Global regulatory intelligence

Map global software supply chain obligations

As cybersecurity threats continue to rise, governments and organizations worldwide are implementing strict SBOM regulations to strengthen software supply chain security. These regulations are designed to enhance transparency, reduce vulnerabilities, and ensure that businesses take proactive measures to secure their software ecosystems.To remain compliant, companies must adhere to these evolving standards, which help mitigate security risks, prevent potential cyberattacks, and avoid costly legal consequences.This page provides a comprehensive breakdown of the most critical global regulations, detailing their specific requirements, impact on businesses, and the role of SBOM in ensuring compliance. With a clear and structured format, this guide simplifies complex regulatory frameworks, making it easier for organizations to understand and implement the necessary security measures.

Track SBOM, vulnerability disclosure, incident reporting, and software transparency obligations by region, industry, and enforcement stage.

89 regulations tracked
0 explicit SBOM signals
0 dated deadlines

89 matching obligations

Need to map these obligations to your products? Turn global SBOM, vulnerability, and software supply chain requirements into a concrete evidence workflow with Exodos.

US CIRCIA Cyber Incident Reporting

North America · United States · Critical Infrastructure, Healthcare & Life Sciences, Financial Services · proposed

proposed

US critical infrastructure incident reporting law requiring CISA to finalize rules for covered cyber incident and ransom payment reporting by covered entities.

Incident Reporting Ransomware Reporting Evidence Critical Infrastructure Governance adjacent SBOM relevance Regulation

US FCC Cyber Trust Mark

North America · United States · Connected Products & IoT · guidance

guidance

Voluntary US cybersecurity labeling program for consumer IoT products, built around conformance testing, label authorization, registry information, and NIST technical criteria.

IoT Labeling Product Security Vulnerability Management Secure Updates Technical Documentation adjacent SBOM relevance Certification

UK Network and Information Systems Regulations

Europe · United Kingdom · Critical Infrastructure, Software & Digital Services · effective

effective

UK framework for network and information system security in operators of essential services and relevant digital service providers, with security and incident reporting duties.

Risk Management Incident Reporting Operational Resilience Evidence Governance implicit SBOM relevance Regulation

UK PRA Operational Incident and Third-Party Reporting

Europe · United Kingdom · Financial Services · upcoming

upcoming

PRA policy for more consistent reporting of operational incidents and material third-party arrangements by regulated financial firms.

Incident Reporting Third-Party Risk Operational Resilience Supplier Risk Evidence adjacent SBOM relevance Regulation

Australia Cyber Security Act 2024

Asia-Pacific · Australia · General Enterprise, Critical Infrastructure, Software & Digital Services · effective

effective

Australian cyber reform package introducing ransomware and cyber extortion payment reporting and broader cyber incident coordination mechanisms.

Ransomware Reporting Incident Reporting Evidence Governance Critical Infrastructure adjacent SBOM relevance Regulation

Australia Security of Critical Infrastructure Act

Asia-Pacific · Australia · Critical Infrastructure, Healthcare & Life Sciences · effective

effective

Critical infrastructure security framework with mandatory cyber incident reporting and risk management obligations for covered assets.

Incident Reporting Critical Infrastructure Risk Management Supplier Risk Evidence implicit SBOM relevance Regulation

Canadian Centre for Cyber Security Software Supply Chain Guidance

North America · Canada · Critical Infrastructure, Government & Public Sector, Software & Digital Services · guidance

guidance

Canadian guidance for protecting organizations from software supply chain threats, including supplier assessment and software component inventory/SBOM considerations.

SBOM Supplier Risk Supply Chain Security Vulnerability Management Risk Management explicit SBOM relevance Guidance

Japan Cyber Infrastructure Provider Guidelines

Asia-Pacific · Japan · Software & Digital Services · proposed

proposed

Draft METI and NCO guidelines describing expected roles for providers that develop, supply, and operate software and cyber infrastructure.

Secure Development Supplier Risk Vulnerability Management Governance Evidence implicit SBOM relevance Regulation

China Cybersecurity Law

Asia-Pacific · China · Critical Infrastructure, General Enterprise · effective

effective

Foundational Chinese cybersecurity law covering network operator security duties, critical information infrastructure protections, security incidents, and network product obligations.

