transparency use cases.

Primary provision CycloneDX bill of materials standard full-stack Bill of Materials standard
SBOM VEX Software Transparency Vulnerability Management Evidence explicit SBOM relevance Standard

CycloneDX Cryptography Bill of Materials (CBOM)

Global · International · Software & Digital Services, Critical Infrastructure, General Enterprise · guidance

guidance

CycloneDX CBOM capability for representing cryptographic assets, relationships, algorithms, keys, certificates, and dependencies to support cryptographic risk and post-quantum readiness.

Primary provision CycloneDX Cryptography Bill of Materials capability algorithms, keys, certificates
CBOM Cryptographic Inventory Cryptographic Agility PQC Readiness Supply Chain Security Evidence explicit SBOM relevance Standard

NIST SP 1800-38B Quantum Readiness: Cryptographic Discovery

North America · United States · Government & Public Sector, Critical Infrastructure, General Enterprise · guidance

guidance

NIST NCCoE practice guide for cryptographic discovery during post-quantum migration, including testing discovery tools and building inventory architecture.

Primary provision NIST SP 1800-38B, Quantum Readiness: Cryptographic Discovery Quantum Readiness: Cryptographic Discovery
CBOM Cryptographic Discovery Cryptographic Inventory PQC Readiness Risk Management Evidence adjacent SBOM relevance Guidance

SPDX ISO/IEC 5962 Software Bill of Materials Standard

Global · International · Software & Digital Services · effective

effective

ISO-standardized SBOM and software package data exchange format used for component, license, security, and provenance transparency.

Primary provision SPDX specification and ISO/IEC 5962 Software Package Data Exchange
SBOM Software Transparency License Compliance Provenance Evidence explicit SBOM relevance Standard

FedRAMP Rev. 5 Cloud Security Authorization

North America · United States · Government & Public Sector, Software & Digital Services · effective

effective

Federal cloud security authorization baseline based on NIST SP 800-53 Rev. 5 controls, including supply chain, vulnerability, and configuration evidence.

Primary provision FedRAMP Rev. 5 security authorization baseline Rev. 5 baselines
Cloud Security Vulnerability Management Supplier Risk Evidence Continuous Monitoring implicit SBOM relevance Framework

DoD Cybersecurity Maturity Model Certification 2.0

North America · United States · Government & Public Sector, Software & Digital Services · phased

phased

DoD contractor cybersecurity certification program for protecting federal contract information and controlled unclassified information.

Primary provision DoD CMMC program Cybersecurity Maturity Model Certification
Governance Access Control Incident Response Supplier Risk Evidence adjacent SBOM relevance Certification

DFARS 252.204-7012 Safeguarding Covered Defense Information

North America · United States · Government & Public Sector, Software & Digital Services · effective

effective

Defense acquisition clause requiring safeguarding of covered defense information and cyber incident reporting by contractors.

Primary provision DFARS 252.204-7012 cyber incident reporting Safeguarding Covered Defense Information
Incident Reporting Supplier Risk Evidence Access Control Vulnerability Management adjacent SBOM relevance Regulation

TSA Pipeline Cybersecurity Security Directives

North America · United States · Critical Infrastructure · effective

effective

Transportation Security Administration cybersecurity directives for critical pipeline owners and operators after major ransomware events.

Primary provision TSA pipeline cybersecurity requirements critical pipeline owners and operators
Incident Reporting Vulnerability Management Operational Resilience Critical Infrastructure Evidence adjacent SBOM relevance Regulation

TSA Rail and Aviation Cybersecurity Requirements

North America · United States · Critical Infrastructure · effective

effective

TSA cybersecurity requirements for designated passenger rail, freight rail, and airport and aircraft operators.

Primary provision TSA transportation cybersecurity requirements cybersecurity requirements for airport and aircraft operators
Incident Reporting Vulnerability Management Access Control Operational Resilience Evidence adjacent SBOM relevance Regulation

EU Cybersecurity Act Certification Framework

Europe · European Union · Software & Digital Services, Connected Products & IoT, Critical Infrastructure · effective

effective

EU cybersecurity certification framework for ICT products, services, and processes, supporting conformity evidence used by other EU product rules.

