As cybersecurity threats continue to rise, governments and organizations worldwide are implementing strict SBOM regulations to strengthen software supply chain security. These regulations are designed to enhance transparency, reduce vulnerabilities, and ensure that businesses take proactive measures to secure their software ecosystems.To remain compliant, companies must adhere to these evolving standards, which help mitigate security risks, prevent potential cyberattacks, and avoid costly legal consequences.This page provides a comprehensive breakdown of the most critical global regulations, detailing their specific requirements, impact on businesses, and the role of SBOM in ensuring compliance. With a clear and structured format, this guide simplifies complex regulatory frameworks, making it easier for organizations to understand and implement the necessary security measures.
Track SBOM, vulnerability disclosure, incident reporting, and software transparency obligations by region, industry, and enforcement stage.
101regulations tracked
0explicit SBOM signals
0dated deadlines
101 matching obligations
Need to map these obligations to your products?Turn global SBOM, vulnerability, and software supply chain requirements into a concrete evidence workflow with Exodos.
Taiwan Cyber Security Management Act
Asia-Pacific · Taiwan · Government & Public Sector, Critical Infrastructure · effective
effective
Taiwan cybersecurity law governing government agencies and specific non-government agencies, including security maintenance and incident reporting.
US FY2027 NDAA Artificial Intelligence Functional Bill of Materials (AIBOM)
North America · United States · Government & Public Sector, AI & Data, Software & Digital Services · proposed
proposed
Proposed FY2027 NDAA Section 1652 would require DFARS updates barring DoD contracts for goods or services that use AI unless the contractor submits an AIBOM before award, renewal, or extension and maintains it for updates to DoD components within 48 hours.
Primary provisionS. 4784 RS, FY2027 NDAA, Section 1652(a)-(d), Artificial Intelligence Functional Bill of Materialsinclude details related to the software, data, and hardware
Machine-readable AIBOM, SBOM for software underpinning AI systems, model identifiers and versions, training data and inference-time data provenance, licensing, sensitivity, lineage, country of origin and processing history, hardware and compute inventory, cloud environments and deployment boundaries, update workflow capable of responding within 48 hours, access controls, digital signing or hashing, secure sharing and repository evidence.
Relevant reference
S. 4784 RS, FY2027 NDAA, Section 1652(a)-(d), Artificial Intelligence Functional Bill of Materials
Exodos note
Treat this as a leading AI supply chain transparency signal: practical AIBOM evidence has to join SBOMs, model metadata, dataset provenance, hardware/cloud deployment context, and secure repository controls. The IST AIBOM memo reinforces that AIBOM should build on SBOM formats instead of replacing them.
include details related to the software, data, and hardware
CISA/G7 Software Bill of Materials for AI Minimum Elements
Global · G7 / United States / European Union / Japan / United Kingdom / Canada · AI & Data, Software & Digital Services, Critical Infrastructure · guidance
guidance
Joint CISA and G7 guidance defining supplemental minimum elements for SBOMs used with AI systems, including model, dataset, infrastructure, security, and system-level transparency.
Primary provisionCISA/G7 Software Bill of Materials for AI - Minimum ElementsAI systems are software systems
AI SBOM metadata, model records, dataset properties, system-level properties, key performance indicators, security properties, infrastructure dependencies.
Relevant reference
CISA/G7 Software Bill of Materials for AI - Minimum Elements
Exodos note
This is the clearest public baseline for AI BOM data: treat models, datasets, infrastructure, and AI services as supply chain evidence, not just software packages.
North America · United States · Critical Infrastructure, Healthcare & Life Sciences, Financial Services · proposed
proposed
US critical infrastructure incident reporting law requiring CISA to finalize rules for covered cyber incident and ransom payment reporting by covered entities.
Primary provisionCIRCIA covered cyber incident and ransom payment reportingreport covered cyber incidents to CISA
North America · United States · Connected Products & IoT · guidance
guidance
Voluntary US cybersecurity labeling program for consumer IoT products, built around conformance testing, label authorization, registry information, and NIST technical criteria.
Primary provisionFCC IoT cybersecurity labeling program, Report and Order FCC 24-26U.S. Cyber Trust Mark
Europe · United Kingdom · Critical Infrastructure, Software & Digital Services · effective
effective
UK framework for network and information system security in operators of essential services and relevant digital service providers, with security and incident reporting duties.
Europe · United Kingdom · Software & Digital Services, General Enterprise, Government & Public Sector · guidance
guidance
UK government software vendor guidance designed to reduce software supply chain attacks and resilience incidents through secure design, development, deployment, communication, and procurement practices.