Risk Management Incident Response Critical Infrastructure Product Security Vulnerability Management Evidence implicit SBOM relevance Regulation

Korea Act on Protection of Information and Communications Infrastructure

Asia-Pacific · South Korea · Critical Infrastructure, Government & Public Sector, Software & Digital Services · effective

effective

Korean framework for protecting major information and communications infrastructure against electronic intrusion and disruption.

Critical Infrastructure Risk Management Incident Response Evidence Governance implicit SBOM relevance Regulation

Korea KISA IoT Security Certification

Asia-Pacific · South Korea · Connected Products & IoT · guidance

guidance

KISA IoT security certification evaluates connected devices across authentication, data protection, cryptography, software security, updates, technical support, OS, network, and hardware security.

IoT Labeling Product Security Secure Updates Vulnerability Management Conformity Evidence adjacent SBOM relevance Certification

Saudi NCA Essential Cybersecurity Controls

Middle East · Saudi Arabia · Government & Public Sector, Critical Infrastructure, General Enterprise · effective

effective

Minimum cybersecurity requirements for Saudi government organizations and critical national infrastructure operators, covering governance, defense, resilience, cloud, third parties, and ICS.

Governance Risk Management Third-Party Risk Cloud Security Industrial Control Systems Evidence implicit SBOM relevance Framework

Saudi NCA Critical Systems Cybersecurity Controls

Middle East · Saudi Arabia · Government & Public Sector, Critical Infrastructure · effective

effective

Saudi critical systems controls extending the ECC for national critical systems across governance, defense, resilience, and third-party/cloud cybersecurity.

Critical Infrastructure Third-Party Risk Cloud Security Resilience Evidence implicit SBOM relevance Framework

UNECE UN Regulation No. 155 Cybersecurity Management System

Global · UNECE Contracting Parties · Automotive & Mobility · effective

effective

Vehicle type approval regulation requiring cybersecurity management systems and risk controls across vehicle lifecycle and supply chain.

Secure Development Supply Chain Security Vulnerability Management Risk Management Evidence Audit Trail implicit SBOM relevance Regulation

UNECE UN Regulation No. 156 Software Update Management System

Global · UNECE Contracting Parties · Automotive & Mobility · effective

effective

Vehicle type approval regulation for software update management systems, including safe and secure software update processes and update documentation.

Secure Updates Change Management Technical Documentation Evidence Audit Trail implicit SBOM relevance Regulation

Auto-ISAC SBOM Best Practices

Global · International · Automotive & Mobility · guidance

guidance

Automotive industry guidance on SBOM program design, supplier exchange, vulnerability operations, confidentiality, and automation across OEM and multi-tier supplier ecosystems.

SBOM Supplier Risk Vulnerability Management Software Transparency Secure Sharing Evidence explicit SBOM relevance Guidance

IMDRF SBOM for Medical Device Cybersecurity

Global · IMDRF Members · Healthcare & Life Sciences · guidance

guidance

International regulator guidance on SBOM principles and practices for medical device cybersecurity across manufacturers, healthcare providers, and other stakeholders.

SBOM Vulnerability Management Software Transparency Post-Market Monitoring Evidence explicit SBOM relevance Guidance

CISA and International Partners Shared Vision for SBOM

Global · International · Software & Digital Services, Critical Infrastructure, Government & Public Sector · guidance

guidance

Joint international guidance setting a shared vision for SBOM as a core tool for vulnerability management, secure-by-design development, and software supply chain transparency.

SBOM Software Transparency Vulnerability Management Secure Development Supply Chain Security explicit SBOM relevance Guidance

IEC 62443-4-1 Secure Product Development Lifecycle

Global · International · Industrial & Manufacturing, Critical Infrastructure · effective

effective

Industrial automation and control system standard defining secure product development lifecycle practices for component suppliers.

Secure Development Vulnerability Management Secure Updates Technical Documentation Evidence explicit SBOM relevance Standard

IEC 62443-4-2 Technical Security Requirements for IACS Components

Global · International · Industrial & Manufacturing, Critical Infrastructure · effective

effective

Component-level security standard for industrial control system products, covering embedded devices, host devices, network devices, and software applications.