Primary provision Regulation (EU) 2019/881 cybersecurity certification European cybersecurity certification framework
Certification Product Security Technical Documentation Evidence Risk Management adjacent SBOM relevance Regulation

EU Cybersecurity Act 2 Proposal

Europe · European Union · Critical Infrastructure, Software & Digital Services, Government & Public Sector · proposed

proposed

European Commission proposal to revise the Cybersecurity Act and introduce a trusted ICT supply chain security framework for risks from high-risk suppliers and third-country dependencies.

Primary provision Proposal for a Regulation for the EU Cybersecurity Act, trusted ICT supply chain security framework trusted ICT supply chain
Trusted ICT Supply Chain Supplier Risk Certification Product Security Evidence adjacent SBOM relevance Proposal

EU eIDAS 2 European Digital Identity Regulation

Europe · European Union · Software & Digital Services, Government & Public Sector · effective

effective

EU digital identity and trust services regulation expanding wallet, trust service, and assurance requirements for digital identity infrastructure.

Primary provision Regulation (EU) 2024/1183 European Digital Identity Framework European Digital Identity Framework
Identity Assurance Product Security Technical Documentation Certification Evidence adjacent SBOM relevance Regulation

EU Medical Device Regulation Cybersecurity Expectations

Europe · European Union · Healthcare & Life Sciences · effective

effective

EU medical device framework requiring safety, performance, technical documentation, risk management, and post-market surveillance for software-enabled devices.

Primary provision Regulation (EU) 2017/745 medical devices medical devices
Risk Management Technical Documentation Post-Market Monitoring Vulnerability Management Evidence implicit SBOM relevance Regulation

EU In Vitro Diagnostic Regulation Cybersecurity Expectations

Europe · European Union · Healthcare & Life Sciences · effective

effective

EU in vitro diagnostic medical device framework covering software-enabled diagnostics, technical documentation, lifecycle risk, and post-market evidence.

Primary provision Regulation (EU) 2017/746 in vitro diagnostic medical devices in vitro diagnostic medical devices
Risk Management Technical Documentation Post-Market Monitoring Vulnerability Management Evidence implicit SBOM relevance Regulation

Germany BSIG and KRITIS Cybersecurity Requirements

Europe · Germany · Critical Infrastructure, Government & Public Sector · effective

effective

German IT security law and critical infrastructure obligations covering security measures, incident reporting, and evidence for operators and providers.

Primary provision BSI KRITIS cybersecurity requirements Critical Infrastructures
Critical Infrastructure Incident Reporting Risk Management Supplier Risk Evidence implicit SBOM relevance Regulation

Germany BSI C5 Cloud Computing Compliance Criteria Catalogue

Europe · Germany · Software & Digital Services, Government & Public Sector · guidance

guidance

BSI cloud security assurance catalogue used by cloud providers and customers for security, transparency, and audit-ready evidence.

Primary provision BSI C5 cloud computing criteria catalogue Cloud Computing Compliance Criteria Catalogue
Cloud Security Supplier Risk Vulnerability Management Evidence Audit Trail adjacent SBOM relevance Framework

TISAX and ENX Vehicle Cybersecurity Assessment

Global · International · Automotive & Mobility · guidance

guidance

Automotive assessment and exchange ecosystem for information security and vehicle cybersecurity assurance across OEM and supplier relationships.

Primary provision ENX vehicle cybersecurity assessment Vehicle Cyber Security
Supplier Risk Product Security Secure Development Evidence Governance implicit SBOM relevance Framework

France ANSSI SecNumCloud

Europe · France · Software & Digital Services, Government & Public Sector · guidance

guidance

French cloud security qualification framework for cloud service providers serving sensitive public and private sector workloads.

Primary provision ANSSI SecNumCloud qualification SecNumCloud
Cloud Security Supplier Risk Vulnerability Management Evidence Certification adjacent SBOM relevance Certification

Italy National Cybersecurity Perimeter

Europe · Italy · Critical Infrastructure, Government & Public Sector · effective

effective

Italian national cybersecurity perimeter requiring security measures and notifications for essential ICT assets and services.