Primary provisionUK Software Security Code of Practice and NCSC implementation guidance, Theme 1reducing the likelihood and impact of software supply chain attacks
Software inventory or SBOM, third-party component inventory, build system and compiler inventory, supplier security requirements, validated and regularly updated inventory, vulnerability response evidence.
Relevant reference
UK Software Security Code of Practice and NCSC implementation guidance, Theme 1
Exodos note
This is not binding law, but it is a strong UK procurement signal: customers should expect vendors to evidence component inventory, supplier controls, and secure development practices.
reducing the likelihood and impact of software supply chain attacks
Asia-Pacific · Australia · Connected Products & IoT, Software & Digital Services · effective
effective
Australian rules introducing mandatory cyber security standards for most consumer smart devices, with obligations that create a need for product software inventory, update, and vulnerability evidence.
Smart-device software inventory, component and dependency evidence, update support policy, vulnerability disclosure process, conformity statement, consumer security information.
Relevant reference
Cyber Security (Security Standards for Smart Device) Rules 2025
Exodos note
Manufacturers should connect smart-device conformity evidence to firmware and software component inventories so vulnerability exposure can be answered quickly.
North America · Canada · Critical Infrastructure, Financial Services, Software & Digital Services · effective
effective
Canadian cyber security law establishing a framework to protect critical cyber systems, including operator obligations for cyber security programs, incident reporting, supply chain risk, and third-party dependencies.
Primary provisionBill C-8, Critical Cyber Systems Protection Actprotect critical cyber systems
Critical system inventory, supplier and service-provider dependency map, software and SaaS supplier evidence, incident reporting records, cyber security program controls, risk mitigation plans.
Relevant reference
Bill C-8, Critical Cyber Systems Protection Act
Exodos note
Covered operators should treat SBOM, supplier, and service-provider evidence as part of the cyber system record needed for supply chain and third-party risk decisions.
Canadian Centre for Cyber Security Software Supply Chain Guidance
North America · Canada · Critical Infrastructure, Government & Public Sector, Software & Digital Services · guidance
guidance
Canadian guidance for protecting organizations from software supply chain threats, including supplier assessment and software component inventory/SBOM considerations.
Asia-Pacific · China · Critical Infrastructure, General Enterprise · effective
effective
Foundational Chinese cybersecurity law covering network operator security duties, critical information infrastructure protections, security incidents, and network product obligations.
Middle East · Saudi Arabia · Government & Public Sector, Critical Infrastructure, General Enterprise · effective
effective
Minimum cybersecurity requirements for Saudi government organizations and critical national infrastructure operators, covering governance, defense, resilience, cloud, third parties, and ICS.
GovernanceRisk ManagementThird-Party RiskCloud SecurityIndustrial Control SystemsEvidenceimplicit SBOM relevanceFramework
Middle East · Saudi Arabia · Government & Public Sector, Critical Infrastructure · effective
effective
Saudi critical systems controls extending the ECC for national critical systems across governance, defense, resilience, and third-party/cloud cybersecurity.
Global · International · Automotive & Mobility · guidance
guidance
Automotive industry guidance on SBOM program design, supplier exchange, vulnerability operations, confidentiality, and automation across OEM and multi-tier supplier ecosystems.
Primary provisionAuto-ISAC SBOM Informational Report, automotive SBOM useautomation is essential to SBOM adoption
Automotive SBOM policy, supplier exchange workflow, NDA or cybersecurity interface agreement controls, vulnerability triage records, SBOM tooling and automation evidence.
Relevant reference
Auto-ISAC SBOM Informational Report, automotive SBOM use
Exodos note
Auto-ISAC frames automotive SBOM as an operating model: trusted exchange, access control, vulnerability context, and supplier-tier visibility all need to work together.
Global · IMDRF Members · Healthcare & Life Sciences · guidance
guidance
International regulator guidance on SBOM principles and practices for medical device cybersecurity across manufacturers, healthcare providers, and other stakeholders.
Primary provisionIMDRF N73 SBOM principles and practices for medical device cybersecuritySoftware Bill of Materials for Medical Device Cybersecurity
CISA and International Partners Shared Vision for SBOM
Global · International · Software & Digital Services, Critical Infrastructure, Government & Public Sector · guidance
guidance
Joint international guidance setting a shared vision for SBOM as a core tool for vulnerability management, secure-by-design development, and software supply chain transparency.
Primary provisionCISA and international partners shared vision for SBOMSoftware Bill of Materials
IEC 62443-4-2 Technical Security Requirements for IACS Components
Global · International · Industrial & Manufacturing, Critical Infrastructure · effective
effective
Component-level security standard for industrial control system products, covering embedded devices, host devices, network devices, and software applications.