Product Security Secure Development Vulnerability Management Technical Documentation Evidence implicit SBOM relevance Standard

IEC 62443-2-1 IACS Security Program Requirements

Global · International · Industrial & Manufacturing, Critical Infrastructure · effective

effective

Program-level industrial automation security management standard for asset owners operating control systems and OT environments.

Risk Management Governance Vulnerability Management Supplier Risk Evidence implicit SBOM relevance Standard

IEC 62443-3-3 System Security Requirements and Security Levels

Global · International · Industrial & Manufacturing, Critical Infrastructure · effective

effective

Industrial control system security standard defining system security requirements and target security levels for zones and conduits.

Risk Management Product Security Access Control Monitoring Evidence adjacent SBOM relevance Standard

ISO/IEC 27001 Information Security Management Systems

Global · International · General Enterprise, Software & Digital Services · effective

effective

International information security management system standard used as a baseline for governance, risk treatment, supplier controls, and audit evidence.

Governance Risk Management Supplier Risk Evidence Audit Trail adjacent SBOM relevance Standard

ISO/IEC 27002 Information Security Controls

Global · International · General Enterprise, Software & Digital Services · effective

effective

Reference control catalogue for information security controls, including supplier relationships, secure development, vulnerability management, and asset management.

Risk Management Supplier Risk Secure Development Vulnerability Management Evidence adjacent SBOM relevance Standard

ISO/IEC 27036 Supplier Relationship Security

Global · International · General Enterprise, Software & Digital Services · effective

effective

Supplier relationship security standard family covering information security risks in ICT supplier and acquirer relationships.

Supplier Risk Third-Party Risk Procurement Security Evidence Governance implicit SBOM relevance Standard

ISO/IEC 27034 Application Security

Global · International · Software & Digital Services · effective

effective

Application security standard family for integrating security controls into application lifecycle and organizational governance.

Secure Development Risk Management Technical Documentation Evidence adjacent SBOM relevance Standard

ISO/IEC 42001 AI Management System

Global · International · AI & Data, Software & Digital Services · effective

effective

AI management system standard for organizations providing or using AI systems, supporting governance, risk controls, and lifecycle evidence.

AI Governance Risk Management Technical Documentation Monitoring Evidence adjacent SBOM relevance Standard

NIST SP 800-218 Secure Software Development Framework

North America · United States · Government & Public Sector, Software & Digital Services · guidance

guidance

US secure software development framework used by federal software supply chain policy and procurement assurance programs.

Secure Development SBOM Vulnerability Management Evidence Attestation explicit SBOM relevance Guidance

NIST SP 800-161 Rev. 1 Cybersecurity Supply Chain Risk Management

North America · United States · Government & Public Sector, Critical Infrastructure, Software & Digital Services · guidance

guidance

Cybersecurity supply chain risk management guidance for federal systems and organizations, covering suppliers, products, services, and system components.

Supplier Risk Supply Chain Security SBOM Risk Management Evidence explicit SBOM relevance Guidance

NIST Cybersecurity Framework 2.0

Global · International · General Enterprise, Critical Infrastructure · guidance

guidance

Cybersecurity risk management framework organized around govern, identify, protect, detect, respond, and recover outcomes.

Governance Risk Management Supplier Risk Vulnerability Management Evidence implicit SBOM relevance Framework

NIST SP 800-53 Rev. 5 System and Services Acquisition Controls

North America · United States · Government & Public Sector, Software & Digital Services · guidance

guidance

Federal security and privacy control catalogue with acquisition, supply chain, developer testing, and flaw remediation controls.

Supplier Risk Secure Development Vulnerability Management Evidence Audit Trail implicit SBOM relevance Framework

CISA NTIA Minimum Elements for SBOM

Global · International · Software & Digital Services, Government & Public Sector · guidance

guidance

Baseline SBOM guidance defining minimum data fields, automation support, and practices for generating, sharing, and using SBOMs.

SBOM Software Transparency Supplier Risk Vulnerability Management Evidence explicit SBOM relevance Guidance

CISA Vulnerability Exploitability eXchange Status Justifications

Global · International · Software & Digital Services, Critical Infrastructure · guidance

guidance

Guidance for communicating whether a known vulnerability affects a product, reducing false positives in SBOM-driven vulnerability operations.

