SBOMs Are Shifting From Best Practice to Legal Obligation, Says InfoQ
In a report from InfoQ covering Viktor Petersson’s talk at QCon London 2026, he warned that Software Bills of Materials (SBOMs) are no longer just a security best practice but are rapidly becoming mandatory due to emerging regulations like the EU Cyber Resilience Act, U.S. Executive Order 14028, FDA device rules, and PCI‑DSS requirements. Petersson explained practical details on generating high‑quality SBOMs, differences between dominant formats like SPDX and CycloneDX, the importance of signing and lifecycle‑managing SBOM artifacts in CI/CD pipelines, and common pitfalls such as merging disparate SBOMs or skipping signing. He stressed teams must treat SBOMs as managed engineering artifacts rather than ad‑hoc documents if they want to meet upcoming compliance windows and improve software supply‑chain transparency.
Comments
Post a Comment