ISO/IEC 27001 Information Security Management Systems
Global · International · General Enterprise, Software & Digital Services · effective
effective
International information security management system standard used as a baseline for governance, risk treatment, supplier controls, and audit evidence.
Primary provisionISO/IEC 27001:2022, information security management systemsinformation security management systems
Global · International · General Enterprise, Software & Digital Services · effective
effective
Reference control catalogue for information security controls, including supplier relationships, secure development, vulnerability management, and asset management.
Primary provisionISO/IEC 27002:2022, information security controlsinformation security controls
North America · United States · Government & Public Sector, Critical Infrastructure, Software & Digital Services · guidance
guidance
Cybersecurity supply chain risk management guidance for federal systems and organizations, covering suppliers, products, services, and system components.
Global · United States / International · Software & Digital Services, Government & Public Sector, Critical Infrastructure · guidance
guidance
CISA update to the SBOM minimum elements baseline, reflecting the current state of maturity in software transparency and supply chain security and expanding expected SBOM capabilities.
Primary provisionCISA 2025 Minimum Elements for a Software Bill of Materialscurrent state of maturity
Current SBOM minimum elements, component identity, supplier identity, dependency relationships, hashes where available, lifecycle process evidence, vulnerability management linkage.
Relevant reference
CISA 2025 Minimum Elements for a Software Bill of Materials
Exodos note
Use the 2025 CISA baseline as the updated acceptance bar for supplier SBOMs, especially where procurement, vulnerability operations, and federal assurance evidence intersect.
CISA Joint Coordinated Vulnerability Disclosure Program Guidance
Global · United States / International · Software & Digital Services, Connected Products & IoT, Critical Infrastructure · guidance
guidance
Joint CISA, NSA, JPCERT/CC, NCSC-NL, and NCSC-UK guidance for software suppliers and online service providers to establish coordinated vulnerability disclosure programs with clear reporting paths, researcher communication, triage, remediation, and disclosure processes.
Primary provisionCISA joint guide, Establishing a Coordinated Vulnerability Disclosure Program to Work With Security ResearchersCoordinated Vulnerability Disclosure Program
CISA joint guide, Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers
Exodos note
This guidance is not a regulation, but it belongs in supplier assurance programs because SBOM, KEV, CVE, and multi-party software supply chain disclosures become more useful when vendors have a repeatable CVD process.
Global · International · Software & Digital Services · guidance
guidance
OWASP verification standard for software components and supply chain controls, including inventory, integrity, provenance, and vulnerability practices.
Primary provisionOWASP Software Component Verification StandardSoftware Component Verification Standard
Global · International · Software & Digital Services, Critical Infrastructure, General Enterprise · guidance
guidance
CycloneDX CBOM capability for representing cryptographic assets, relationships, algorithms, keys, certificates, and dependencies to support cryptographic risk and post-quantum readiness.
Primary provisionCycloneDX Cryptography Bill of Materials capabilityalgorithms, keys, certificates
North America · United States · Government & Public Sector, Critical Infrastructure, General Enterprise · guidance
guidance
NIST NCCoE practice guide for cryptographic discovery during post-quantum migration, including testing discovery tools and building inventory architecture.
North America · United States · Government & Public Sector, Software & Digital Services · effective
effective
Federal cloud security authorization baseline based on NIST SP 800-53 Rev. 5 controls, including supply chain, vulnerability, and configuration evidence.
Europe · European Union · Critical Infrastructure, Software & Digital Services, Government & Public Sector · proposed
proposed
European Commission proposal to revise the Cybersecurity Act and introduce a trusted ICT supply chain security framework for risks from high-risk suppliers and third-country dependencies.
Primary provisionProposal for a Regulation for the EU Cybersecurity Act, trusted ICT supply chain security frameworktrusted ICT supply chain
ICT supplier risk classification, high-risk supplier exposure evidence, software and service dependency map, certification evidence, product and service security assurance records.
Relevant reference
Proposal for a Regulation for the EU Cybersecurity Act, trusted ICT supply chain security framework
Exodos note
Organizations exposed to EU critical sectors should prepare supplier and software dependency evidence now, because high-risk supplier reviews become stronger when tied to product-level component data.
EU Medical Device Regulation Cybersecurity Expectations
Europe · European Union · Healthcare & Life Sciences · effective
effective
EU medical device framework requiring safety, performance, technical documentation, risk management, and post-market surveillance for software-enabled devices.