VEX Vulnerability Management Software Transparency Evidence Supplier Communication explicit SBOM relevance Guidance

CISA Known Exploited Vulnerabilities Catalog

Global · International · Critical Infrastructure, Software & Digital Services, Government & Public Sector · guidance

guidance

Catalog of vulnerabilities known to be exploited in the wild, used for prioritized remediation and risk-based vulnerability management.

Vulnerability Management Remediation Evidence Incident Response adjacent SBOM relevance Guidance

CISA Secure by Design Guidance

Global · International · Software & Digital Services, Connected Products & IoT · guidance

guidance

Secure by Design guidance urging technology manufacturers to make secure product development and vulnerability handling core business practices.

Secure Development Vulnerability Disclosure Secure Defaults Evidence Governance implicit SBOM relevance Guidance

SLSA Supply-chain Levels for Software Artifacts

Global · International · Software & Digital Services · guidance

guidance

Open framework for improving build integrity and provenance across software supply chains, from source through build and distribution.

Build Provenance Secure Development Supply Chain Security Evidence Attestation adjacent SBOM relevance Framework

OpenSSF Scorecard

Global · International · Software & Digital Services · guidance

guidance

Open-source project health and security scoring tool used to evaluate dependency risk signals across source repositories.

Supplier Risk Open Source Risk Secure Development Evidence adjacent SBOM relevance Framework

OWASP Software Component Verification Standard

Global · International · Software & Digital Services · guidance

guidance

OWASP verification standard for software components and supply chain controls, including inventory, integrity, provenance, and vulnerability practices.

SBOM Supply Chain Security Secure Development Vulnerability Management Evidence explicit SBOM relevance Framework

CycloneDX SBOM Standard

Global · International · Software & Digital Services · guidance

guidance

Machine-readable bill of materials standard supporting SBOM, SaaSBOM, VEX, CBOM, and other software supply chain transparency use cases.

SBOM VEX Software Transparency Vulnerability Management Evidence explicit SBOM relevance Standard

SPDX ISO/IEC 5962 Software Bill of Materials Standard

Global · International · Software & Digital Services · effective

effective

ISO-standardized SBOM and software package data exchange format used for component, license, security, and provenance transparency.

SBOM Software Transparency License Compliance Provenance Evidence explicit SBOM relevance Standard

FedRAMP Rev. 5 Cloud Security Authorization

North America · United States · Government & Public Sector, Software & Digital Services · effective

effective

Federal cloud security authorization baseline based on NIST SP 800-53 Rev. 5 controls, including supply chain, vulnerability, and configuration evidence.

Cloud Security Vulnerability Management Supplier Risk Evidence Continuous Monitoring implicit SBOM relevance Framework

DoD Cybersecurity Maturity Model Certification 2.0

North America · United States · Government & Public Sector, Software & Digital Services · phased

phased

DoD contractor cybersecurity certification program for protecting federal contract information and controlled unclassified information.

Governance Access Control Incident Response Supplier Risk Evidence adjacent SBOM relevance Certification

DFARS 252.204-7012 Safeguarding Covered Defense Information

North America · United States · Government & Public Sector, Software & Digital Services · effective

effective

Defense acquisition clause requiring safeguarding of covered defense information and cyber incident reporting by contractors.

Incident Reporting Supplier Risk Evidence Access Control Vulnerability Management adjacent SBOM relevance Regulation

TSA Pipeline Cybersecurity Security Directives

North America · United States · Critical Infrastructure · effective

effective

Transportation Security Administration cybersecurity directives for critical pipeline owners and operators after major ransomware events.

Incident Reporting Vulnerability Management Operational Resilience Critical Infrastructure Evidence adjacent SBOM relevance Regulation

TSA Rail and Aviation Cybersecurity Requirements

North America · United States · Critical Infrastructure · effective

effective

TSA cybersecurity requirements for designated passenger rail, freight rail, and airport and aircraft operators.

Incident Reporting Vulnerability Management Access Control Operational Resilience Evidence adjacent SBOM relevance Regulation

EU Cybersecurity Act Certification Framework

Europe · European Union · Software & Digital Services, Connected Products & IoT, Critical Infrastructure · effective

effective

EU cybersecurity certification framework for ICT products, services, and processes, supporting conformity evidence used by other EU product rules.