Primary provision ACN national cybersecurity perimeter Perimetro di sicurezza nazionale cibernetica
Critical Infrastructure Incident Reporting Supplier Risk Risk Management Evidence implicit SBOM relevance Regulation

Malaysia Cyber Security Act 2024

Asia-Pacific · Malaysia · Critical Infrastructure, Government & Public Sector · effective

effective

Malaysian cybersecurity law establishing national critical information infrastructure duties, incident reporting, and cybersecurity service provider licensing.

Primary provision Malaysia Cyber Security Act 2024 Cyber Security Act 2024
Critical Infrastructure Incident Reporting Risk Management Supplier Risk Evidence implicit SBOM relevance Regulation

Thailand Cybersecurity Act

Asia-Pacific · Thailand · Critical Infrastructure, Government & Public Sector · effective

effective

Thai cybersecurity law establishing national cybersecurity governance and requirements for critical information infrastructure organizations.

Primary provision Thailand Cybersecurity Act B.E. 2562 Cybersecurity Act
Critical Infrastructure Incident Response Risk Management Governance Evidence implicit SBOM relevance Regulation

UAE Information Assurance Regulation

Middle East · United Arab Emirates · Government & Public Sector, Critical Infrastructure · effective

effective

UAE national information assurance controls for government and critical entities covering governance, risk, operations, and third-party security.

Primary provision UAE Information Assurance Regulation Information Assurance
Governance Risk Management Third-Party Risk Evidence Incident Response adjacent SBOM relevance Framework

Qatar National Information Assurance Policy

Middle East · Qatar · Government & Public Sector, Critical Infrastructure · guidance

guidance

Qatar national information assurance baseline for protecting government and critical information systems.

Primary provision Qatar national information assurance materials National Cyber Security Agency
Governance Risk Management Third-Party Risk Evidence Incident Response adjacent SBOM relevance Framework

Brazil BACEN Resolution 4,893 Cybersecurity and Cloud Outsourcing

Latin America · Brazil · Financial Services · effective

effective

Brazil Central Bank cybersecurity policy and cloud outsourcing requirements for financial institutions and payment institutions.

Primary provision BACEN Resolution CMN 4,893 cybersecurity policy
Cybersecurity Policy Third-Party Risk Cloud Security Incident Reporting Evidence implicit SBOM relevance Regulation

Hong Kong HKMA TM-G-1 Technology Risk Management

Asia-Pacific · Hong Kong · Financial Services · guidance

guidance

HKMA supervisory guidance for authorized institutions managing technology risk, cyber resilience, outsourcing, and incident response.

Primary provision HKMA technology risk management guidance Technology Risk Management
Technology Risk Third-Party Risk Incident Response Vulnerability Management Evidence implicit SBOM relevance Guidance

APRA CPS 234 Information Security

Asia-Pacific · Australia · Financial Services · effective

effective

Information security standard requiring APRA-regulated entities to manage information security capability, controls, incidents, testing, audit, and third-party control assurance.

Information Security Incident Reporting Third-Party Risk Control Assurance Audit Trail implicit SBOM relevance Standard

NERC CIP-013 Supply Chain Risk Management

North America · United States, Canada · Critical Infrastructure · effective

effective

Reliability standard requiring covered electric-sector entities to identify and manage cybersecurity risks from vendors and supply chain relationships.

Supplier Risk Supply Chain Security Access Control Change Management Evidence Audit Trail implicit SBOM relevance Standard

China Network Product Security Vulnerability Management Provisions

Asia-Pacific · China · Software & Digital Services, Connected Products & IoT · effective

effective

Rules governing discovery, reporting, repair, and publication of security vulnerabilities in network products including hardware and software.

Primary provision China network product security vulnerability management provisions network product security vulnerabilities
Vulnerability Disclosure Vulnerability Management Product Security Incident Reporting Evidence implicit SBOM relevance Regulation

India CERT-In Cyber Security Directions

Asia-Pacific · India · General Enterprise, Software & Digital Services · effective

effective

CERT-In directions requiring covered entities to report specified cyber incidents rapidly and maintain relevant logs and security practices.

Incident Reporting Logging Evidence Vulnerability Management Governance adjacent SBOM relevance Regulation

OMB M-23-02 Migrating to Post-Quantum Cryptography

North America · United States · Government & Public Sector, Critical Infrastructure, General Enterprise · effective

effective

OMB memorandum directing federal agencies to prepare for post-quantum cryptography by inventorying cryptographic systems, prioritizing high-value and high-impact assets, and assessing migration funding.

