Skip to content

SBOM Use-Case: Supplier

One of the key use cases for SBOMs is to provide transparency to your customers about the software you are shipping. By providing an SBOM, you can give your customers confidence in your product and your development practices.

This is especially important for customers in regulated industries, such as healthcare and finance, where there are strict requirements for software supply chain security.

To learn more about how to generate and provide SBOMs to your customers, please see the Producer section of the SBOM lifecycle.

Both the Cyber Resilliance Act (CRA) of the European Union as well as the Executive Order 14028 in the United States have identified the software supply chain as a critical part to ensure any digital product. Besides these legislative examples it is also possible that customers or partners want to make their own due dilligence on the software they intend to deploy. Thus, a vendor needs to be able to provide documentation on the software composition of their product. SBOMs are the tool to do so and are even explicitly mentioned by the CRA.

A newly developed software is supposed to be released into the Eurpean Market. To ensure compliance with regulations the software supply chain has to be documented. The CRA explicitly names SBOMs as the solution to this.