{"id":654,"date":"2026-08-13T06:46:45","date_gmt":"2026-08-13T06:46:45","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=654"},"modified":"2026-08-13T06:46:45","modified_gmt":"2026-08-13T06:46:45","slug":"sbom","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/sbom\/","title":{"rendered":"SBOM Explained: Software Bill of Materials"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: SBOM\n     Shared glossary design system. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n.og .p-yes{background:var(--sage-100);color:var(--sage-700)}\n.og .p-no{background:#eef0f4;color:var(--muted)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">An SBOM is a machine-readable list of every component inside a piece of software, so that when a vulnerability is announced you can tell in minutes whether it affects you.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">Code security<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>A software bill of materials records each component in a build: name, version, supplier, licence and where it sits in the dependency tree. It is generated automatically at build time, usually in the SPDX or CycloneDX format, and increasingly requested by enterprise buyers during procurement.<\/p>\n<\/div>\n\n<p>The reason it exists is speed. When a widely used library is found to be vulnerable, the question every customer asks is whether you use it. Without an SBOM that answer takes days of searching. With one it takes a query.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#contains\">What an SBOM records<\/a><\/li>\n    <li><a href=\"#formats\">Formats and how it is produced<\/a><\/li>\n    <li><a href=\"#why\">Why buyers ask for one<\/a><\/li>\n    <li><a href=\"#osto\">How Osto generates SBOMs<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"contains\">What an SBOM records<\/h2>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 240\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"Anatomy of one SBOM entry: component, version, supplier, licence, dependency relationship and unique identifier.\">\n  <text x=\"20\" y=\"26\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" letter-spacing=\"1.2\" fill=\"#0f1538\">ONE ENTRY IN AN SBOM<\/text>\n\n  <rect x=\"12\" y=\"42\" width=\"152\" height=\"52\" rx=\"10\" fill=\"#e9ecfa\"\/>\n  <text x=\"88\" y=\"64\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" font-weight=\"700\" fill=\"#4a52a8\">COMPONENT<\/text>\n  <text x=\"88\" y=\"83\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">openssl<\/text>\n\n  <rect x=\"172\" y=\"42\" width=\"132\" height=\"52\" rx=\"10\" fill=\"#e9ecfa\"\/>\n  <text x=\"238\" y=\"64\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" font-weight=\"700\" fill=\"#4a52a8\">VERSION<\/text>\n  <text x=\"238\" y=\"83\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">3.0.11<\/text>\n\n  <rect x=\"312\" y=\"42\" width=\"152\" height=\"52\" rx=\"10\" fill=\"#e3f0e9\"\/>\n  <text x=\"388\" y=\"64\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" font-weight=\"700\" fill=\"#3a6f5d\">SUPPLIER<\/text>\n  <text x=\"388\" y=\"83\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">OpenSSL Project<\/text>\n\n  <rect x=\"472\" y=\"42\" width=\"132\" height=\"52\" rx=\"10\" fill=\"#fbe9dc\"\/>\n  <text x=\"538\" y=\"64\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" font-weight=\"700\" fill=\"#a2603a\">LICENCE<\/text>\n  <text x=\"538\" y=\"83\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">Apache-2.0<\/text>\n\n  <rect x=\"612\" y=\"42\" width=\"136\" height=\"52\" rx=\"10\" fill=\"#f0e6f3\"\/>\n  <text x=\"680\" y=\"64\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" font-weight=\"700\" fill=\"#6b4576\">RELATIONSHIP<\/text>\n  <text x=\"680\" y=\"83\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">transitive<\/text>\n\n  <rect x=\"12\" y=\"104\" width=\"736\" height=\"46\" rx=\"10\" fill=\"#1c267a\"\/>\n  <text x=\"30\" y=\"124\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" font-weight=\"700\" fill=\"#b9c1e6\">UNIQUE IDENTIFIER<\/text>\n  <text x=\"30\" y=\"142\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#ffffff\">pkg:generic\/openssl@3.0.11<\/text>\n\n  <text x=\"380\" y=\"184\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" fill=\"#0f1538\">The identifier is what makes it machine-readable. A name and version as free text<\/text>\n  <text x=\"380\" y=\"204\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" fill=\"#0f1538\">cannot be matched reliably against a vulnerability feed.<\/text>\n  <text x=\"380\" y=\"228\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">Repeat for every component in the build, often several hundred entries.<\/text>\n<\/svg>\n<\/div>\n<\/figure>\n\n<h2 id=\"formats\" class=\"c-sage\">Formats and how it is produced<\/h2>\n\n<p>Two formats dominate. Both are machine-readable, and most tooling can convert between them, so the choice usually follows whatever your customer asks for.<\/p>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>Format<\/th><th>Background<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><strong>SPDX<\/strong><\/td><td>An ISO-standardised format originating in licence compliance, common where legal review matters<\/td><\/tr>\n    <tr><td><strong>CycloneDX<\/strong><\/td><td>An OWASP project designed for security use cases, common in application security tooling<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<div class=\"callout\">\n  <p class=\"k\">Generate it in the build, not afterwards<\/p>\n  <p>An SBOM written by hand or produced weeks later describes something that no longer matches what you shipped. It should come out of the same pipeline that produces the artefact, so the two always correspond.