Primary provisionRegulation (EU) 2017/745 medical devicesmedical devices
EU In Vitro Diagnostic Regulation Cybersecurity Expectations
Europe · European Union · Healthcare & Life Sciences · effective
effective
EU in vitro diagnostic medical device framework covering software-enabled diagnostics, technical documentation, lifecycle risk, and post-market evidence.
Primary provisionRegulation (EU) 2017/746 in vitro diagnostic medical devicesin vitro diagnostic medical devices
Germany BSIG and KRITIS Cybersecurity Requirements
Europe · Germany · Critical Infrastructure, Government & Public Sector · effective
effective
German IT security law and critical infrastructure obligations covering security measures, incident reporting, and evidence for operators and providers.
Asia-Pacific · Malaysia · Critical Infrastructure, Government & Public Sector · effective
effective
Malaysian cybersecurity law establishing national critical information infrastructure duties, incident reporting, and cybersecurity service provider licensing.
Asia-Pacific · Australia · Financial Services · effective
effective
Information security standard requiring APRA-regulated entities to manage information security capability, controls, incidents, testing, audit, and third-party control assurance.
Information SecurityIncident ReportingThird-Party RiskControl AssuranceAudit Trailimplicit SBOM relevanceStandard
Effective
Deadline
Evidence to prepare
Information asset inventory, third-party control assurance, security testing, incident notification records, internal audit evidence.
Exodos note
Component and supplier inventories support information asset classification and third-party assurance.
North America · United States, Canada · Critical Infrastructure · effective
effective
Reliability standard requiring covered electric-sector entities to identify and manage cybersecurity risks from vendors and supply chain relationships.
OMB M-23-02 Migrating to Post-Quantum Cryptography
North America · United States · Government & Public Sector, Critical Infrastructure, General Enterprise · effective
effective
OMB memorandum directing federal agencies to prepare for post-quantum cryptography by inventorying cryptographic systems, prioritizing high-value and high-impact assets, and assessing migration funding.
Primary provisionOMB M-23-02, Section II prioritized inventory of cryptographic systemsprioritized inventory of cryptographic systems
North America · United States · Healthcare & Life Sciences · effective
effective
FDA cybersecurity expectations for medical device submissions and postmarket lifecycle management, including software component transparency and vulnerability management.
Primary provisionFD&C Act Section 524B(b)(3)provide a software bill of materials
Asia-Pacific · India · Financial Services · effective
effective
RBI directions for regulated entities outsourcing IT services, covering governance, risk management, confidentiality, business continuity, audit, and third-party oversight.
North America · United States · General Enterprise, Financial Services · effective
effective
Requires public companies to disclose material cybersecurity incidents and annually describe cybersecurity risk management, strategy, governance, and oversight.
Canada OSFI Guideline B-13 Technology and Cyber Risk Management
North America · Canada · Financial Services · effective
effective
OSFI guidance setting expectations for federally regulated financial institutions to manage technology and cyber risks, including incident reporting and resilience.
MAS technology risk obligations for payment service providers, including fast notification of relevant incidents and controls over technology operations.
US EO 14028 and Federal Secure Software Attestation
North America · United States · Government & Public Sector, Software & Digital Services · effective
effective
Federal software supply chain policy requiring software producers serving the US government to attest to secure development practices, with SBOMs and artifacts used by agencies as supporting evidence.
Primary provisionExecutive Order 14028, Section 4(e)(vii)providing a purchaser a Software Bill of Materials
UK Product Security and Telecommunications Infrastructure Regime
Europe · United Kingdom · Connected Products & IoT · effective
effective
UK consumer connectable product security regime requiring manufacturers, importers, and distributors to meet minimum security requirements and provide statements of compliance.
Primary provisionUK PSTI product security regime, security requirements for connectable productsstatement of compliance
Statement of compliance, password/security requirement evidence, vulnerability reporting channel, support period disclosure, importer/distributor records.
Relevant reference
UK PSTI product security regime, security requirements for connectable products
Exodos note
A product trust center can connect PSTI support-period and vulnerability-channel evidence with component transparency.
North America · Canada · Financial Services · effective
effective
OSFI third-party risk guidance requiring federally regulated financial institutions to manage risks across outsourced and other third-party arrangements.
Europe · European Union · Critical Infrastructure, Software & Digital Services, Government & Public Sector · effective
effective
EU-wide cybersecurity framework for essential and important entities, including risk management, incident reporting, supervision, and supply chain security measures.
Primary provisionDirective (EU) 2022/2555, Article 21 supply chain securitysecurity in network and information systems acquisition, development and maintenance
Asia-Pacific · China · AI & Data, Software & Digital Services, General Enterprise · effective
effective
Chinese network data security regulation requiring data processors to implement protection measures and report network product or service security defects and vulnerabilities.