Primary provision OMB M-23-02, Section II prioritized inventory of cryptographic systems prioritized inventory of cryptographic systems
CBOM Cryptographic Inventory PQC Readiness Risk Management Evidence Migration Planning adjacent SBOM relevance Policy

US FDA Cybersecurity in Medical Devices

North America · United States · Healthcare & Life Sciences · effective

effective

FDA cybersecurity expectations for medical device submissions and postmarket lifecycle management, including software component transparency and vulnerability management.

Primary provision FD&C Act Section 524B(b)(3) provide a software bill of materials
SBOM Vulnerability Management Coordinated Vulnerability Disclosure Secure Development Evidence Post-Market Monitoring explicit SBOM relevance Regulation

RBI Outsourcing of IT Services Directions

Asia-Pacific · India · Financial Services · effective

effective

RBI directions for regulated entities outsourcing IT services, covering governance, risk management, confidentiality, business continuity, audit, and third-party oversight.

Third-Party Risk Supplier Risk Business Continuity Audit Trail Evidence Governance implicit SBOM relevance Regulation

US SEC Cybersecurity Disclosure Rule

North America · United States · General Enterprise, Financial Services · effective

effective

Requires public companies to disclose material cybersecurity incidents and annually describe cybersecurity risk management, strategy, governance, and oversight.

Primary provision SEC cybersecurity risk management, strategy, governance, and incident disclosure rule material cybersecurity incidents
Incident Reporting Governance Risk Management Evidence Audit Trail adjacent SBOM relevance Regulation

Canada OSFI Guideline B-13 Technology and Cyber Risk Management

North America · Canada · Financial Services · effective

effective

OSFI guidance setting expectations for federally regulated financial institutions to manage technology and cyber risks, including incident reporting and resilience.

Technology Risk Incident Reporting Governance Resilience Testing Evidence implicit SBOM relevance Regulation

MAS Technology Risk Management Notice

Asia-Pacific · Singapore · Financial Services · effective

effective

MAS technology risk obligations for payment service providers, including fast notification of relevant incidents and controls over technology operations.

Incident Reporting Technology Risk Governance Evidence Operational Resilience adjacent SBOM relevance Guidance

US EO 14028 and Federal Secure Software Attestation

North America · United States · Government & Public Sector, Software & Digital Services · effective

effective

Federal software supply chain policy requiring software producers serving the US government to attest to secure development practices, with SBOMs and artifacts used by agencies as supporting evidence.

Primary provision Executive Order 14028, Section 4(e)(vii) providing a purchaser a Software Bill of Materials
Secure Development SBOM Vulnerability Disclosure Evidence Attestation Supply Chain Security explicit SBOM relevance Regulation

UK Product Security and Telecommunications Infrastructure Regime

Europe · United Kingdom · Connected Products & IoT · effective

effective

UK consumer connectable product security regime requiring manufacturers, importers, and distributors to meet minimum security requirements and provide statements of compliance.

Primary provision UK PSTI product security regime, security requirements for connectable products statement of compliance
Product Security Vulnerability Disclosure Technical Documentation Conformity Evidence Secure Defaults adjacent SBOM relevance Regulation

Canada OSFI Guideline B-10 Third-Party Risk Management

North America · Canada · Financial Services · effective

effective

OSFI third-party risk guidance requiring federally regulated financial institutions to manage risks across outsourced and other third-party arrangements.

Third-Party Risk Supplier Risk Operational Resilience Audit Trail Evidence implicit SBOM relevance Regulation

EU NIS2 Directive

Europe · European Union · Critical Infrastructure, Software & Digital Services, Government & Public Sector · effective

effective

EU-wide cybersecurity framework for essential and important entities, including risk management, incident reporting, supervision, and supply chain security measures.

Primary provision Directive (EU) 2022/2555, Article 21 supply chain security security in network and information systems acquisition, development and maintenance
Risk Management Incident Reporting Supply Chain Security Supplier Risk Governance Evidence implicit SBOM relevance Directive

China Network Data Security Management Regulation

Asia-Pacific · China · AI & Data, Software & Digital Services, General Enterprise · effective

effective

Chinese network data security regulation requiring data processors to implement protection measures and report network product or service security defects and vulnerabilities.