<\/p>\n<\/div>\n\n<h2 id=\"why\" class=\"c-apri\">Why buyers ask for one<\/h2>\n\n<div class=\"trio\">\n  <div class=\"tcard a\">\n    <p class=\"n\">Incident response<\/p>\n    <p>When a major vulnerability lands, they need to know within hours which suppliers are affected.<\/p>\n  <\/div>\n  <div class=\"tcard b\">\n    <p class=\"n\">Procurement policy<\/p>\n    <p>Regulated and government buyers increasingly require an SBOM as a <a href=\"https:\/\/www.osto.one\/resources\/blog\/soc-2-readiness-checklist\/\">condition of purchase<\/a>.<\/p>\n  <\/div>\n  <div class=\"tcard c\">\n    <p class=\"n\">Licence exposure<\/p>\n    <p>Legal teams check for copyleft terms that could affect how the product is distributed.<\/p>\n  <\/div>\n<\/div>\n\n<h2 id=\"osto\">How Osto generates SBOMs<\/h2>\n\n<p>Osto&#8217;s code security module produces an SBOM as part of the same process that runs <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sast\/\">SAST<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sca\/\">SCA<\/a>, alongside open-source licence compliance. The inventory therefore stays aligned with the dependency findings rather than sitting in a separate tool, and when a customer asks whether a newly announced vulnerability affects you, the answer comes from the same place the evidence lives.<\/p>\n\n<p class=\"related\"><strong>Product documentation:<\/strong> Setup guides and technical reference are available in the <a href=\"https:\/\/docs.osto.one\/\" target=\"_blank\" rel=\"noopener\">Osto documentation<\/a>.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Free security assessment<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Answer the next dependency scare in minutes<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Osto generates your SBOM in the same pipeline that runs SAST and SCA, so the inventory always matches what you shipped.<\/p>\n  <a href=\"https:\/\/osto.one\/contact\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 30px;border-radius:12px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Get a free security assessment<\/span><\/a>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:transparent;color:#ffffff;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:600;font-size:16px;text-decoration:none;border:1.5px solid rgba(255,255,255,.5);border-radius:12px;padding:13px 28px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#ffffff;\">Book a platform walkthrough<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:14px 0 0;\">SPDX and CycloneDX &middot; Generated at build &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What does SBOM stand for?<\/summary>\n  <p>Software bill of materials. It is a machine-readable inventory of every component in a piece of software, including name, version, supplier, licence and dependency relationships.<\/p>\n<\/details>\n\n<details>\n  <summary>Is an SBOM the same as SCA?<\/summary>\n  <p>No. SCA is the analysis that identifies components and checks them against vulnerability and licence data. The SBOM is the inventory artefact itself, which can be shared with a customer. Most SCA tools generate one.<\/p>\n<\/details>\n\n<details>\n  <summary>Which SBOM format should we use?<\/summary>\n  <p>SPDX and CycloneDX are both widely accepted, and tooling converts between them. Generate whichever your customers request, and keep it produced automatically at build time.<\/p>\n<\/details>\n\n<details>\n  <summary>Do we have to share our SBOM with customers?<\/summary>\n  <p>Increasingly yes for regulated and government buyers, and often on request in enterprise procurement. Some organisations share a reduced version listing components without internal structure, which is generally accepted.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sca\/\">SCA<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sast\/\">SAST<\/a> &middot; CVE &middot; Supply Chain Security &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vulnerability-management\/\">Vulnerability Management<\/a> &middot; Security Questionnaire<\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>An SBOM is a machine-readable list of every component inside a piece of software, so that when a vulnerability is\u2026<\/p>\n","protected":false},"author":8,"featured_media":655,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[91],"class_list":["post-654","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-sbom"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/654","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=654"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/654\/revisions"}],"predecessor-version":[{"id":656,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/654\/revisions\/656"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/655"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=654"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=654"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=654"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}