Japanese IoT product security conformity assessment scheme with baseline and higher assurance labels intended to support procurement and international alignment.
Global · Payment Card Industry · Financial Services, Software & Digital Services · effective
effective
PCI DSS v4.0.1 Requirement 6.3.2 requires entities to maintain an inventory of bespoke and custom software and third-party software components incorporated into that software to support vulnerability and patch management.
Primary provisionPCI DSS v4.0.1 Requirement 6.3.2 and testing procedures 6.3.2.a-binventory of bespoke and custom software
Inventory of bespoke and custom software, third-party software components, libraries, APIs, payment software components and dependencies, supported execution platforms or environments, vulnerability and patch management records, software documentation, software composition analysis evidence.
Relevant reference
PCI DSS v4.0.1 Requirement 6.3.2 and testing procedures 6.3.2.a-b
Exodos note
PCI DSS does not prescribe a specific SBOM format, but Requirement 6.3.2 creates a practical SBOM control: payment software teams need component-level inventory tied to vulnerability and patch evidence.
EU Radio Equipment Directive Cybersecurity Delegated Regulation
Europe · European Union · Connected Products & IoT · phased
phased
Activates cybersecurity, privacy, and fraud-protection essential requirements for categories of internet-connected radio equipment under the Radio Equipment Directive.
Primary provisionDelegated Regulation (EU) 2022/30, Article 3 internet-connected radio equipmentdoes not harm the network or its functioning
Cybersecurity framework for critical information infrastructure, expanded by 2024 amendments to cover additional classes such as foundational digital infrastructure providers.
China GB 44495 and GB 44496 Vehicle Cybersecurity Standards
Asia-Pacific · China · Automotive & Mobility · effective
effective
Mandatory Chinese vehicle cybersecurity and software update standards covering CSMS-style governance, technical controls, inspection and test methods, software update management, and vehicle evidence.
OMB Memorandum M-26-05 Risk-Based Software and Hardware Security
North America · United States · Government & Public Sector, Software & Digital Services · effective
effective
Federal policy shifting software and hardware security assurance from universal attestation to agency risk-based contractual and validation approaches.
Primary provisionOMB M-26-05, software and hardware security validationprovide a current software bill of materials
Europe · United Kingdom · Automotive & Mobility · phased
phased
Great Britain type approval implementation of UN R155 cybersecurity and UN R156 software update requirements, with phased dates for new vehicle types, complete vehicles, completed vehicles, and special purpose vehicles.
Asia-Pacific · Australia · Financial Services · effective
effective
APRA standard requiring regulated entities to manage operational risks, maintain critical operations through disruption, and manage service-provider arrangements.
Asia-Pacific · China · Connected Products & IoT · upcoming
upcoming
China cybersecurity labeling framework for internet-connected products, including security capability levels, testing, reports, conformity statements, and vulnerability handling.
Europe · European Union · AI & Data, Software & Digital Services, Healthcare & Life Sciences · phased
phased
Risk-based AI regulation requiring technical documentation, logging, post-market monitoring, incident reporting, and cybersecurity measures for high-risk AI systems.
Primary provisionRegulation (EU) 2024/1689, Annex IV technical documentationtechnical documentation shall be drawn up before that system is placed on the market
Europe · European Union · Industrial & Manufacturing · upcoming
upcoming
Updates EU machinery safety rules for connected and software-enabled machinery, including protection against corruption where safety functions depend on software or data.
Primary provisionRegulation (EU) 2023/1230, Annex III 1.1.9 protection against corruptionidentify the software installed on it
Europe · European Union · Software & Digital Services, Connected Products & IoT, Industrial & Manufacturing · phased
phased
Horizontal cybersecurity law for products with digital elements, combining secure-by-design duties, vulnerability handling, incident reporting, technical documentation, and software component transparency. CRA vulnerability and incident reporting obligations apply from 11 September 2026 through the ENISA Single Reporting Platform.
Primary provisionRegulation (EU) 2024/2847, Annex I Part II, vulnerability handling requirementsidentify and document components contained in the products
Product security risk assessment, SBOM or equivalent component records, vulnerability handling process, ENISA Single Reporting Platform workflow, conformity evidence, support period records.
Relevant reference
Regulation (EU) 2024/2847, Annex I Part II, vulnerability handling requirements
Exodos note
Anchor EU product compliance around a living component system of record, not a one-time SBOM export. Reporting readiness now needs a product-to-component-to-vulnerability path before the 11 September 2026 CRA reporting date.
identify and document components contained in the products