Vulnerability Disclosure Incident Reporting Data Security Risk Assessment Product Security implicit SBOM relevance Regulation

EU Digital Operational Resilience Act (DORA)

Europe · European Union · Financial Services, Software & Digital Services · effective

effective

Operational resilience regime for financial entities covering ICT risk management, major incident reporting, resilience testing, information sharing, and ICT third-party risk.

Primary provision Regulation (EU) 2022/2554, ICT third-party risk management manage ICT third-party risk as an integral component of ICT risk
Supplier Risk Incident Reporting Operational Resilience Evidence Audit Trail Third-Party Risk implicit SBOM relevance Regulation

Japan JC-STAR IoT Product Security Scheme

Asia-Pacific · Japan · Connected Products & IoT, Critical Infrastructure · phased

phased

Japanese IoT product security conformity assessment scheme with baseline and higher assurance labels intended to support procurement and international alignment.

IoT Labeling Product Security Secure Updates Vulnerability Management Conformity Evidence adjacent SBOM relevance Certification

PCI DSS v4.0.1 Software Component Inventory

Global · Payment Card Industry · Financial Services, Software & Digital Services · effective

effective

PCI DSS v4.0.1 Requirement 6.3.2 requires entities to maintain an inventory of bespoke and custom software and third-party software components incorporated into that software to support vulnerability and patch management.

Primary provision PCI DSS v4.0.1 Requirement 6.3.2 and testing procedures 6.3.2.a-b inventory of bespoke and custom software
SBOM Software Component Inventory Vulnerability Management Patch Management Secure Development Evidence explicit SBOM relevance Standard

EU Radio Equipment Directive Cybersecurity Delegated Regulation

Europe · European Union · Connected Products & IoT · phased

phased

Activates cybersecurity, privacy, and fraud-protection essential requirements for categories of internet-connected radio equipment under the Radio Equipment Directive.

Primary provision Delegated Regulation (EU) 2022/30, Article 3 internet-connected radio equipment does not harm the network or its functioning
Product Security Vulnerability Management Secure Development Technical Documentation Conformity Evidence adjacent SBOM relevance Regulation

EU Data Act Cloud Switching and Interoperability

Europe · European Union · Software & Digital Services, General Enterprise · phased

phased

EU data access and cloud switching regulation affecting data processing services, interoperability, switching, and contractual transparency.

Primary provision Regulation (EU) 2023/2854 Data Act switching between data processing services
Cloud Portability Technical Documentation Supplier Risk Governance Evidence adjacent SBOM relevance Regulation

Switzerland Cyberattack Reporting for Critical Infrastructure

Europe · Switzerland · Critical Infrastructure, General Enterprise · effective

effective

Swiss cyberattack reporting obligation for operators of critical infrastructure with phased enforcement and notification duties.

Primary provision NCSC cyberattack reporting obligation Reporting obligation for cyberattacks
Incident Reporting Critical Infrastructure Evidence Risk Management Supplier Risk adjacent SBOM relevance Regulation

Singapore Cybersecurity Act

Asia-Pacific · Singapore · Critical Infrastructure, Software & Digital Services · phased

phased

Cybersecurity framework for critical information infrastructure, expanded by 2024 amendments to cover additional classes such as foundational digital infrastructure providers.

Critical Infrastructure Incident Reporting Cybersecurity Codes Governance Evidence implicit SBOM relevance Regulation

China GB 44495 and GB 44496 Vehicle Cybersecurity Standards

Asia-Pacific · China · Automotive & Mobility · effective

effective

Mandatory Chinese vehicle cybersecurity and software update standards covering CSMS-style governance, technical controls, inspection and test methods, software update management, and vehicle evidence.

Cybersecurity Management System Secure Updates Vulnerability Management Product Security Technical Documentation Evidence implicit SBOM relevance Standard

OMB Memorandum M-26-05 Risk-Based Software and Hardware Security

North America · United States · Government & Public Sector, Software & Digital Services · effective

effective

Federal policy shifting software and hardware security assurance from universal attestation to agency risk-based contractual and validation approaches.