Certification Product Security Technical Documentation Evidence Risk Management adjacent SBOM relevance Regulation

EU eIDAS 2 European Digital Identity Regulation

Europe · European Union · Software & Digital Services, Government & Public Sector · effective

effective

EU digital identity and trust services regulation expanding wallet, trust service, and assurance requirements for digital identity infrastructure.

Identity Assurance Product Security Technical Documentation Certification Evidence adjacent SBOM relevance Regulation

EU Medical Device Regulation Cybersecurity Expectations

Europe · European Union · Healthcare & Life Sciences · effective

effective

EU medical device framework requiring safety, performance, technical documentation, risk management, and post-market surveillance for software-enabled devices.

Risk Management Technical Documentation Post-Market Monitoring Vulnerability Management Evidence implicit SBOM relevance Regulation

EU In Vitro Diagnostic Regulation Cybersecurity Expectations

Europe · European Union · Healthcare & Life Sciences · effective

effective

EU in vitro diagnostic medical device framework covering software-enabled diagnostics, technical documentation, lifecycle risk, and post-market evidence.

Risk Management Technical Documentation Post-Market Monitoring Vulnerability Management Evidence implicit SBOM relevance Regulation

Germany BSIG and KRITIS Cybersecurity Requirements

Europe · Germany · Critical Infrastructure, Government & Public Sector · effective

effective

German IT security law and critical infrastructure obligations covering security measures, incident reporting, and evidence for operators and providers.

Critical Infrastructure Incident Reporting Risk Management Supplier Risk Evidence implicit SBOM relevance Regulation

Germany BSI C5 Cloud Computing Compliance Criteria Catalogue

Europe · Germany · Software & Digital Services, Government & Public Sector · guidance

guidance

BSI cloud security assurance catalogue used by cloud providers and customers for security, transparency, and audit-ready evidence.

Cloud Security Supplier Risk Vulnerability Management Evidence Audit Trail adjacent SBOM relevance Framework

TISAX and ENX Vehicle Cybersecurity Assessment

Global · International · Automotive & Mobility · guidance

guidance

Automotive assessment and exchange ecosystem for information security and vehicle cybersecurity assurance across OEM and supplier relationships.

Supplier Risk Product Security Secure Development Evidence Governance implicit SBOM relevance Framework

France ANSSI SecNumCloud

Europe · France · Software & Digital Services, Government & Public Sector · guidance

guidance

French cloud security qualification framework for cloud service providers serving sensitive public and private sector workloads.

Cloud Security Supplier Risk Vulnerability Management Evidence Certification adjacent SBOM relevance Certification

Italy National Cybersecurity Perimeter

Europe · Italy · Critical Infrastructure, Government & Public Sector · effective

effective

Italian national cybersecurity perimeter requiring security measures and notifications for essential ICT assets and services.

Critical Infrastructure Incident Reporting Supplier Risk Risk Management Evidence implicit SBOM relevance Regulation

Malaysia Cyber Security Act 2024

Asia-Pacific · Malaysia · Critical Infrastructure, Government & Public Sector · effective

effective

Malaysian cybersecurity law establishing national critical information infrastructure duties, incident reporting, and cybersecurity service provider licensing.

Critical Infrastructure Incident Reporting Risk Management Supplier Risk Evidence implicit SBOM relevance Regulation

Thailand Cybersecurity Act

Asia-Pacific · Thailand · Critical Infrastructure, Government & Public Sector · effective

effective

Thai cybersecurity law establishing national cybersecurity governance and requirements for critical information infrastructure organizations.

Critical Infrastructure Incident Response Risk Management Governance Evidence implicit SBOM relevance Regulation

UAE Information Assurance Regulation

Middle East · United Arab Emirates · Government & Public Sector, Critical Infrastructure · effective

effective

UAE national information assurance controls for government and critical entities covering governance, risk, operations, and third-party security.

Governance Risk Management Third-Party Risk Evidence Incident Response adjacent SBOM relevance Framework

Qatar National Information Assurance Policy

Middle East · Qatar · Government & Public Sector, Critical Infrastructure · guidance

guidance

Qatar national information assurance baseline for protecting government and critical information systems.

Governance Risk Management Third-Party Risk Evidence Incident Response adjacent SBOM relevance Framework

Brazil BACEN Resolution 4,893 Cybersecurity and Cloud Outsourcing

Latin America · Brazil · Financial Services · effective

effective

Brazil Central Bank cybersecurity policy and cloud outsourcing requirements for financial institutions and payment institutions.

Cybersecurity Policy Third-Party Risk Cloud Security Incident Reporting Evidence implicit SBOM relevance Regulation

Hong Kong HKMA TM-G-1 Technology Risk Management

Asia-Pacific · Hong Kong · Financial Services · guidance

guidance

HKMA supervisory guidance for authorized institutions managing technology risk, cyber resilience, outsourcing, and incident response.

Technology Risk Third-Party Risk Incident Response Vulnerability Management Evidence implicit SBOM relevance Guidance

Taiwan Cyber Security Management Act

Asia-Pacific · Taiwan · Government & Public Sector, Critical Infrastructure · effective

effective

Taiwan cybersecurity law governing government agencies and specific non-government agencies, including security maintenance and incident reporting.

Critical Infrastructure Incident Reporting Governance Risk Management Evidence implicit SBOM relevance Regulation

APRA CPS 234 Information Security

Asia-Pacific · Australia · Financial Services · effective

effective

Information security standard requiring APRA-regulated entities to manage information security capability, controls, incidents, testing, audit, and third-party control assurance.

Information Security Incident Reporting Third-Party Risk Control Assurance Audit Trail implicit SBOM relevance Standard

NERC CIP-013 Supply Chain Risk Management

North America · United States, Canada · Critical Infrastructure · effective

effective

Reliability standard requiring covered electric-sector entities to identify and manage cybersecurity risks from vendors and supply chain relationships.

Supplier Risk Supply Chain Security Access Control Change Management Evidence Audit Trail implicit SBOM relevance Standard

China Network Product Security Vulnerability Management Provisions

Asia-Pacific · China · Software & Digital Services, Connected Products & IoT · effective

effective

Rules governing discovery, reporting, repair, and publication of security vulnerabilities in network products including hardware and software.

Vulnerability Disclosure Vulnerability Management Product Security Incident Reporting Evidence implicit SBOM relevance Regulation

India CERT-In Cyber Security Directions

Asia-Pacific · India · General Enterprise, Software & Digital Services · effective

effective

CERT-In directions requiring covered entities to report specified cyber incidents rapidly and maintain relevant logs and security practices.

Incident Reporting Logging Evidence Vulnerability Management Governance adjacent SBOM relevance Regulation

US FDA Cybersecurity in Medical Devices

North America · United States · Healthcare & Life Sciences · effective

effective

FDA cybersecurity expectations for medical device submissions and postmarket lifecycle management, including software component transparency and vulnerability management.

SBOM Vulnerability Management Coordinated Vulnerability Disclosure Secure Development Evidence Post-Market Monitoring explicit SBOM relevance Regulation

RBI Outsourcing of IT Services Directions

Asia-Pacific · India · Financial Services · effective

effective

RBI directions for regulated entities outsourcing IT services, covering governance, risk management, confidentiality, business continuity, audit, and third-party oversight.

Third-Party Risk Supplier Risk Business Continuity Audit Trail Evidence Governance implicit SBOM relevance Regulation

US SEC Cybersecurity Disclosure Rule

North America · United States · General Enterprise, Financial Services · effective

effective

Requires public companies to disclose material cybersecurity incidents and annually describe cybersecurity risk management, strategy, governance, and oversight.

Incident Reporting Governance Risk Management Evidence Audit Trail adjacent SBOM relevance Regulation

Canada OSFI Guideline B-13 Technology and Cyber Risk Management

North America · Canada · Financial Services · effective

effective

OSFI guidance setting expectations for federally regulated financial institutions to manage technology and cyber risks, including incident reporting and resilience.

Technology Risk Incident Reporting Governance Resilience Testing Evidence implicit SBOM relevance Regulation

MAS Technology Risk Management Notice

Asia-Pacific · Singapore · Financial Services · effective

effective

MAS technology risk obligations for payment service providers, including fast notification of relevant incidents and controls over technology operations.