Primary provision OMB M-26-05, software and hardware security validation provide a current software bill of materials
Risk Management Secure Development SBOM Supplier Risk Evidence Procurement Security explicit SBOM relevance Policy

UK GB Type Approval R155 and R156 Requirements

Europe · United Kingdom · Automotive & Mobility · phased

phased

Great Britain type approval implementation of UN R155 cybersecurity and UN R156 software update requirements, with phased dates for new vehicle types, complete vehicles, completed vehicles, and special purpose vehicles.

Cybersecurity Management System Secure Updates Supplier Risk Technical Documentation Evidence Audit Trail implicit SBOM relevance Standard

APRA CPS 230 Operational Risk Management

Asia-Pacific · Australia · Financial Services · effective

effective

APRA standard requiring regulated entities to manage operational risks, maintain critical operations through disruption, and manage service-provider arrangements.

Operational Resilience Third-Party Risk Supplier Risk Business Continuity Evidence adjacent SBOM relevance Standard

China Cybersecurity Label Management Measures

Asia-Pacific · China · Connected Products & IoT · upcoming

upcoming

China cybersecurity labeling framework for internet-connected products, including security capability levels, testing, reports, conformity statements, and vulnerability handling.

IoT Labeling Product Security Vulnerability Management Conformity Evidence Technical Documentation adjacent SBOM relevance Certification

EU AI Act

Europe · European Union · AI & Data, Software & Digital Services, Healthcare & Life Sciences · phased

phased

Risk-based AI regulation requiring technical documentation, logging, post-market monitoring, incident reporting, and cybersecurity measures for high-risk AI systems.

Primary provision Regulation (EU) 2024/1689, Annex IV technical documentation technical documentation shall be drawn up before that system is placed on the market
Technical Documentation Incident Reporting Post-Market Monitoring Governance Evidence Risk Management adjacent SBOM relevance Regulation

EU Machinery Regulation

Europe · European Union · Industrial & Manufacturing · upcoming

upcoming

Updates EU machinery safety rules for connected and software-enabled machinery, including protection against corruption where safety functions depend on software or data.

Primary provision Regulation (EU) 2023/1230, Annex III 1.1.9 protection against corruption identify the software installed on it
Product Security Technical Documentation Risk Management Secure Updates Evidence adjacent SBOM relevance Regulation

EU Cyber Resilience Act (CRA)

Europe · European Union · Software & Digital Services, Connected Products & IoT, Industrial & Manufacturing · phased

phased

Horizontal cybersecurity law for products with digital elements, combining secure-by-design duties, vulnerability handling, incident reporting, technical documentation, and software component transparency. CRA vulnerability and incident reporting obligations apply from 11 September 2026 through the ENISA Single Reporting Platform.

Primary provision Regulation (EU) 2024/2847, Annex I Part II, vulnerability handling requirements identify and document components contained in the products
SBOM Vulnerability Disclosure Incident Reporting Technical Documentation Secure Development Supply Chain Security explicit SBOM relevance Regulation
SBOM Compliance Dashboard
Real-time software bill of materials tracking and compliance status
Product Components Compliance Last Updated
Automotive Platform v2.3 1,247 98% UNECE R155 2024-12-19
Medical Device Suite 892 100% FDA 2024-12-18
Financial Services API 1,534 96% EO 14028 2024-12-17
IoT Gateway Firmware 2,103 99% EU CRA 2024-12-19
Resources

Guides. Blogs. Regulations.

Find blogs, beginner guides, and compliance regulations to help you understand and implement SBOMs with confidence.

Latest insights and updates from the SBOM world

A Static SBOM Scan Is Not SBOM Management

There is a dangerous shortcut in the SBOM market.

Read More

FOSS Notices Are Still Being Managed Like It's 2009

Open-source compliance has a quiet operational problem.

Read More

The CRA Deadline Is Not 2027. Your Evidence Problem Starts Now.

Many product and security teams are treating the Cyber Resilience Act as a 2027 problem.

Read More

See how Exodos manages compliance

Join FOSS and security teams who have transformed their SBOM management from a compliance burden into a strategic advantage.

Start Free Trial