Incident Reporting Technology Risk Governance Evidence Operational Resilience adjacent SBOM relevance Guidance

US EO 14028 and Federal Secure Software Attestation

North America · United States · Government & Public Sector, Software & Digital Services · effective

effective

Federal software supply chain policy requiring software producers serving the US government to attest to secure development practices, with SBOMs and artifacts used by agencies as supporting evidence.

Secure Development SBOM Vulnerability Disclosure Evidence Attestation Supply Chain Security explicit SBOM relevance Regulation

UK Product Security and Telecommunications Infrastructure Regime

Europe · United Kingdom · Connected Products & IoT · effective

effective

UK consumer connectable product security regime requiring manufacturers, importers, and distributors to meet minimum security requirements and provide statements of compliance.

Product Security Vulnerability Disclosure Technical Documentation Conformity Evidence Secure Defaults adjacent SBOM relevance Regulation

Canada OSFI Guideline B-10 Third-Party Risk Management

North America · Canada · Financial Services · effective

effective

OSFI third-party risk guidance requiring federally regulated financial institutions to manage risks across outsourced and other third-party arrangements.

Third-Party Risk Supplier Risk Operational Resilience Audit Trail Evidence implicit SBOM relevance Regulation

EU NIS2 Directive

Europe · European Union · Critical Infrastructure, Software & Digital Services, Government & Public Sector · effective

effective

EU-wide cybersecurity framework for essential and important entities, including risk management, incident reporting, supervision, and supply chain security measures.

Risk Management Incident Reporting Supply Chain Security Supplier Risk Governance Evidence implicit SBOM relevance Directive

China Network Data Security Management Regulation

Asia-Pacific · China · AI & Data, Software & Digital Services, General Enterprise · effective

effective

Chinese network data security regulation requiring data processors to implement protection measures and report network product or service security defects and vulnerabilities.

Vulnerability Disclosure Incident Reporting Data Security Risk Assessment Product Security implicit SBOM relevance Regulation

EU Digital Operational Resilience Act (DORA)

Europe · European Union · Financial Services, Software & Digital Services · effective

effective

Operational resilience regime for financial entities covering ICT risk management, major incident reporting, resilience testing, information sharing, and ICT third-party risk.

Supplier Risk Incident Reporting Operational Resilience Evidence Audit Trail Third-Party Risk implicit SBOM relevance Regulation

Japan JC-STAR IoT Product Security Scheme

Asia-Pacific · Japan · Connected Products & IoT, Critical Infrastructure · phased

phased

Japanese IoT product security conformity assessment scheme with baseline and higher assurance labels intended to support procurement and international alignment.

IoT Labeling Product Security Secure Updates Vulnerability Management Conformity Evidence adjacent SBOM relevance Certification

EU Radio Equipment Directive Cybersecurity Delegated Regulation

Europe · European Union · Connected Products & IoT · phased

phased

Activates cybersecurity, privacy, and fraud-protection essential requirements for categories of internet-connected radio equipment under the Radio Equipment Directive.

Product Security Vulnerability Management Secure Development Technical Documentation Conformity Evidence adjacent SBOM relevance Regulation

EU Data Act Cloud Switching and Interoperability

Europe · European Union · Software & Digital Services, General Enterprise · phased

phased

EU data access and cloud switching regulation affecting data processing services, interoperability, switching, and contractual transparency.

Cloud Portability Technical Documentation Supplier Risk Governance Evidence adjacent SBOM relevance Regulation

Switzerland Cyberattack Reporting for Critical Infrastructure

Europe · Switzerland · Critical Infrastructure, General Enterprise · effective

effective

Swiss cyberattack reporting obligation for operators of critical infrastructure with phased enforcement and notification duties.

Incident Reporting Critical Infrastructure Evidence Risk Management Supplier Risk adjacent SBOM relevance Regulation

Singapore Cybersecurity Act

Asia-Pacific · Singapore · Critical Infrastructure, Software & Digital Services · phased

phased

Cybersecurity framework for critical information infrastructure, expanded by 2024 amendments to cover additional classes such as foundational digital infrastructure providers.

Critical Infrastructure Incident Reporting Cybersecurity Codes Governance Evidence implicit SBOM relevance Regulation

China GB 44495 and GB 44496 Vehicle Cybersecurity Standards

Asia-Pacific · China · Automotive & Mobility · effective

effective

Mandatory Chinese vehicle cybersecurity and software update standards covering CSMS-style governance, technical controls, inspection and test methods, software update management, and vehicle evidence.

Cybersecurity Management System Secure Updates Vulnerability Management Product Security Technical Documentation Evidence implicit SBOM relevance Standard

OMB Memorandum M-26-05 Risk-Based Software and Hardware Security

North America · United States · Government & Public Sector, Software & Digital Services · effective

effective

Federal policy shifting software and hardware security assurance from universal attestation to agency risk-based contractual and validation approaches.

Risk Management Secure Development SBOM Supplier Risk Evidence Procurement Security explicit SBOM relevance Policy

UK GB Type Approval R155 and R156 Requirements

Europe · United Kingdom · Automotive & Mobility · phased

phased

Great Britain type approval implementation of UN R155 cybersecurity and UN R156 software update requirements, with phased dates for new vehicle types, complete vehicles, completed vehicles, and special purpose vehicles.

Cybersecurity Management System Secure Updates Supplier Risk Technical Documentation Evidence Audit Trail implicit SBOM relevance Standard

APRA CPS 230 Operational Risk Management

Asia-Pacific · Australia · Financial Services · effective

effective

APRA standard requiring regulated entities to manage operational risks, maintain critical operations through disruption, and manage service-provider arrangements.

Operational Resilience Third-Party Risk Supplier Risk Business Continuity Evidence adjacent SBOM relevance Standard

China Cybersecurity Label Management Measures

Asia-Pacific · China · Connected Products & IoT · upcoming

upcoming

China cybersecurity labeling framework for internet-connected products, including security capability levels, testing, reports, conformity statements, and vulnerability handling.

IoT Labeling Product Security Vulnerability Management Conformity Evidence Technical Documentation adjacent SBOM relevance Certification

EU AI Act

Europe · European Union · AI & Data, Software & Digital Services, Healthcare & Life Sciences · phased

phased

Risk-based AI regulation requiring technical documentation, logging, post-market monitoring, incident reporting, and cybersecurity measures for high-risk AI systems.

Technical Documentation Incident Reporting Post-Market Monitoring Governance Evidence Risk Management adjacent SBOM relevance Regulation

EU Machinery Regulation

Europe · European Union · Industrial & Manufacturing · upcoming

upcoming

Updates EU machinery safety rules for connected and software-enabled machinery, including protection against corruption where safety functions depend on software or data.

Product Security Technical Documentation Risk Management Secure Updates Evidence adjacent SBOM relevance Regulation

EU Cyber Resilience Act (CRA)

Europe · European Union · Software & Digital Services, Connected Products & IoT, Industrial & Manufacturing · phased

phased

Horizontal cybersecurity law for products with digital elements, combining secure-by-design duties, vulnerability handling, incident reporting, technical documentation, and software component transparency.

SBOM Vulnerability Disclosure Incident Reporting Technical Documentation Secure Development Supply Chain Security explicit SBOM relevance Regulation
SBOM Compliance Dashboard
Real-time software bill of materials tracking and compliance status
Product Components Compliance Last Updated
Automotive Platform v2.3 1,247 98% UNECE R155 2024-12-19
Medical Device Suite 892 100% FDA 2024-12-18
Financial Services API 1,534 96% EO 14028 2024-12-17
IoT Gateway Firmware 2,103 99% EU CRA 2024-12-19
Resources

Guides. Blogs. Regulations.

Find blogs, beginner guides, and compliance regulations to help you understand and implement SBOMs with confidence.

Latest insights and updates from the SBOM world

Secure SBOM Sharing Without Oversharing

A practical model for “least disclosure” using ABAC, redaction, and the SBOM Trust Center

Read More

SBOM CI/CD Automation. A Reference Architecture That Stays Accurate.

Read More

The SBOM Supplier Request Kit

Templates, SLAs, tracking fields, and an audit-ready workflow (without the email chaos)

Read More

See how Exodos manages compliance

Join FOSS and security teams who have transformed their SBOM management from a compliance burden into a strategic advantage.

Start Free Trial